familyvaletgate (confidence: low, static-only)created2026-08-13
SHA-256: 61db1447817fd3b40db67ed261238e15f6338dc642a7a5a4bbf0c0ea5248594e

Build / RE

Toolchain

MinGW-w64 GCC 15.2.0 (x86_64-posix-seh-rev0), C++17 STL, Windows GUI subsystem. ^[exiftool.json:18] ^[strings.txt:1974] Linker version 2.45 (GNU ld, not MSVC). ^[exiftool.json:18] No packer or protector; entropy is flat (0.44–0.46) across all sections. ^[binwalk.txt] Binary size 1,012,944 bytes.

Code Quality

Modern C++: heavy use of std::basic_string, std::vector, std::fstream, range-checked append (vector::_M_realloc_append). ^[strings.txt:1475] Clean error-handling strings ("HTTP send/recv error %lu from %s", "CRASH DETECTED — previous instance did not exit cleanly"). Structured logging to %TEMP%\agent.log. ^[strings.txt:1391–1393]

Anti-Analysis

None observed statically. No IsDebuggerPresent, no NtGlobalFlag, no VM checks, no timing gates. The binary is not stripped — C++ STL and GCC runtime symbols are present. No section encryption or self-modifying code.

Notable Functions

Address Role Evidence
0x1400058e3 Application main GetTempPathA, fopen/fread/fclose on %TEMP%\agent.log, prints "Agent starting v1.0.0", crash-recovery loop. ^[r2:fcn.1400058e3] ^[strings.txt:1391]
0x140002af4 HTTP transport Full WinHttp client: WinHttpCrackUrl, WinHttpOpen, WinHttpConnect, WinHttpOpenRequest, WinHttpSendRequest, WinHttpReceiveResponse, chunked download with 0x6400000 byte cap. ^[r2:fcn.140002af4]
0x14000455a C2 beacon builder Builds JSON payload {"agent_id":"...","hostname":"...","username":"...","os":"windows","ip":"...","pid":...,"elevated":false,"version":"...","crash_log":"..."}. ^[r2:fcn.14000455a] ^[strings.txt:1367–1375]
0x1400c6c90 Dynamic API loader GetModuleHandleA("kernelbase.dll") → GetProcAddress("SetThreadDescription"). ^[r2:fcn.1400c6c90] ^[strings.txt:1772–1773]

Imports

WINHTTP.dll (WinHttpOpen, WinHttpCrackUrl, WinHttpSetOption, WinHttpConnect, WinHttpOpenRequest, WinHttpAddRequestHeaders, WinHttpSendRequest, WinHttpReceiveResponse, WinHttpQueryHeaders, WinHttpQueryDataAvailable, WinHttpReadData, WinHttpCloseHandle), bcrypt.dll (BCryptOpenAlgorithmProvider), KERNEL32.dll (CreateProcessA, GetProcAddress, GetModuleHandleA, GetTempPathA, GetStartupInfoA, GetCurrentProcessId, GetModuleFileNameA, CreatePipe, WaitForMultipleObjects, Sleep), ADVAPI32.dll (registry), api-ms-win-crt-* (stdio, heap, filesystem). ^[pefile.txt]

Signing

Unsigned. No authenticode, no Rich header. Timestamp 2026-05-27 10:39:38 UTC. ^[exiftool.json:15]

Deploy / ATT&CK

Initial Access

Dropped by gcleaner distribution infrastructure per OpenCTI label dropped-by-gcleaner. ^[triage.json]

Execution

  • T1059.003 — cmd.exe / whoami / tasklist /FO CSV /NH invoked via CreateProcessA + CreatePipe. ^[strings.txt:1422–1426] ^[r2:fcn.1400058e3]
  • T1106 — CreateProcessA for payload launch ("DEPLOY launched PID=%lu"). ^[strings.txt:1363]
  • T1053.005 — schtasks /create /tn WindowsCacheTask /tr "..." /sc ONLOGON /f /rl HIGHEST. ^[strings.txt:1433] ^[procedures/schtasks-onlogon-persistence.md]

Persistence

  • T1053.005 — Scheduled task WindowsCacheTask triggers at logon with highest privileges. Payload copies itself to %TEMP%\Microsoft\Windows\Caches\svchost.exe. ^[strings.txt:1430–1440]
  • T1547.001 — unpersist command removes the task via schtasks /delete /tn WindowsCacheTask /f. ^[strings.txt:1439]

Defense Evasion

  • T1027.002 — AES payload decryption (aesEncrypt, "Invalid AES key — using fallback"). ^[strings.txt:1380–1413] bcrypt.dll imported; likely CNG AES-GCM or AES-CBC. ^[pefile.txt] ^[techniques/bcrypt-aes-gcm-payload-decryption.md]
  • T1036.005 — Masquerades as svchost.exe in %TEMP%\Microsoft\Windows\Caches\. ^[strings.txt:1440]
  • T1036.004 — User-agent masquerade: ValetGate/2.0 (Windows NT 10.0; Kiosk). ^[strings.txt] ^[r2:fcn.140002af4]

Discovery

  • T1082 — whoami, tasklist, system info gathered for C2 beacon. ^[strings.txt:1422–1424]
  • T1033 — Username and hostname in beacon JSON. ^[strings.txt:1368–1369]

Collection

  • T1074.001 — Task results batched in JSON array and exfiltrated. ^[strings.txt:1376–1379]
  • T1560 — AES encryption of outbound task results (aesEncrypt). ^[strings.txt:1380]

C2 — Command & Control

  • T1071.001 — HTTPS C2 to https://pankebab.com. ^[strings.txt:1366] ^[r2:fcn.14000455a]
  • T1071.001 — REST API paths masqueraded as vehicle/valet operations:
    • GET /api/v1/vehicle/entry (beacon / check-in)
    • POST /api/v1/vehicle/exit (task results / exfil)
    • GET /api/v1/parking/spot/status (poll for new tasks) ^[strings.txt:1464–1466] ^[r2:fcn.14000455a]
  • T1573.002 — Custom request header X-Vehicle-ID. ^[strings.txt:1385]
  • T1001.002 — Stacked JSON fields: agent_id, hostname, username, os, ip, pid, elevated, version, crash_log, results[] with task_id, type, data. ^[strings.txt:1367–1379]

Exfiltration

Task results (results[]) returned via encrypted HTTPS POST. ^[strings.txt:1376–1380] ^[r2:fcn.140002af4]

Impact

  • T1496 — update, update-enc, deploy, deploy-enc, dexec commands for secondary payload delivery and execution. ^[strings.txt:1442–1457]
  • T1490 — Self-update capability (vg_upd.bat batch script for staged restart). ^[strings.txt:1341–1347]

Attribution

  • Family: Tentatively ValetGate per the hardcoded user-agent string and vehicle-themed C2 API paths. Confidence low — single sample, static-only, no CAPE detonation. Could be a custom build or a renamed open-source RAT.
  • Distribution: gcleaner multi-payload pipeline (OpenCTI dropped-by-gcleaner). ^[triage.json] ^[entities/gcleaner.md]
  • Builder: MinGW-w64 GCC 15.2.0 on Windows (or cross-compiled from Linux). Timestamp 2026-05-27.

Static-only analysis. No CAPE detonation available. Dynamic inferences are conservative — runtime may reveal additional TTPs (e.g., registry writes, file drops, network resolution patterns).