Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Get2

Get2

TLP:CLEAR
Family

AI Analysis

· 3 days ago

Executive Summary

Get2 is a C++ downloader used by the TA505 threat actor to deliver various Ransomware and botloader families. By establishing early connections with attackers’ command servers it fetches additional payloads at runtime, ensuring swift deployment of secondary malware components.

Enhanced Description

Get2 is a C++-developed executable that functions primarily as a malicious downloader. It has been observed in attribution reports linked to the state-sponsored threat actor group TA505, serving as an initial foothold for later-stage payloads such as FlawedGrace, FlawedAmmyy, Snatch, and SDBbot. The binary typically arrives through spear‑phishing attachments or drive‑by downloads and, once executed on a Windows system, establishes outbound connections to a command-and-control (C&C) server to request additional malware binaries. Once the secondary payload is retrieved, Get2 executes it in memory or writes it to disk under innocuous names. The downloader incorporates basic evasion techniques—such as obfuscating network traffic and disabling debugger checks—to maintain persistence during brief reconnaissance phases. Its modus operandi mirrors a broader TA505 toolkit strategy that emphasizes speed, anonymity, and modularity: the agent first compromises the target, then delivers highly configurable ransomware or data‑exfiltration applications depending on the engagement’s objectives. The impact of Get2 is primarily as a delivery vector; however, its presence signals an ongoing compromise that can quickly blossom into a full‑blown attack. It creates a gateway for more destructive malware families and paves the way for credential harvesting, persistence mechanisms, or data exfiltration once the subsequent payloads are deployed.

Key Capabilities

  • Downloads additional malicious binaries from remote C&C servers
  • Executes retrieved payloads in memory or writes them to disk
  • Implements basic code obfuscation and anti-debug checks
  • Establishes persistent execution via scheduled tasks or registry persistence
  • Evasion through network traffic masking

ATT&CK Techniques

T1105
T1059
T1204

Recommended Actions

  • Deploy endpoint protection that flags unknown executables named Get2.exe
  • Block outbound traffic to known TA505 C&C IPs/URLs using firewall rules
  • Enable application whitelisting on corporate endpoints
  • Apply OS and patch updates to reduce exploitation surface
  • Conduct regular IOC scans for file hash or domain matches
  • Implement user education about spear‑phishing attachment risks

Suggested Tags

TA505
Downloader
C++
Windows
Malware
Malicious Payload Delivery
Command & Control
Stealth
Infection Vector

Confidence Assessment

The available data is limited to a single attribution report linking Get2 to TA505. While the technical description of its behaviour is clear, we lack concrete indicators such as hashes, IPs, and detailed process instrumentation, leaving gaps in detection specificity and precise technique mapping. Confidence in the high‑level capabilities is moderate; however, absence of comprehensive evidence reduces certainty regarding all operational behaviors.

Description

Get2 is a downloader written in C++ that has been used by TA505 to deliver FlawedGrace, FlawedAmmyy, Snatch and SDBbot.(Citation: Proofpoint TA505 October 2019)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.