Get2

S0460

Malware.View on attack.mitre.org

About this malware

Get2 is a downloader written in C++ that has been used by TA505 to deliver FlawedGrace, FlawedAmmyy, Snatch and SDBbot.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1033
System Owner/User Discovery

Get2 has the ability to identify the current username of an infected host.

T1055.001
Dynamic-link Library Injection

Get2 has the ability to inject DLLs into processes.

T1057
Process Discovery

Get2 has the ability to identify running processes on an infected host.

T1059
Command and Scripting Interpreter

Get2 has the ability to run executables with command-line arguments.

T1071.001
Web Protocols

Get2 has the ability to use HTTP to send information collected from an infected host to C2.

T1082
System Information Discovery

Get2 has the ability to identify the computer name and Windows version of an infected host.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Proofpoint TA505 October 2019 Open source
    Schwarz, D. et al. (2019, October 16). TA505 Distributes New SDBbot Remote Access Trojan with Get2 Downloader. Retrieved May 29, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.