Get2
MITRE ATT&CK: S0460 View on attack.mitre.org
Aliases: FRIENDSPEAK, GetandGo, Get2
- First seen
- 2019-06-01 00:00:00
- Malware type
- downloader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 87 (15 malicious)
- Last IoC activity
- 2026-09-02 00:38:49
- Profile updated
- 2026-07-07 12:41:18
Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications
Context
Get2 is a downloader written in C++ that has been used by TA505 to deliver FlawedGrace, FlawedAmmyy, Snatch and SDBbot.
Recent IoC activity
15 malicious indicators in Maltiverse are attributed to Get2 (S0460). The 15 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | scanotec.dk | 2026-09-03 | 2 |
| hostname | seiyuu.ne.jp | 2026-09-02 | 1 |
| hostname | unser-en.de | 2026-09-02 | 1 |
| hostname | organic-harmony.com | 2026-09-02 | 1 |
| hostname | washington-twp.com | 2026-09-02 | 1 |
| hostname | cumc-hmb.com | 2026-05-31 | 1 |
| URL | http://reachtherapyllc.com/1q0hts9.html | 2026-01-01 | 1 |
| file sample | P002983_37478.xls | 2025-12-27 | 1 |
| URL | http://gmy.su/:jjOab | 2025-11-14 | 1 |
| URL | http://ntskeptics.org/ukpg.html | 2025-11-11 | 1 |
| URL | http://4sv.xyz/advertisment.php | 2025-10-19 | 1 |
| URL | http://gmy.su/:jlOab | 2025-10-02 | 1 |
| file sample | 585ec4c541d0185e467bff79d611e7c1.dll | 2025-09-30 | 1 |
| URL | http://mosgid.ru/~mosgid/u4mt.html | 2025-09-22 | 1 |
| URL | http://www.epower-adv.it/wounding.php | 2025-07-17 | 1 |
Detection coverage
- 1 YARA rules
- 177 Sigma rules
Malware & tools used
- Dynamic-link Library Injection (attack-pattern)
- Process Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Command and Scripting Interpreter (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Web Protocols (attack-pattern)
Used by threat actors
- TA505 (threat-actor)
Detection rules
- MALPEDIA_Win_Get2_Auto (yara-rule)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- proofpoint.com — Ta505 Distributes New Sdbbot Remote Access Trojan Get2 Downloader (report)
- telekom.com — Cybersecurity Ta505 S Box Of Chocolate 597672 (report)
- telekom.com — Cybersecurity Ta505 Returns With A New Bag Of Tricks 602104 (report)
- secureworks.com — Gold Tahoe (report)
- telekom.com — Eager Beaver A Short Overview Of The Restless Threat Actor Ta505 609546 (report)
- blog.fox-it.com — Ta505 A Brief History Of Their Time (report)
- github.com — Tafof Unpacker (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 006 (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 009 (report)
- hornetsecurity.com — Clop Clop Ta505 Html Malspam Analysis (report)
- telekom.com — Inside Of Cl0P S Ransomware Operation 615824 (report)
- blog.intel471.com — A Brief History Of Ta505 (report)
- intel471.com — A Brief History Of Ta505 (report)
- ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
- proofpoint.com — Coronavirus Threat Landscape Update (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Get2 (report)
- intel471.com — Ta505 Get2 Loader Malware December 2020 (report)
- github.com — Malware%20Analysis%2004 10 2019.Md (report)
- elis531989.medium.com — Funtastic Packers And Where To Find Them 41429A7Ef9A7 (report)
- blog.intel471.com — Flowspec Ta505S Bulletproof Hoster Of Choice (report)
- goggleheadedhacker.com — 13 (report)
- MITRE ATT&CK — S0460 (report)