Skip to content

Malware

ostap

Ostap is a commodity JScript downloader first seen in campaigns in 2016.

ostap is a JavaScript malware family.

Background

Ostap is a commodity JScript downloader that first appeared in campaigns during 2016. It has been seen distributed inside ACE archives and within VBA macro-enabled Microsoft Office documents. More recent builds use WMI to check whether any process from a blacklist is running:

AgentSimulator.exe anti-virus.EXE BehaviorDumper BennyDB.exe ctfmon.exe fakepos_bin FrzState2k gemu-ga.exe (Possible misspelling of Qemu hypervisor’s guest agent, qemu-ga.exe) ImmunityDebugger.exe KMS Server Service.exe ProcessHacker procexp Proxifier.exe python tcpdump VBoxService VBoxTray.exe VmRemoteGuest vmtoolsd VMware2B.exe VzService.exe winace Wireshark

Should any blacklisted process be detected, the malware shuts itself down.

Ostap has been observed acting as a delivery mechanism for other families, among them Nymaim, Backswap and TrickBot.


Source: Malpedia (Fraunhofer FKIE).