ostap
- First seen
- 2016-01-01 00:00:00
- Malware type
- downloader, loader
- Family
- Malware family
- Profile updated
- 2026-07-07 14:31:51
Targeted industries: financial-services technology-and-telecommunications
Context
Ostap is a commodity JScript downloader first seen in campaigns in 2016. It has been observed being delivered in ACE archives and VBA macro-enabled Microsoft Office documents. Recent versions of Ostap query WMI to check for a blacklist of running processes: AgentSimulator.exe anti-virus.EXE BehaviorDumper BennyDB.exe ctfmon.exe fakepos_bin FrzState2k gemu-ga.exe (Possible misspelling of Qemu hypervisor’s guest agent, qemu-ga.exe) ImmunityDebugger.exe KMS Server Service.exe ProcessHacker procexp Proxifier.exe python tcpdump VBoxService VBoxTray.exe VmRemoteGuest vmtoolsd VMware2B.exe VzService.exe winace Wireshark If a blacklisted process is found, the malware terminates. Ostap has been observed delivering other malware families, including Nymaim, Backswap and TrickBot.
Reports & references
- Trend Micro — Ssl Tls Technical Brief (report)
- malpedia.caad.fkie.fraunhofer.de — Js.Ostap (report)
- intrinsec.com — Deobfuscating Hunting Ostap (report)
- malfind.com — From The Archive 1 Ostap Dropper Deobfuscation And Analysis (report)
- labs.bitdefender.com — 5 Times More Coronavirus Themed Malware Reports During March (report)
- bromium.com — Deobfuscating Ostap Trickbots Javascript Downloader (report)
- marcoramilli.com — C2 Traffic Patterns Personal Notes (report)
- Trend Micro — Latest Trickbot Campaign Delivered Via Highly Obfuscated Js File (report)
- cert.pl — Ostap Malware Analysis Backswap Dropper (report)
- github.com — Deobfuscate Ostap.Py (report)