-
Latest
#trickbot maldocs have 0 detections on VT. Doc hashes: https://gist.github.com/kirk-sayre-work/c4d9347608429c43b7d11f167b19b763 … . Still drops#ostap.#ostap reaches out to 185[.]180[.]199[.]102 for the 2nd stage. -
I've updated deobfuscate_ostap.py (v0.0.5) to support UTF-16
#Ostap samples. https://github.com/cryptogramfan/Malware-Analysis-Scripts/blob/master/deobfuscate_ostap.py …pic.twitter.com/DuyhRCHlYT
-
Security researcher Oliver Hough (
@olihough86) has recently created a tool to automate the Ostap process. https://github.com/olihough86/ostap-deobfuscator …#TrickBot#Malware#OStap#Cybersecurity#InfoSec#BlueTeam#Emotet#Ryuk#Malspam#Maldoc#IOCs -
Here’s my write-up on deobfuscating
#Ostap, a commodity JScript downloader that#TrickBot operators started using in early August. As part of the research, I’ve released a Python script (deobfuscate_ostap.py) to automate its deobfuscation.https://twitter.com/bromium/status/1168874891459743746 …
Prikaži ovu nit -
2020-01-27 New
#Ostap -#Trickbot maldoc.
p://185.]159.]82.]182/gox/go.php?zs=h21&ed=<9randomdigits>
No VT submission - No AnyRun activities>
https://app.any.run/tasks/d1c192b3-b442-4fd3-8f65-909ed221a516/ …
@reecdeep@JAMESWT_MHT@James_inthe_box @hexraptor@luc4m#malware#ThreatIntelpic.twitter.com/DSkg66AMtP
-
-
-
Ostap is delivered also as a Control Panel module https://app.any.run/tasks/8d3f0dfd-e40f-43d3-abe6-3e78de36f34f/ … the wscript.exe remain running for further payloads deploymt, with sysmon one can try event 1 (ProcCreate) not followed by 5 (ProcTerminate) within say 1min for wscript|cscript|mshta|wmic etc.
#ostap pic.twitter.com/sLKNBgahPg
Prikaži ovu nit -
What kind of malware is dropped by this
#maldoc in Czech?
Is this #ostap downloader? Subject: Připomenutí o splacení dluhu FileName: F-44011156.doc https://www.virustotal.com/gui/file/fa9678e101c7985f03efff98ded8dde8ef2cc748dc8687b44787221b2a76f6f9/detection …https://app.any.run/tasks/62f827f2-5502-4504-9ca0-2d306372b1b3 … -
more
#ostap no trigger in sandbox https://app.any.run/tasks/042ccd67-cb36-453e-83be-867bcadcfb75/ … 23/56 on VT - not bad, but Kaspersky and Microsoft failing to flag it (at time of tweet) https://www.virustotal.com/gui/file/defbf0e619282af8052eebfc0e5a2588732571e0b7cc10cd1e90a945df68d5a8/detection … -
Some fresh looking
#ostap https://app.any.run/tasks/9a36a45b-489f-4039-bfb6-e793c641c0f4 … if you want to play with deobfuscating it then you should be able to adjust the regex in my (quick and dirty) tool https://github.com/olihough86/ostap-deobfuscator … it's not a a very challenging obfuscation at all, great exercise for beginnersPrikaži ovu nit -
Thanks
@decalage2! Now you can use#oletools to detect this new trick used by recent#ostap downloaders!@JAMESWT_MHT@reecdeep@Certego_IRT@CertPa@a_de_pasqualehttps://twitter.com/decalage2/status/1221902787149168640 …
-
#trickbot#ostap spam email italy 24_01_2019 example Samples https://app.any.run/tasks/76d37bb9-1ca6-4f6e-a685-f3ba41f131fe …@guelfoweb@VirITeXplorer@Certego_IRT@matte_lodi@reecdeep@merlos1977@luc4m@malwrhunterteam@James_inthe_box@FewAtoms@Arkbird_SOLG@VK_Intel@58_158_177_102@sugimu_sec@bry_campbellpic.twitter.com/vSAaeBruzF
Prikaži ovu nit -
#malware#trickbot#maldoc by#ostap http://185.159.82.182/go/go.php?zs=h20&ed=<9randomdigits>rnx=<7randomdigits> https://app.any.run/tasks/207ae34d-d8bf-4c07-99ae-ff38a5954388/ …@VK_Intel@GarWarner@JAMESWT_MHT@James_inthe_box@merlos1977@matte_lodi#threatintel#threathunting#infosec#CyberSecuritypic.twitter.com/WXU6cFXcht
-
2020-01-23

#OSTAP -#trickbot maldoc.
p://185.]159.]82.]194/5pIuWL/dWva9v.php?a=h23&b=<9randomdigits>
No activities on AnyRun >
https://app.any.run/tasks/3acff778-e7ff-4348-83df-10062779ac40/ …
Low AV detection rate on VT > 6/59
@reecdeep @hexraptor@luc4m#malware#threatintelpic.twitter.com/bnr6PZYTix
-
Details on deobfuscating the latest round of
#ostap >#TrickBot campaigns.https://twitter.com/Cyjax_Ltd/status/1220304760609394688 …Prikaži ovu nit -
-
#malspam "FatturaN.NNNNNN.doc" delivering#ostap
VT:ab87c1f58ef83b5585f4773910fe7ff2
@malwrhunterteam@dvk01uk@James_inthe_box@JAMESWT_MHT@malware_traffic@Racco42@makflwana@pollo290987@Antelox@bad_packets@VK_Intel @425A_@HazMalware@Mesiaghpic.twitter.com/yiNR7vzSDO
-
#Ostap JavaScript downloader still used to deliver#TrickBot sampleshttps://twitter.com/James_inthe_box/status/1209150941661810690 …
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.