SyrianMT

Malware family · 4 sample(s) · 4 indicator record(s) · 3 signing certificate(s)

About SyrianMT

Nation-state mobile malware targeting Syrians (COVID-19 and other lures), tracked with rotating package names (com.Google.Gmail, GOOD.BYE.GOOGLE, com.android.tester, com.syria.tel, syria.tel.ctu, com.syriatel.ctu). Unusually, the C2 host and port live in the app's string resources under the short keys "h" and "p".

Indicators

IndicatorTypeSampleFirst seen
82.137.218.185:10000 ip 78e669d3b20e… 2020-04-23
82.137.218.185:10000 ip 8f997e606a13… 2020-04-13
82.137.218.185:1999 ip b0e5bde5c6c6… 2017-12-31
82.137.218.185:10000 ip 0a399c83c1dc… 2020-04-12

Detected samples without extractable endpoint (1)

Family matched by code marker or hash attribution, but no C2 is statically extractable — the endpoint arrives at runtime.

SHA-256PackageNoteFirst seen
8f997e606a13… GOOD.BYE.GOOGLE 2020-04-13