SyrianMT
Malware family · 4 sample(s) · 4 indicator record(s) · 3 signing certificate(s)
About SyrianMT
Nation-state mobile malware targeting Syrians (COVID-19 and other lures), tracked with rotating package names (com.Google.Gmail, GOOD.BYE.GOOGLE, com.android.tester, com.syria.tel, syria.tel.ctu, com.syriatel.ctu). Unusually, the C2 host and port live in the app's string resources under the short keys "h" and "p".
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| 82.137.218.185:10000 | ip | 78e669d3b20e… | 2020-04-23 |
| 82.137.218.185:10000 | ip | 8f997e606a13… | 2020-04-13 |
| 82.137.218.185:1999 | ip | b0e5bde5c6c6… | 2017-12-31 |
| 82.137.218.185:10000 | ip | 0a399c83c1dc… | 2020-04-12 |
Detected samples without extractable endpoint (1)
Family matched by code marker or hash attribution, but no C2 is statically extractable — the endpoint arrives at runtime.
| SHA-256 | Package | Note | First seen |
|---|---|---|---|
| 8f997e606a13… | GOOD.BYE.GOOGLE | 2020-04-13 |