82.137.218.185:10000

ip not resolving

Tracked by C2 Tracker · Whois queried 2026-10-04T17:50:10

Network

Network
SY-ISP-TARASSUL
CIDR
82.137.218.0/23
Country
SY

Contact

Handle
82.137.218.0 - 82.137.219.255
Abuse
[email protected]

Observed in malware

FamilySample SHA-256First seen
SandroRat b0e5bde5c6c6… 2017-12-31
SyrianMT 0a399c83c1dc… 2020-04-12
SyrianMT 8f997e606a13… 2020-04-13
SyrianMT 78e669d3b20e… 2020-04-23

About SandroRat

Android remote-access trojan sold as "DroidJack", repackaged under many names over the years. Its config (host + port) hides in the static initializer of an obfuscated helper class referenced from MainActivity.onCreate via an sget-byte field read.

About SyrianMT

Nation-state mobile malware targeting Syrians (COVID-19 and other lures), tracked with rotating package names (com.Google.Gmail, GOOD.BYE.GOOGLE, com.android.tester, com.syria.tel, syria.tel.ctu, com.syriatel.ctu). Unusually, the C2 host and port live in the app's string resources under the short keys "h" and "p".

Signing certificate

Subject CN
Android
Issuer CN
Android
Valid
2008-04-15 → 2035-09-01
Fingerprint
c8a2e9bccf597c2fb6dc66bee293fc13f2fc47ec77bc6b2b0d52c11f51192ab8

Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.