b0e5bde5c6c6904f5c63c026…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
b0e5bde5c6c6904f5c63c02662a754daa6d53dbb934512dab2547aea75801ec5
MD5
a0afccd2cac6d3fc87d92f022f0451e5

Observed

Families
SandroRat, SyrianMT
First seen
2017-12-31

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
82.137.218.185 ip 1999 — SandroRat 2017-12-31

Signing certificate

Subject CN
Lorensius W. L. T
Issuer CN
Lorensius W. L. T
Fingerprint
518ac8bdaf0c767deb31bae1eba826adbef793a68f22784cf3e19c67ba87ecb9

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About SandroRat

Android remote-access trojan sold as "DroidJack", repackaged under many names over the years. Its config (host + port) hides in the static initializer of an obfuscated helper class referenced from MainActivity.onCreate via an sget-byte field read.

About SyrianMT

Nation-state mobile malware targeting Syrians (COVID-19 and other lures), tracked with rotating package names (com.Google.Gmail, GOOD.BYE.GOOGLE, com.android.tester, com.syria.tel, syria.tel.ctu, com.syriatel.ctu). Unusually, the C2 host and port live in the app's string resources under the short keys "h" and "p".