82.137.218.185:10000
ipTracked by C2 Tracker · Whois queried 2026-10-04T17:50:10
Network
- Network
- SY-ISP-TARASSUL
- CIDR
- 82.137.218.0/23
- Country
- SY
Contact
- Handle
- 82.137.218.0 - 82.137.219.255
- Abuse
- exp-dir@net.sy
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| SandroRat | b0e5bde5c6c6… | 2017-12-31 |
| SyrianMT | 0a399c83c1dc… | 2020-04-12 |
| SyrianMT | 8f997e606a13… | 2020-04-13 |
| SyrianMT | 78e669d3b20e… | 2020-04-23 |
About SandroRat
Android remote-access trojan sold as "DroidJack", repackaged under many names over the years. Its config (host + port) hides in the static initializer of an obfuscated helper class referenced from MainActivity.onCreate via an sget-byte field read.
About SyrianMT
Nation-state mobile malware targeting Syrians (COVID-19 and other lures), tracked with rotating package names (com.Google.Gmail, GOOD.BYE.GOOGLE, com.android.tester, com.syria.tel, syria.tel.ctu, com.syriatel.ctu). Unusually, the C2 host and port live in the app's string resources under the short keys "h" and "p".
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2008-04-15 → 2035-09-01
- Fingerprint
- c8a2e9bccf597c2fb6dc66bee293fc13f2fc47ec77bc6b2b0d52c11f51192ab8
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.