78e669d3b20e5f1f33985f72…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Identification
- SHA-256
- 78e669d3b20e5f1f33985f7228bf6a9410f61cb949fc0e9df5379537d54f981c
- MD5
- 48dae89653161e7c3e4829d5451702dc
Observed
- Families
- SyrianMT
- First seen
- 2020-04-23
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 82.137.218.185 | ip | 10000 | — | SyrianMT | 2020-04-23 |
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Fingerprint
- c8a2e9bccf597c2fb6dc66bee293fc13f2fc47ec77bc6b2b0d52c11f51192ab8
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About SyrianMT
Nation-state mobile malware targeting Syrians (COVID-19 and other lures), tracked with rotating package names (com.Google.Gmail, GOOD.BYE.GOOGLE, com.android.tester, com.syria.tel, syria.tel.ctu, com.syriatel.ctu). Unusually, the C2 host and port live in the app's string resources under the short keys "h" and "p".