Warning: The following files contain malicious software. They are intended for security researchers and should only be executed under controlled environments.
Wednesday, 06 Mar 2013
We are currently searching for the following samples:
MD5s: ed86876db98db35d8c205f8c0b92b0a4 & 02c2ee77cf5aaf8ac03739640c46e822
Both are mentioned in the following EFF report: The Internet is Back in Syria and So is Malware Targeting Syrian Activists
In addition, we are looking for the file 'important.rar', used in a Facebook-based attack. Link to CyberArabs post
Thursday, 31 Jan 2013
One new sample has been added, 185c8d11c0611cae7c81f4458bf1adea / ActiveX.exe. Some notes and background detailing it here and here.
Tuesday, 02 Dec 2012
Two additional samples, Skype Encription v 2.1.exe and FacebookWebBrowser.exe, have been added. The list of samples has also been adjusted so that the most recently-posted samples appear at the top. This does not necessarily correspond to when they were first seen in the wild.
Tuesday, 13 Nov 2012
Three more samples added.
Wednesday, 31 Oct 2012
The front page has been redesigned.
Sunday, 09 Sept 2012
Two more samples are now available for download thanks to y0ug of malware.lu. We appreciate it!
The samples are:
Saturday, 01 Sept 2012
ouAdded another hash/report from the EFF regarding a Syrian regime-created "antihacker" tool, which drops DarkComet. The report goes into detail about the program's behavior and includes screenshots. Currently looking for a sample of this hash.
Saturday, 14 Jul 2012
Another sample & report added.
Tuesday, 10 Jul 2012
A through report prepared by Telecomix agents has been included in our list of media. It details a malware sample from February of this year. Link here: https://docs.google.com/open?id=0B2lkfUkdFSQjWVlKbTVMQ3dNY3M
Monday, 09 Jul 2012
We've added a page to list any links relating to Syrian malware samples. This includes both news articles and technical analysis.
Welcome to SyrianMalware.com. This website is a catalog of malicious software developed by the Al-Assad regime specifically for targeting dissidents.