It found that that malware sent back details to an internet address, 216.6.0.28, which has been assigned to the Syrian Telecommunications Establishment ??? indicating that unlike the vast majority of malware, which is used by criminals to download bank or other details and controlled via machines on the wider web, this one connects back to an official address inside Syria.