tnt.freedomdf.xyz
domain C2Tracked by C2 Tracker · Whois queried never
Registration
- Registrar
- —
- Registered
- —
- Expires
- —
DNS
- Resolves to
- —
- Nameservers
- —
- Status
- —
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| Black Hawk | 6827edb54e23… | C2 | 2026-10-07 |
| Black Hawk | 12b72de4d786… | C2 | 2026-10-08 |
About Black Hawk
An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a "Rakuten account protection" app (label "楽天アカウント保護", padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family's extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2008-02-29 → 2035-07-17
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.