193.32.2.245:8080/ws/device
ip C2Tracked by C2 Tracker · Whois queried never
Network
- Network
- -
- CIDR
- -
- Country
- -
Contact
- Handle
- -
- Abuse
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| Black Hawk | 322b70d95c18… | C2 | – |
About Black Hawk
An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a "Rakuten account protection" app (label "楽天アカウント保護", padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family's extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords.
Signing certificate
- Subject CN
- editor
- Issuer CN
- editor
- Valid
- 2016-01-10 → 2115-12-17
- Fingerprint
- 6215f00baa4bf18bab5792fc796bfc5555917240f14f7c7e672d956888d75c96
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.