v-game.eu.cc/full.html

domain C2 resolving

Tracked by C2 Tracker · Updated as of 2026-10-10 · Whois queried 2026-10-10T09:51:03

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
43.163.232.104
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
Black Hawk 8c08e15adf3e… C2 2026-09-20

About Black Hawk

An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a "Rakuten account protection" app (label "楽天アカウント保護", padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family's extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords.

Signing certificate

Subject CN
Android
Issuer CN
Android
Valid
2008-02-29 → 2035-07-17
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.