2a4cf22220b95ad1f802efd1…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
2a4cf22220b95ad1f802efd1ae8abea56e83dc598d66eb073d75882d20858e39
MD5
ae866cd8ff9ad51b09bc2799fbdef3d2

Observed

Families
BladeHawk
First seen
2021-09-10

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
alex00.ddns.net domain 4000 — BladeHawk 2021-09-10

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About BladeHawk

Android spyware family identified by its distinctive package dat.a8andoserverx with a persistent MainService. The C2 host and port sit as plain const-strings in an inner thread class (MainService$1), handed directly to InetAddress.getByName() and Integer.parseInt().