322b70d95c188df74e0bda95…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
wss://193.32.2.245:8080/ws/device.Recovered configuration
Source: native XOR packer (ApkInstallerManager .so) -> installed banker APK
Identification
- SHA-256
- 322b70d95c188df74e0bda9569ac4101f4ac5a4f7eab0ce3b5088f62e57c69a0
- MD5
- 2be562e0ba1f8d741761fbad61028de1
Observed
- Families
- Black Hawk
- First seen
- –
APK metadata
Summary
- Type
- Android · APK
- Package
- -
- Main activity
- mkl.aifga.qjkvb.Obcn44t9ingxkpg
- Internal version
- -
- Displayed version
- -
- Min SDK
- -
- Target SDK
- -
Signing certificate
- Valid from
- 2016-01-10 08:03:09
- Valid to
- 2115-12-17 08:03:09
- Serial
- 231bc320
- Thumbprint
- 927ca44949d7788aa86f9d7f04d7fdacecd1dfb9
- Subject
- CN:editor
- Issuer
- CN:editor
Intent filters - actions
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 193.32.2.245/ws/device | ip | 8080 | wss | Black Hawk | – |
Signing certificate
- Subject CN
- editor
- Issuer CN
- editor
- Fingerprint
- 6215f00baa4bf18bab5792fc796bfc5555917240f14f7c7e672d956888d75c96
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Black Hawk
An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a "Rakuten account protection" app (label "楽天アカウント保護", padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family's extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords.