322b70d95c188df74e0bda95…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Black Hawk. An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a “Rakuten account protection” app (label “楽天アカウント保護”, padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family’s extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords. Indicators: wss://193.32.2.245:8080/ws/device.

Recovered configuration

inner_package
com.arch.blue.edge

Source: native XOR packer (ApkInstallerManager .so) -> installed banker APK

Identification

SHA-256
322b70d95c188df74e0bda9569ac4101f4ac5a4f7eab0ce3b5088f62e57c69a0
MD5
2be562e0ba1f8d741761fbad61028de1

Observed

Families
Black Hawk
First seen
–

APK metadata

Summary

Type
Android · APK
Package
-
Main activity
mkl.aifga.qjkvb.Obcn44t9ingxkpg
Internal version
-
Displayed version
-
Min SDK
-
Target SDK
-

Signing certificate

Valid from
2016-01-10 08:03:09
Valid to
2115-12-17 08:03:09
Serial
231bc320
Thumbprint
927ca44949d7788aa86f9d7f04d7fdacecd1dfb9
Subject
CN:editor
Issuer
CN:editor

Activities (2)

  • mkl.aifga.qjkvb.Obcn44t9ingxkpg
  • mkl.aifga.qjkvb.ui.Vkxejjz80rm

Services (1)

  • mkl.aifga.qjkvb.vpn.Zn08552by93z

Receivers (3)

  • androidx.profileinstaller.ProfileInstallReceiver
  • mkl.aifga.qjkvb.installer.Gtxt0719em4
  • mkl.aifga.qjkvb.installer.K62zfrh2acuw

Providers (2)

  • androidx.core.content.FileProvider
  • androidx.startup.InitializationProvider

Intent filters - actions

android.intent.action.MY_PACKAGE_REPLACEDandroid.intent.action.PACKAGE_ADDEDandroid.intent.action.PACKAGE_REPLACEDandroid.net.VpnServiceandroidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILE

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
193.32.2.245/ws/device ip 8080 wss Black Hawk –

Signing certificate

Subject CN
editor
Issuer CN
editor
Fingerprint
6215f00baa4bf18bab5792fc796bfc5555917240f14f7c7e672d956888d75c96

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Black Hawk

An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a "Rakuten account protection" app (label "楽天アカウント保護", padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family's extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords.