6827edb54e2310ae0179751b…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
https://tnt.freedomdf.xyz.Recovered configuration
Source: native XOR packer (libsa.so) -> inner dex Cf config
Identification
- SHA-256
- 6827edb54e2310ae0179751b9204ec58a792fb3dbfb410dfaa2c435cc8e9d4c0
- MD5
- bc7f0950326ec45d0a216779cc52e0ba
Observed
- Families
- Black Hawk
- First seen
- 2026-10-07
APK metadata
Summary
- Type
- Android · APK
- Package
- com.safe.high.link
- Main activity
- com.safe.high.link.MainActivity
- Internal version
- 10929
- Displayed version
- 1.9.29
- Min SDK
- 24
- Target SDK
- 34
Signing certificate
- Valid from
- 2008-02-29 01:33:46
- Valid to
- 2035-07-17 01:33:46
- Serial
- 936eacbe07f201df
- Thumbprint
- 61ed377e85d386a8dfee6b864bd85b0bfaa5af81
- Subject
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
- Subject email
- android@android.com
- Issuer
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Permissions (5)
Intent filters — actions
Unpacked payload
The real payload hidden inside the packer, recovered by unwrapping the sample (Black Hawk native XOR packer (installed banker APK)). This is the actual capability set the malware runs with — the APK metadata above is only the decoy loader shell.
Summary
- Package
- com.tech.ultra.tower
- Main activity
- —
- Internal version
- 50607
- Displayed version
- 5.6.7
- Min SDK
- 24
- Target SDK
- 34
Signing certificate
- Valid from
- 2008-02-29 01:33:46
- Valid to
- 2035-07-17 01:33:46
- Serial
- 936eacbe07f201df
- Thumbprint
- 61ed377e85d386a8dfee6b864bd85b0bfaa5af81
- Subject
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
- Subject email
- android@android.com
- Issuer
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Permissions (39)
Intent filters — actions
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| tnt.freedomdf.xyz | domain | — | https | Black Hawk | 2026-10-07 |
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Black Hawk
An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a "Rakuten account protection" app (label "楽天アカウント保護", padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family's extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords.