6827edb54e2310ae0179751b…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Black Hawk. An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a “Rakuten account protection” app (label “楽天アカウント保護”, padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family’s extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords. Indicators: https://tnt.freedomdf.xyz.

Recovered configuration

aes_key
e4c4d8c57b925b9b36984081427bf9008966dcb564e418562c4a91857fe5f872
inner_package
com.tech.ultra.tower

Source: native XOR packer (libsa.so) -> inner dex Cf config

Identification

SHA-256
6827edb54e2310ae0179751b9204ec58a792fb3dbfb410dfaa2c435cc8e9d4c0
MD5
bc7f0950326ec45d0a216779cc52e0ba

Observed

Families
Black Hawk
First seen
2026-10-07

APK metadata

Summary

Type
Android · APK
Package
com.safe.high.link
Main activity
com.safe.high.link.MainActivity
Internal version
10929
Displayed version
1.9.29
Min SDK
24
Target SDK
34

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Subject email
android@android.com
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com

Permissions (5)

Decoy loader shell — the real permission set is under Unpacked payload below.

Activities (2)

  • com.safe.high.link.MainActivity
  • com.safe.high.link.Wv

Services (1)

  • com.safe.high.link.Bv

Receivers (2)

  • androidx.profileinstaller.ProfileInstallReceiver
  • com.safe.high.link.Ir

Providers (2)

  • androidx.core.content.FileProvider
  • androidx.startup.InitializationProvider

Intent filters — actions

androidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEcom.safe.high.link.INSTALL_COMPLETE

Unpacked payload

The real payload hidden inside the packer, recovered by unwrapping the sample (Black Hawk native XOR packer (installed banker APK)). This is the actual capability set the malware runs with — the APK metadata above is only the decoy loader shell.

Summary

Package
com.tech.ultra.tower
Main activity
—
Internal version
50607
Displayed version
5.6.7
Min SDK
24
Target SDK
34

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Subject email
android@android.com
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com

Permissions (39)

android.permission.ACCESS_COARSE_LOCATIONandroid.permission.ACCESS_FINE_LOCATIONandroid.permission.ACCESS_NETWORK_STATEandroid.permission.ACCESS_WIFI_STATEandroid.permission.CAMERAandroid.permission.FOREGROUND_SERVICEandroid.permission.FOREGROUND_SERVICE_CAMERAandroid.permission.FOREGROUND_SERVICE_LOCATIONandroid.permission.FOREGROUND_SERVICE_MEDIA_PROJECTIONandroid.permission.FOREGROUND_SERVICE_MICROPHONEandroid.permission.FOREGROUND_SERVICE_SPECIAL_USEandroid.permission.GET_ACCOUNTSandroid.permission.INTERNETandroid.permission.MANAGE_EXTERNAL_STORAGEandroid.permission.POST_NOTIFICATIONSandroid.permission.QUERY_ALL_PACKAGESandroid.permission.READ_CONTACTSandroid.permission.READ_EXTERNAL_STORAGEandroid.permission.READ_MEDIA_AUDIOandroid.permission.READ_MEDIA_IMAGESandroid.permission.READ_MEDIA_VIDEOandroid.permission.READ_MEDIA_VISUAL_USER_SELECTEDandroid.permission.READ_PHONE_STATEandroid.permission.READ_SMSandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.RECEIVE_SMSandroid.permission.RECORD_AUDIOandroid.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONSandroid.permission.SCHEDULE_EXACT_ALARMandroid.permission.SEND_SMSandroid.permission.USE_BIOMETRICandroid.permission.USE_EXACT_ALARMandroid.permission.USE_FULL_SCREEN_INTENTandroid.permission.WAKE_LOCKandroid.permission.WRITE_EXTERNAL_STORAGEandroid.permission.WRITE_SECURE_SETTINGSandroid.permission.WRITE_SETTINGScom.google.android.c2dm.permission.RECEIVEcom.tech.ultra.tower.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (8)

  • com.google.android.gms.common.api.GoogleApiActivity
  • com.tech.ultra.tower.activity.AccGuideActivity
  • com.tech.ultra.tower.activity.GrantRequestPage
  • com.tech.ultra.tower.activity.MainGateway
  • com.tech.ultra.tower.activity.SplashGateway
  • com.tech.ultra.tower.activity.WakeScreenPage
  • com.tech.ultra.tower.features.credential.CredentialPromptActivity
  • com.tech.ultra.tower.inject.WebPayloadPage

Services (17)

  • androidx.room.MultiInstanceInvalidationService
  • androidx.work.impl.background.systemalarm.SystemAlarmService
  • androidx.work.impl.background.systemjob.SystemJobService
  • androidx.work.impl.foreground.SystemForegroundService
  • com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
  • com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService
  • com.google.firebase.components.ComponentDiscoveryService
  • com.google.firebase.messaging.FirebaseMessagingService
  • com.tech.ultra.tower.features.screen.ScreenCastService
  • com.tech.ultra.tower.keepalive.AdminKeepAliveDaemon
  • com.tech.ultra.tower.keepalive.FcmWakeService
  • com.tech.ultra.tower.keepalive.KeepAliveMediaBrowserService
  • com.tech.ultra.tower.keepalive.KeepAliveMediaRouteService
  • com.tech.ultra.tower.keepalive.KeepAliveTileService
  • com.tech.ultra.tower.keepalive.RecoveryJobService
  • com.tech.ultra.tower.service.CoreTaskAgent
  • com.tech.ultra.tower.service.PlatformAssistDaemon

Receivers (16)

  • androidx.profileinstaller.ProfileInstallReceiver
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
  • androidx.work.impl.background.systemalarm.RescheduleReceiver
  • androidx.work.impl.diagnostics.DiagnosticsReceiver
  • androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver
  • com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver
  • com.google.firebase.iid.FirebaseInstanceIdReceiver
  • com.tech.ultra.tower.keepalive.AdminEventReceiver
  • com.tech.ultra.tower.keepalive.AlarmKeepAliveReceiver
  • com.tech.ultra.tower.keepalive.KeepAliveWidgetProvider
  • com.tech.ultra.tower.receiver.BootReceiver
  • com.tech.ultra.tower.receiver.PackageEventReceiver

Providers (4)

  • androidx.core.content.FileProvider
  • androidx.startup.InitializationProvider
  • com.google.firebase.provider.FirebaseInitProvider
  • com.tech.ultra.tower.keepalive.KeepAliveProvider

Intent filters — actions

android.accessibilityservice.AccessibilityServiceandroid.app.action.DEVICE_ADMIN_DISABLEDandroid.app.action.DEVICE_ADMIN_DISABLE_REQUESTEDandroid.app.action.DEVICE_ADMIN_ENABLEDandroid.appwidget.action.APPWIDGET_UPDATEandroid.intent.action.ACTION_POWER_CONNECTEDandroid.intent.action.ACTION_POWER_DISCONNECTEDandroid.intent.action.ACTION_SHUTDOWNandroid.intent.action.BATTERY_LOWandroid.intent.action.BATTERY_OKAYandroid.intent.action.BOOT_COMPLETEDandroid.intent.action.DEVICE_STORAGE_LOWandroid.intent.action.DEVICE_STORAGE_OKandroid.intent.action.LOCKED_BOOT_COMPLETEDandroid.intent.action.MY_PACKAGE_REPLACEDandroid.intent.action.PACKAGE_ADDEDandroid.intent.action.PACKAGE_CHANGEDandroid.intent.action.PACKAGE_REMOVEDandroid.intent.action.PACKAGE_REPLACEDandroid.intent.action.QUICKBOOT_POWERONandroid.intent.action.SCREEN_ONandroid.intent.action.TIMEZONE_CHANGEDandroid.intent.action.TIME_SETandroid.intent.action.USER_PRESENTandroid.media.MediaRouteProviderServiceandroid.media.browse.MediaBrowserServiceandroid.net.conn.CONNECTIVITY_CHANGEandroid.service.quicksettings.action.QS_TILEandroidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEandroidx.work.diagnostics.REQUEST_DIAGNOSTICSandroidx.work.impl.background.systemalarm.UpdateProxiescom.google.android.c2dm.intent.RECEIVEcom.google.firebase.MESSAGING_EVENT

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
tnt.freedomdf.xyz domain — https Black Hawk 2026-10-07

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Black Hawk

An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a "Rakuten account protection" app (label "楽天アカウント保護", padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family's extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords.