8c08e15adf3e789b2a936e38…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Black Hawk. An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a “Rakuten account protection” app (label “楽天アカウント保護”, padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family’s extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords. Indicators: https://v-game.eu.cc/full.html, https://www.mangcun.xyz.

Recovered configuration

aes_key
3d74a4b922f5160e75be411dfb8fc30b
inner_package
com.tool.clear.storm

Source: Cf config in app dex (payload in encrypted assets)

Identification

SHA-256
8c08e15adf3e789b2a936e38aaf8e70cf4443b535a00f3aaf716606a53b4a400
MD5
16a3333a80856950784f81a9d4a94122

Observed

Families
Black Hawk
First seen
2026-09-20

C2 configuration (2)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
v-game.eu.cc/full.html domain - https Black Hawk 2026-09-20
www.mangcun.xyz domain - https Black Hawk 2026-09-20

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Black Hawk

An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a "Rakuten account protection" app (label "楽天アカウント保護", padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family's extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords.