d27a9bf383b5a969d61206fa…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
HK Banking Stealer (provisional) — an Android banking trojan, distributed as
ptonk.lv3c3.rkmmg, self-signed as “ba6152c2”. It installs further packages. Communicates with 1 operator endpoint. Three-stage packed Android banking/crypto stealer disguised as a system/Google Play update (app label “系统更新”, “发现新版本” update dialog). Stage 1 (package ptonk.lv3c3.rkmmg, loader com.forest481.security) AES-CBC-decrypts assets/cfg.dat with the hardcoded key “sK8xQ2mN7vL4pR9w” to a properties config (target package app.topsafe871, rk = base64 AES key for the payload), then AES-CBC-decrypts assets/data.bin with that key to a stage-2 APK (app.topsafe871). The stage-2 dex string-encrypts every literal as ENC: blobs, deobfuscated by com.forest481.security.util.CryptoUtil.decrypt = base64-decode then repeating-XOR with “x9#Kp$2mL@7vQ!nZ”. Decrypting those recovers the C2 (raw TCP socket to 114.66.37.132, port from server_port config) and the target-app list: HK/China banking and crypto-wallet apps including HSBC HK (hk.com.hsbc.hsbchkmobilebanking), Bank of China HK (com.bochk.app.aos), SPDB (cn.com.spdb.mobilebank.per), Binance, imToken (im.token.app) and TokenPocket (vip.mytokenpocket). C2 binary-verified by full static unpack of all three stages. Family label provisional. Indicators: 114.66.37.132.Recovered configuration
c2_transport
raw TCP socket (server_port config)
lure
Google Play / system update (Chinese)
package
ptonk.lv3c3.rkmmg
packer
3-stage AES (cfg.dat/data.bin) + ENC: XOR string crypto
stage2_package
app.topsafe871
targets
HK/China banking + crypto wallets (HSBC HK, BOCHK, SPDB, Binance, imToken, TokenPocket)
Identification
- SHA-256
- d27a9bf383b5a969d61206fa16a6734477d0c5bb93740b6aebb3049446ed42ce
- MD5
- 1dbc5aff5faf8ed015aef54952ea09ff
Observed
- Families
- HK Banking Stealer (provisional)
- First seen
- 2026-10-08
APK metadata
Summary
- Type
- Android · APK
- Package
- ptonk.lv3c3.rkmmg
- Main activity
- com.forest481.security.MainActivity
- Internal version
- 1
- Displayed version
- 1.0
- Min SDK
- 21
- Target SDK
- 34
Signing certificate
- Valid from
- 2026-04-10 12:51:22
- Valid to
- 2126-03-17 12:51:22
- Serial
- 5f469d13
- Thumbprint
- 542a739db417f9680bc246819872e75f16b5ba40
- Subject
- C:ba6152c2, CN:ba6152c2, L:ba6152c2, O:ba6152c2, ST:ba6152c2, OU:ba6152c2
- Issuer
- C:ba6152c2, CN:ba6152c2, L:ba6152c2, O:ba6152c2, ST:ba6152c2, OU:ba6152c2
Permissions (4)
Intent filters — actions
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 114.66.37.132 | ip | — | — | HK Banking Stealer (provisional) | 2026-10-08 |
Signing certificate
- Subject CN
- ba6152c2
- Issuer CN
- ba6152c2
- Fingerprint
- 83c9cec90600c6e764289f294dfb33d476b69bab5ff3fb03826ba3fb69367ad9
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.