BladeHawk
Malware family · 2 sample(s) · 2 indicator record(s) · 1 signing certificate(s)
About BladeHawk
Android spyware family identified by its distinctive package dat.a8andoserverx with a persistent MainService. The C2 host and port sit as plain const-strings in an inner thread class (MainService$1), handed directly to InetAddress.getByName() and Integer.parseInt().
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| adam9.ddns.net:4000 | domain | d3033e7305b2… | 2021-10-07 |
| alex00.ddns.net:4000 | domain | 2a4cf22220b9… | 2021-09-10 |