2b2de48e0f4e0f678c9e0a32…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Black Hawk (黑鹰安卓远控), unpacked variant (no libsa.so). Fake Rakuten app net.play.core.time (楽天アカウント保護). The Cf config sits directly in the app dex; the real payload is in two encrypted sibling assets. C2 https://www.hyzj.shop (Cf.S1); AES key Cf.K1 b639d490e53821cd6e8235b625411ab2; inner package com.good.pure.grand.

Identification

SHA-256
2b2de48e0f4e0f678c9e0a324358238937237e76357b6cd29f52192835bac970
MD5
c52f4e95dde85351b8d33dcddc79e177

Observed

Families
Black Hawk
First seen
2026-09-30

APK metadata

Summary

Type
Android · APK
Package
net.play.core.time
Main activity
net.play.core.time.MainActivity
Internal version
20473
Displayed version
2.4.73
Min SDK
24
Target SDK
34

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]
Subject email
[email protected]
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]

Permissions (4)

android.permission.INTERNETandroid.permission.POST_NOTIFICATIONSandroid.permission.REQUEST_INSTALL_PACKAGESnet.play.core.time.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (2)

  • net.play.core.time.MainActivity
  • net.play.core.time.Wv

Services (1)

  • net.play.core.time.Bv

Receivers (2)

  • androidx.profileinstaller.ProfileInstallReceiver
  • net.play.core.time.Ir

Providers (2)

  • androidx.core.content.FileProvider
  • androidx.startup.InitializationProvider

Intent filters - actions

androidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEnet.play.core.time.INSTALL_COMPLETE

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
www.hyzj.shop domain - https Black Hawk 2026-09-30

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Black Hawk

An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a "Rakuten account protection" app (label "楽天アカウント保護", padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family's extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords.