429c9de426ae01faa2ffc088…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
org.work.play.fast, display name 楽天アカウント保護 (“Rakuten Account Protection”).
Native XOR packer: stub Sa Application loads libsa.so and decrypts the real DEX from asset mqtepbznwo with a 32-byte XOR key (payload[i]^=key[i%32], 8-byte length header); the 17.7 MB rb38JoWoZ asset is size-padding decoy. Inner trojan package com.next.move.work.
C2 https://www.collectpointsjp.com. Per-build AES-256 exfil key (Cf.K1): 7e875d4c0ef5b503f5923612911fe75d9cda034dc586b86d91a8151f96be4a5e.Identification
- SHA-256
- 429c9de426ae01faa2ffc08850e70fa0b4ace5fa2a56b7908fa9dacb72a77fbd
- MD5
- cd9b8f2f30becf7f008895c07c6169bf
Observed
- Families
- Black Hawk
- First seen
- 2026-10-05
APK metadata
Summary
- Type
- Android · APK
- Package
- org.work.play.fast
- Main activity
- org.work.play.fast.MainActivity
- Internal version
- 10668
- Displayed version
- 1.6.68
- Min SDK
- 24
- Target SDK
- 34
Signing certificate
- Valid from
- 2008-02-29 01:33:46
- Valid to
- 2035-07-17 01:33:46
- Serial
- 936eacbe07f201df
- Thumbprint
- 61ed377e85d386a8dfee6b864bd85b0bfaa5af81
- Subject
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]
- Subject email
- [email protected]
- Issuer
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]
Permissions (4)
Intent filters - actions
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| www.collectpointsjp.com | domain | - | https | Black Hawk | 2026-10-05 |
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Black Hawk
An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a "Rakuten account protection" app (label "楽天アカウント保護", padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family's extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords.