d3033e7305b2c547c0682e75…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
d3033e7305b2c547c0682e75fcd06666688ed98f57f8ab45936ef127d654eb49
MD5
d67384b838fd39c7a3552da04e03df4e

Observed

Families
BladeHawk
First seen
2021-10-07

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
adam9.ddns.net domain 4000 — BladeHawk 2021-10-07

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About BladeHawk

Android spyware family identified by its distinctive package dat.a8andoserverx with a persistent MainService. The C2 host and port sit as plain const-strings in an inner thread class (MainService$1), handed directly to InetAddress.getByName() and Integer.parseInt().