eaaaf4000ff494c2522ea96b…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Black Hawk. An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a “Rakuten account protection” app (label “楽天アカウント保護”, padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family’s extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords. Indicators: https://echo.mmaldwh.com, https://www.hyzj.shop.

Recovered configuration

aes_key
9edf0620971c511340939f0e2ddf7866
inner_package
com.high.work.swift

Source: Cf config in app dex (payload in encrypted assets)

Identification

SHA-256
eaaaf4000ff494c2522ea96b5d0c3614c0bfd68b751a7a13f8d5247d01043823
MD5
ec03a883ae2a749fda00b6c70135d0c7

Observed

Families
Black Hawk
First seen
2026-09-20

APK metadata

Summary

Type
Android · APK
Package
org.core.cloud.love
Main activity
org.core.cloud.love.MainActivity
Internal version
20362
Displayed version
2.3.62
Min SDK
24
Target SDK
34

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]
Subject email
[email protected]
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]

Permissions (4)

android.permission.INTERNETandroid.permission.POST_NOTIFICATIONSandroid.permission.REQUEST_INSTALL_PACKAGESorg.core.cloud.love.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (2)

  • org.core.cloud.love.MainActivity
  • org.core.cloud.love.Wv

Services (1)

  • org.core.cloud.love.Bv

Receivers (2)

  • androidx.profileinstaller.ProfileInstallReceiver
  • org.core.cloud.love.Ir

Providers (2)

  • androidx.core.content.FileProvider
  • androidx.startup.InitializationProvider

Intent filters - actions

androidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEorg.core.cloud.love.INSTALL_COMPLETE

C2 configuration (2)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
echo.mmaldwh.com domain - https Black Hawk 2026-09-20
www.hyzj.shop domain - https Black Hawk 2026-09-20

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Black Hawk

An Android banking/credential phishing trojan distributed under targeted brand lures. Observed builds impersonate Japanese services - for example a "Rakuten account protection" app (label "楽天アカウント保護", padded with zero-width characters) - under innocuous package names (com.safe.high.link, org.fast.clean.work). It ships a small native helper (lib/*/libsa.so) and requests REQUEST_INSTALL_PACKAGES to drop and install follow-on payloads. The C2 is decoded by the family's extractor from the sample and recovered in plaintext; samples in this cluster beacon to https://tnt.freedomdf.xyz. Phishing lure and overlay content steal account credentials and intercepted one-time passwords.