IOC Report
https://app.temu.com/cmsg_transit.html?_cmsg_biz=9001&_cmsg_channel=mail&_cmsg_locale=100~ja~JPY&msgid=100-20241001-15-B-783234786743422976-427-orGMX05z&_p_landing=1&_x_src=mail

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
dropped
Chrome Cache Entry: 101
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 102
ASCII text, with very long lines (9866)
dropped
Chrome Cache Entry: 103
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
downloaded
Chrome Cache Entry: 104
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 105
ASCII text, with very long lines (14554)
dropped
Chrome Cache Entry: 106
JSON data
dropped
Chrome Cache Entry: 71
ASCII text, with very long lines (32556)
downloaded
Chrome Cache Entry: 72
Unicode text, UTF-8 text, with very long lines (33078), with no line terminators
downloaded
Chrome Cache Entry: 73
JSON data
dropped
Chrome Cache Entry: 74
ASCII text, with very long lines (17079)
downloaded
Chrome Cache Entry: 75
JSON data
dropped
Chrome Cache Entry: 76
JSON data
dropped
Chrome Cache Entry: 77
ASCII text, with very long lines (16448)
downloaded
Chrome Cache Entry: 78
JSON data
dropped
Chrome Cache Entry: 79
ASCII text, with very long lines (31871)
dropped
Chrome Cache Entry: 80
ASCII text, with very long lines (31857), with no line terminators
downloaded
Chrome Cache Entry: 81
JSON data
dropped
Chrome Cache Entry: 82
ASCII text, with very long lines (4610)
downloaded
Chrome Cache Entry: 83
Unicode text, UTF-8 text, with very long lines (51665)
downloaded
Chrome Cache Entry: 84
ASCII text, with very long lines (31871)
downloaded
Chrome Cache Entry: 85
ASCII text, with very long lines (8125), with no line terminators
downloaded
Chrome Cache Entry: 86
JSON data
downloaded
Chrome Cache Entry: 87
Unicode text, UTF-8 text, with very long lines (65507), with no line terminators
dropped
Chrome Cache Entry: 88
JSON data
dropped
Chrome Cache Entry: 89
ASCII text, with very long lines (16448)
dropped
Chrome Cache Entry: 90
ASCII text, with very long lines (14554)
downloaded
Chrome Cache Entry: 91
ASCII text, with very long lines (32386)
downloaded
Chrome Cache Entry: 92
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
downloaded
Chrome Cache Entry: 93
Unicode text, UTF-8 text, with very long lines (65507), with no line terminators
downloaded
Chrome Cache Entry: 94
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
dropped
Chrome Cache Entry: 95
ASCII text, with very long lines (32386)
dropped
Chrome Cache Entry: 96
ASCII text, with very long lines (13237)
downloaded
Chrome Cache Entry: 97
Unicode text, UTF-8 text, with very long lines (65532), with no line terminators
downloaded
Chrome Cache Entry: 98
JSON data
dropped
Chrome Cache Entry: 99
ASCII text, with very long lines (9866)
downloaded
There are 27 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2420 --field-trial-handle=2336,i,11922094584853678706,15377271422260973123,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://app.temu.com/cmsg_transit.html?_cmsg_biz=9001&_cmsg_channel=mail&_cmsg_locale=100~ja~JPY&msgid=100-20241001-15-B-783234786743422976-427-orGMX05z&_p_landing=1&_x_src=mail"

URLs

Name
IP
Malicious
https://app.temu.com/cmsg_transit.html?_cmsg_biz=9001&_cmsg_channel=mail&_cmsg_locale=100~ja~JPY&msgid=100-20241001-15-B-783234786743422976-427-orGMX05z&_p_landing=1&_x_src=mail
https://www.temu.com/api/phantom/dm/wl/cg
20.157.217.118
https://www.temu.com/favicon.ico
20.157.217.118
http://temudebug.com/sourcemaps/assets/js/react_webpack_runtime_18e952b53862e96f8ff5.js.map
unknown
https://www.temu.com/api/bg/bg-uranus-api/uranus_cart/user_cart_num
20.157.217.118
http://temudebug.com/sourcemaps/assets/js/5498_aaab1713d6d5f1679827.js.map
unknown
https://www.temu.com/api/bg/jayce/apply_info/weak_query_purchase_protection
20.157.217.118
https://www.temu.com/api/phantom/xg/pfb/b
20.157.217.118
http://temudebug.com/sourcemaps/assets/js/9112_b0e8c76918dbb40583ab.js.map
unknown
https://www.temu.com/bgc_purchase_protection.html?_cmsg_locale=100~ja~JPY&_cmsg_channel=mail&_cmsg_biz=9001&msgid=100-20241001-15-B-783234786743422976-427-orGMX05z&_x_src=mail&_p_landing=1
20.157.217.118
https://www.temu.com/cmsg_transit.html?_cmsg_biz=9001&_cmsg_channel=mail&_cmsg_locale=100~ja~JPY&msgid=100-20241001-15-B-783234786743422976-427-orGMX05z&_p_landing=1&_x_src=mail
20.157.217.118
https://www.temu.com/api/poppy/v1/shade_words?scene=shade_words
20.157.217.118
https://www.temu.com/api/passport/token/touch
20.157.217.118
http://temudebug.com/sourcemaps/assets/js/biz_layout_search_panel_2462bf359887949285a8.js.map
unknown
http://temudebug.com/sourcemaps/assets/js/73_47b1f831db6ae6e17186.js.map
unknown
https://us.pftk.temu.com/pmm/api/pmm/front_err
52.149.234.104
http://temudebug.com/sourcemaps/assets/js/w/bgt_purchase_protection_607eb01e22892a5404cd.js.map
unknown
https://www.temu.com/api/alexa/pc/homepage/activity
20.157.217.118
https://www.temu.com/bgn_verification.html?VerifyAuthToken=cUtPZVcyknjY1Uq8kS3VdAf832ec0d4edd2c482&from=https%3A%2F%2Fwww.temu.com%2Fw%2Fbgt_purchase_protection.html%3F_cmsg_locale%3D100~ja~JPY%26_cmsg_channel%3Dmail%26_cmsg_biz%3D9001%26msgid%3D100-20241001-15-B-783234786743422976-427-orGMX05z%26_p_landing%3D1&_x_msgid=100-20241001-15-B-783234786743422976-427-orGMX05z&_x_src=mail&refer_page_name=bgt_purchase_protection&refer_page_id=10135_1728081774784_w1fz0yalax&refer_page_sn=10135&_x_sessn_id=jjxz2g1cya
20.157.217.118
http://temudebug.com/sourcemaps/assets/js/biz_layout_sc_sidebar_31b465b41673fac6f1f4.js.map
unknown
http://temudebug.com/sourcemaps/assets/js/biz_vendors_d21628ec04c1ec4aa8ac.js.map
unknown
https://www.temu.com/api/server/_stm
20.157.217.118
https://us.pftk.temu.com/pmm/api/pmm/api
52.149.234.104
https://us.pftk.temu.com/pmm/api/pmm/defined
52.149.234.104
http://temudebug.com/sourcemaps/assets/js/biz_layout_anti_fraud_popup_4fb7121944c7c1d297b7.js.map
unknown
https://us.thtk.temu.com/c/th.gif
4.157.73.169
https://www.temu.com/api/phantom/xg/pfb/a3
20.157.217.118
https://www.temu.com/api/bg/huygens/region/list
20.157.217.118
http://temudebug.com/sourcemaps/assets/js/biz_layout_old_category_select_drop_list_a5eaad461c0f8a14a
unknown
https://www.temu.com/api/poppy/v1/title_bar_list?scene=home_title_bar_list
20.157.217.118
http://temudebug.com/sourcemaps/assets/js/biz_layout_activity_coupon_popup_36eec30beee59d406c87.js.m
unknown
http://temudebug.com/sourcemaps/assets/js/biz_layout_activity_download_dialog_379b1715c5e5346f858c.j
unknown
https://app.temu.com/cmsg_transit.html?_cmsg_biz=9001&_cmsg_channel=mail&_cmsg_locale=100~ja~JPY&msgid=100-20241001-15-B-783234786743422976-427-orGMX05z&_p_landing=1&_x_src=mail
20.67.168.214
https://www.temu.com/w/bgt_purchase_protection.html?_cmsg_locale=100~ja~JPY&_cmsg_channel=mail&_cmsg_biz=9001&msgid=100-20241001-15-B-783234786743422976-427-orGMX05z&_x_src=mail&_p_landing=1
https://www.temu.com/api/adx/cm/ttc?scene=1&type=0
20.157.217.118
http://temudebug.com/sourcemaps/assets/js/vendors_08e34f37eeceb6f4a01e.js.map
unknown
There are 25 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
pftk-us.temu.com
52.149.234.104
gw-c-eu-isp.temu.com
20.157.217.118
gw-eu.temu.com
20.67.168.214
thtk-us.temu.com
4.157.73.169
www.google.com
142.250.186.132
cs396.wpc.thetacdn.net
152.199.19.158
default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
217.20.57.34
aimg.kwcdn.com
unknown
avatar-us.kwcdn.com
unknown
www.temu.com
unknown
dl.kwcdn.com
unknown
img.kwcdn.com
unknown
static.kwcdn.com
unknown
app.temu.com
unknown
us.pftk.temu.com
unknown
us.thtk.temu.com
unknown
There are 7 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
192.168.2.8
unknown
unknown
192.168.2.7
unknown
unknown
152.199.19.158
cs396.wpc.thetacdn.net
United States
192.168.2.9
unknown
unknown
192.168.2.6
unknown
unknown
192.168.2.5
unknown
unknown
4.157.73.169
thtk-us.temu.com
United States
20.157.217.118
gw-c-eu-isp.temu.com
United States
52.149.234.104
pftk-us.temu.com
United States
239.255.255.250
unknown
Reserved
20.67.168.214
gw-eu.temu.com
United States
20.157.217.65
unknown
United States
142.250.186.132
www.google.com
United States
There are 3 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://www.temu.com/w/bgt_purchase_protection.html?_cmsg_locale=100~ja~JPY&_cmsg_channel=mail&_cmsg_biz=9001&msgid=100-20241001-15-B-783234786743422976-427-orGMX05z&_x_src=mail&_p_landing=1