IOC Report
https://app.temu.com/cmsg_transit.html?_cmsg_biz=9016&_cmsg_channel=mail&_cmsg_locale=100~ja~JPY&msgid=100-20241001-15-B-783239451837149184-427-qj36dSf3&_p_landing=1&_x_src=mail

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 4 21:44:07 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 4 21:44:07 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 5 07:56:51 2023, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 4 21:44:07 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 4 21:44:07 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 4 21:44:07 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 120
ASCII text, with very long lines (2565), with no line terminators
downloaded
Chrome Cache Entry: 121
Unicode text, UTF-8 text, with very long lines (33078), with no line terminators
downloaded
Chrome Cache Entry: 122
ASCII text, with very long lines (36519)
downloaded
Chrome Cache Entry: 123
ASCII text, with very long lines (26509)
downloaded
Chrome Cache Entry: 124
Unicode text, UTF-8 text, with very long lines (65507), with no line terminators
downloaded
Chrome Cache Entry: 125
Unicode text, UTF-8 text, with very long lines (14623), with no line terminators
downloaded
Chrome Cache Entry: 126
ASCII text, with very long lines (19610)
downloaded
Chrome Cache Entry: 127
JSON data
dropped
Chrome Cache Entry: 128
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 129
JSON data
dropped
Chrome Cache Entry: 130
Unicode text, UTF-8 text, with very long lines (36672)
downloaded
Chrome Cache Entry: 131
JSON data
dropped
Chrome Cache Entry: 132
JSON data
dropped
Chrome Cache Entry: 133
ASCII text, with very long lines (16197)
downloaded
Chrome Cache Entry: 134
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 135
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
dropped
Chrome Cache Entry: 136
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 137
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 138
JSON data
dropped
Chrome Cache Entry: 139
ASCII text, with very long lines (31857), with no line terminators
downloaded
Chrome Cache Entry: 140
ASCII text, with very long lines (64989)
dropped
Chrome Cache Entry: 141
ASCII text, with very long lines (16809)
downloaded
Chrome Cache Entry: 142
JSON data
dropped
Chrome Cache Entry: 143
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 144
JSON data
downloaded
Chrome Cache Entry: 145
ASCII text, with very long lines (62146)
downloaded
Chrome Cache Entry: 146
JSON data
dropped
Chrome Cache Entry: 147
ASCII text, with very long lines (41019)
downloaded
Chrome Cache Entry: 148
Unicode text, UTF-8 text, with very long lines (59875)
dropped
Chrome Cache Entry: 149
ASCII text, with very long lines (9961)
dropped
Chrome Cache Entry: 150
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
dropped
Chrome Cache Entry: 151
JSON data
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (17112)
downloaded
Chrome Cache Entry: 153
JSON data
dropped
Chrome Cache Entry: 154
JSON data
dropped
Chrome Cache Entry: 155
ASCII text, with very long lines (26509)
dropped
Chrome Cache Entry: 156
ASCII text, with very long lines (13331)
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 158
ASCII text, with very long lines (4664)
downloaded
Chrome Cache Entry: 159
Unicode text, UTF-8 text, with very long lines (51816)
downloaded
Chrome Cache Entry: 160
ASCII text, with very long lines (549)
dropped
Chrome Cache Entry: 161
JSON data
downloaded
Chrome Cache Entry: 162
JSON data
dropped
Chrome Cache Entry: 163
MS Windows icon resource - 1 icon, 64x64, 32 bits/pixel
downloaded
Chrome Cache Entry: 164
Unicode text, UTF-8 text, with very long lines (65507), with no line terminators
dropped
Chrome Cache Entry: 165
ASCII text, with very long lines (10885)
dropped
Chrome Cache Entry: 166
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 167
ASCII text, with very long lines (17246), with no line terminators
downloaded
Chrome Cache Entry: 168
ASCII text, with very long lines (20585)
downloaded
Chrome Cache Entry: 169
ASCII text, with very long lines (16197)
dropped
Chrome Cache Entry: 170
Unicode text, UTF-8 text, with very long lines (65507), with no line terminators
dropped
Chrome Cache Entry: 171
Unicode text, UTF-8 text, with very long lines (65532), with no line terminators
downloaded
Chrome Cache Entry: 172
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
downloaded
Chrome Cache Entry: 173
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 174
ASCII text, with very long lines (61323)
downloaded
Chrome Cache Entry: 175
JSON data
dropped
Chrome Cache Entry: 176
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
downloaded
Chrome Cache Entry: 177
JSON data
dropped
Chrome Cache Entry: 178
Unicode text, UTF-8 text, with very long lines (59875)
downloaded
Chrome Cache Entry: 179
JSON data
downloaded
Chrome Cache Entry: 180
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
downloaded
Chrome Cache Entry: 181
ASCII text, with very long lines (61323)
dropped
Chrome Cache Entry: 182
Unicode text, UTF-8 text, with very long lines (36672)
dropped
Chrome Cache Entry: 183
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 184
JSON data
dropped
Chrome Cache Entry: 185
ASCII text, with very long lines (427)
dropped
Chrome Cache Entry: 186
ASCII text, with very long lines (64989)
downloaded
Chrome Cache Entry: 187
JSON data
dropped
Chrome Cache Entry: 188
JSON data
dropped
Chrome Cache Entry: 189
Unicode text, UTF-8 text, with very long lines (65507), with no line terminators
downloaded
Chrome Cache Entry: 190
ASCII text, with very long lines (13785)
downloaded
Chrome Cache Entry: 191
JSON data
dropped
Chrome Cache Entry: 192
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 193
ASCII text, with very long lines (427)
downloaded
Chrome Cache Entry: 194
ASCII text, with very long lines (9961)
downloaded
Chrome Cache Entry: 195
ASCII text, with very long lines (10885)
downloaded
Chrome Cache Entry: 196
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
downloaded
Chrome Cache Entry: 197
JSON data
dropped
Chrome Cache Entry: 198
ASCII text, with very long lines (549)
downloaded
Chrome Cache Entry: 199
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 200
JSON data
dropped
Chrome Cache Entry: 201
ASCII text, with very long lines (17112)
dropped
Chrome Cache Entry: 202
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
dropped
Chrome Cache Entry: 203
MS Windows icon resource - 1 icon, 64x64, 32 bits/pixel
dropped
Chrome Cache Entry: 204
JSON data
dropped
Chrome Cache Entry: 205
JSON data
dropped
There are 83 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2116 --field-trial-handle=2044,i,9082435770602869201,4102732852736141338,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://app.temu.com/cmsg_transit.html?_cmsg_biz=9016&_cmsg_channel=mail&_cmsg_locale=100~ja~JPY&msgid=100-20241001-15-B-783239451837149184-427-qj36dSf3&_p_landing=1&_x_src=mail"

URLs

Name
IP
Malicious
https://app.temu.com/cmsg_transit.html?_cmsg_biz=9016&_cmsg_channel=mail&_cmsg_locale=100~ja~JPY&msgid=100-20241001-15-B-783239451837149184-427-qj36dSf3&_p_landing=1&_x_src=mail
http://temudebug.com/sourcemaps/assets/js/6623_29fd2d7d304540aafb3b.js.map
unknown
http://temudebug.com/sourcemaps/assets/js/biz_layout_activity_coupon_popup_0b63976f112a33311eec.js.m
unknown
https://www.temu.com/support_question_detail.html?id1=208&id2=1444&_cmsg_locale=100~ja~JPY&_cmsg_channel=mail&_cmsg_biz=9016&msgid=100-20241001-15-B-783239451837149184-427-qj36dSf3&_x_src=mail&_p_landing=1
http://temudebug.com/sourcemaps/assets/js/8861_38e97e111afd5a469034.js.map
unknown
http://temudebug.com/sourcemaps/assets/js/5668_e8ed4c9797de5b24419b.js.map
unknown
https://www.temu.com/api/poppy/v1/shade_words?scene=shade_words
20.157.119.2
http://temudebug.com/sourcemaps/assets/js/9869_b3abfa7f9ae0e73b4ab8.js.map
unknown
http://temudebug.com/sourcemaps/assets/js/biz_vendors_ffe7393e014b653d1144.js.map
unknown
https://www.temu.com/api/passport/token/touch
20.157.119.2
http://temudebug.com/sourcemaps/assets/js/bgn_verification_d364cd95103953510a62.js.map
unknown
https://www.temu.com/cmsg_transit.html?_cmsg_biz=9016&_cmsg_channel=mail&_cmsg_locale=100~ja~JPY&msgid=100-20241001-15-B-783239451837149184-427-qj36dSf3&_p_landing=1&_x_src=mail
20.157.119.2
https://us.pftk.temu.com/pmm/api/pmm/front_err
20.33.59.10
https://www.temu.com/api/phantom/xg/pfb/l1
20.157.119.2
http://temudebug.com/sourcemaps/assets/js/6503_30100d38f6781971ce2a.js.map
unknown
http://temudebug.com/sourcemaps/assets/js/8066_6fa292cb743601eac5e9.js.map
unknown
https://www.temu.com/api/bg/aristotle/available_after_sale_order_list
20.157.119.2
http://temudebug.com/sourcemaps/assets/js/a_u_8a29ce37c8890a9912f7.js.map
unknown
http://temudebug.com/sourcemaps/assets/js/323_a99c1f94b3c1e86a3551.js.map
unknown
http://temudebug.com/sourcemaps/assets/js/slider_verify_7d87f03db1fa53ec2d2a.js.map
unknown
https://www.temu.com/api/potts/faq/recommended_topics
20.157.119.2
http://temudebug.com/sourcemaps/assets/js/9877_a5338b48aec11bf8f56f.js.map
unknown
https://us.pftk.temu.com/pmm/api/pmm/api
20.33.59.10
https://www.temu.com/api/potts/faq/questionInfo
20.157.119.2
http://temudebug.com/sourcemaps/assets/js/biz_layout_anti_fraud_popup_c8d8090ee05d0a07955d.js.map
unknown
http://temudebug.com/sourcemaps/assets/js/biz_layout_sc_sidebar_4aad6a3bdaa42e239e8c.js.map
unknown
http://temudebug.com/sourcemaps/assets/js/biz_vendors_e5c7aef807b7b01a78f1.js.map
unknown
https://us.thtk.temu.com/c/th.gif
4.157.73.169
https://www.temu.com/api/tmod/lizard/sensitive/recognize
20.157.119.2
https://www.temu.com/api/poppy/v1/title_bar_list?scene=home_title_bar_list
20.157.119.2
http://temudebug.com/sourcemaps/assets/js/3968_d2f8dd56b6639c29a9e0.js.map
unknown
http://temudebug.com/sourcemaps/assets/js/react_webpack_runtime_805c3831a4266d98d3a3.js.map
unknown
http://temudebug.com/sourcemaps/assets/js/7869_0402a3d2572e04acb0a2.js.map
unknown
https://www.temu.com/api/phantom/vc_pre_ck
20.157.119.2
https://www.temu.com/api/adx/cm/ttc?scene=1&type=0
20.157.119.2
https://www.temu.com/api/phantom/dm/wl/cg
20.157.119.2
https://us.pftk.temu.com/pmm/api/pmm/front_log
20.33.59.10
https://www.temu.com/api/bg/bg-uranus-api/uranus_cart/user_cart_num
20.157.119.2
http://temudebug.com/sourcemaps/assets/js/support_question_detail_9b57186436cd2019b38a.js.map
unknown
https://www.temu.com/api/phantom/xg/pfb/b
20.157.119.2
https://www.temu.com/api/potts/faq/questions
20.157.119.2
https://www.temu.com/bgn_verification.html?VerifyAuthToken=Kcq0FKJgpoIcTu1bSmUCOAfbe58b2087a8b57b8&from=https%3A%2F%2Fwww.temu.com%2Fsupport_question_detail.html%3Fid1%3D208%26id2%3D1444%26_cmsg_locale%3D100~ja~JPY%26_cmsg_channel%3Dmail%26_cmsg_biz%3D9016%26msgid%3D100-20241001-15-B-783239451837149184-427-qj36dSf3%26_x_src%3Dmail%26_p_landing%3D1&type=iframe&iframeMsgId=7w0f3xiucd6xd0j6qgds5
20.157.119.2
http://temudebug.com/sourcemaps/assets/js/303_cb15ff493dab6beb3d09.js.map
unknown
http://temudebug.com/sourcemaps/assets/js/5126_76a7e111f6a13fb32a52.js.map
unknown
http://temudebug.com/sourcemaps/assets/js/20_81a566316b9785b3f7f7.js.map
unknown
https://app.temu.com/cmsg_transit.html?_cmsg_biz=9016&_cmsg_channel=mail&_cmsg_locale=100~ja~JPY&msgid=100-20241001-15-B-783239451837149184-427-qj36dSf3&_p_landing=1&_x_src=mail
20.107.144.102
https://static-2.kwcdn.com/m-assets/assets/js/biz_vendors_ffe7393e014b653d1144.js
152.199.19.158
http://temudebug.com/sourcemaps/assets/js/vendors_5e70d6849738c7c4bc06.js.map
unknown
http://temudebug.com/sourcemaps/assets/js/3246_691d52500b6efb23c080.js.map
unknown
http://temudebug.com/sourcemaps/assets/js/react_webpack_runtime_d40da5e837c34c0e19aa.js.map
unknown
http://temudebug.com/sourcemaps/assets/js/biz_layout_old_category_select_drop_list_7b73b451a7909a19a
unknown
http://temudebug.com/sourcemaps/assets/js/503_3942d836d7336413da47.js.map
unknown
https://www.temu.com/api/alexa/pc/homepage/activity
20.157.119.2
https://www.temu.com/api/phantom/obtain_captcha
20.157.119.2
https://www.temu.com/api/server/_stm
20.157.119.2
https://us.pftk.temu.com/pmm/api/pmm/defined
20.33.59.10
https://www.temu.com/api/phantom/xg/pfb/a3
20.157.119.2
http://temudebug.com/sourcemaps/assets/js/vendors_111051a0d0a17fc1c9d7.js.map
unknown
https://www.temu.com/api/bg/huygens/region/list
20.157.119.2
https://www.temu.com/api/phantom/xg/pfb/a4
20.157.119.2
http://temudebug.com/sourcemaps/assets/js/biz_layout_search_panel_19037cdf5c43d6ff990c.js.map
unknown
https://aimg.kwcdn.com/m-img/bg/commodity/49f40dd9-d74f-433b-8b6d-1df6114271aa.ttf);font-weight:400;
unknown
https://www.temu.com/api/potts/faq/categories
20.157.119.2
http://temudebug.com/sourcemaps/assets/js/biz_layout_activity_download_dialog_0b9cacffc93fb50e5df5.j
unknown
There are 53 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
pftk-us.temu.com
20.33.59.10
gw-c-eu-isp.temu.com
20.157.119.2
gw-eu.temu.com
20.107.144.102
thtk-us.temu.com
4.157.73.169
www.google.com
142.250.185.68
cs396.wpc.thetacdn.net
152.199.19.158
fp2e7a.wpc.phicdn.net
192.229.221.95
aimg.kwcdn.com
unknown
www.temu.com
unknown
static.kwcdn.com
unknown
static-1.kwcdn.com
unknown
app.temu.com
unknown
us.pftk.temu.com
unknown
us.thtk.temu.com
unknown
static-2.kwcdn.com
unknown
There are 5 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.185.68
www.google.com
United States
192.168.2.8
unknown
unknown
152.199.19.158
cs396.wpc.thetacdn.net
United States
192.168.2.9
unknown
unknown
20.157.119.2
gw-c-eu-isp.temu.com
United States
192.168.2.6
unknown
unknown
20.33.59.10
pftk-us.temu.com
United States
4.157.73.169
thtk-us.temu.com
United States
20.107.144.102
gw-eu.temu.com
United States
239.255.255.250
unknown
Reserved

DOM / HTML

URL
Malicious
https://www.temu.com/support_question_detail.html?id1=208&id2=1444&_cmsg_locale=100~ja~JPY&_cmsg_channel=mail&_cmsg_biz=9016&msgid=100-20241001-15-B-783239451837149184-427-qj36dSf3&_x_src=mail&_p_landing=1
https://www.temu.com/support_question_detail.html?id1=208&id2=1444&_cmsg_locale=100~ja~JPY&_cmsg_channel=mail&_cmsg_biz=9016&msgid=100-20241001-15-B-783239451837149184-427-qj36dSf3&_x_src=mail&_p_landing=1
https://www.temu.com/support_question_detail.html?id1=208&id2=1444&_cmsg_locale=100~ja~JPY&_cmsg_channel=mail&_cmsg_biz=9016&msgid=100-20241001-15-B-783239451837149184-427-qj36dSf3&_x_src=mail&_p_landing=1
https://www.temu.com/support_question_detail.html?id1=208&id2=1444&_cmsg_locale=100~ja~JPY&_cmsg_channel=mail&_cmsg_biz=9016&msgid=100-20241001-15-B-783239451837149184-427-qj36dSf3&_x_src=mail&_p_landing=1
https://www.temu.com/support_question_detail.html?id1=208&id2=1444&_cmsg_locale=100~ja~JPY&_cmsg_channel=mail&_cmsg_biz=9016&msgid=100-20241001-15-B-783239451837149184-427-qj36dSf3&_x_src=mail&_p_landing=1
https://www.temu.com/support_question_detail.html?id1=208&id2=1444&_cmsg_locale=100~ja~JPY&_cmsg_channel=mail&_cmsg_biz=9016&msgid=100-20241001-15-B-783239451837149184-427-qj36dSf3&_x_src=mail&_p_landing=1
https://www.temu.com/support_question_detail.html?id1=208&id2=1444&_cmsg_locale=100~ja~JPY&_cmsg_channel=mail&_cmsg_biz=9016&msgid=100-20241001-15-B-783239451837149184-427-qj36dSf3&_x_src=mail&_p_landing=1
https://www.temu.com/support_question_detail.html?id1=208&id2=1444&_cmsg_locale=100~ja~JPY&_cmsg_channel=mail&_cmsg_biz=9016&msgid=100-20241001-15-B-783239451837149184-427-qj36dSf3&_x_src=mail&_p_landing=1