🌐 Documenting early IOCs from TikTok Seller auto-downloads | React2Shell (CVE-2025-55182) YARA matches | Seeking correlations

Joined July 2024
41 Photos and videos
Pinned Tweet
🚨 TikTok Seller US – Observed Auto-Download Behavior (June 2024 – Jan 2026) This post summarizes reproducible observations, collected artifacts, and third-party analysis results related to auto-downloaded files observed while logging into the official TikTok Seller US platform beginning in June 2024. This is not an attribution claim. The goal is documentation and correlation in case others observed similar behavior. 1. Environment & Context • Platform: seller-us[.]tiktok[.]com (official TikTok Seller US) • Login flow: tiktok[.]com → Seller Center → Login with TikTok • Browsers: Google Chrome, Microsoft Edge • Antivirus: Kaspersky (sole engine flagging at the time) • Devices: Primary work computer (bookmarked URL); separate spare laptop (fully updated, manual URL entry) 2. Initial Observation (late June 2024) During login, Kaspersky displayed repeated quarantine pop-ups. After multiple occurrences, detections were identified as: HEUR:Trojan.Script.Generic Detections occurred when: • Logging into Seller Center • Clicking affiliate links inside Seller Central (see profile banner screenshot for log showing seller-us[.]tiktok[.]com and affiliate-us[.]tiktok[.]com subdomains) TikTok support contacted June 28, 2024 (rep response: “this is quite alarming”) 3. Reproduction Same behavior replicated on spare laptop (unused for years, fully updated before testing, manual URL entry) Consistent File 7 Trojan detection across both machines and browsers. 4. Artifacts 11 .blob files auto-downloaded into IndexedDB folder, named sequentially: a, b, c, 2–9. Primary detected files: File 7: c026d2ae1d2439cc7200d0085b955cb0b8a53a80bf9c9585daac129041c4e716 File 8: 8a333b62d5c4580137ccd33ebbecb65b6fae4c45c78007c3becdef6beb95e067 All uploaded to VirusTotal and Hybrid Analysis 5. Capture Session (July 4, 2024) Traces screen recording per Kaspersky request → detection shifted to File 8. Archive permissions altered (SYSTEM user removed). Undetected files disappeared shortly after. System instability observed after session (high data usage notification → mouse unresponsive → forced shutdown required). Clock remained stuck on July 4 when restarted >1 month later. Files reappeared on reboot. 6. Analysis Results Early VT scans (July–Dec 2024): THOR YARA matches on both files (Linux script indicators, Base64/bash combos, Java ProcessBuilder, Through the Wire components). Jan 2026 reanalysis: Match to EXPL_SUSP_JS_POC_Dec25 → indicators from React Server RCE PoC (CVE-2025-55182). 7. Sandbox Behavior (File 7) CAPE/Zenbox: Executed as .hta via mshta.exe. Dropped additional .hta files. Interacted with browser cookies/cache/history. Locale/geofencing checks, anti-VM evasion. Memory contained RCE/XSS payloads with callback attempts to boe-i18n.oast-row.byted-dast[.]com (ByteDance internal DAST subdomain, paths for bash/python/nodejs/groovy/etc.). 8. Related Domains Observed Four .blob files contained references to titkok[.]com • 1a8b473ea7c8139c85cd21e74d3b7f1c7f1d500d791c69fe01fa5e3200d534c0 • dd2f1ae3942d4ea1a78de292220134d23ec52fbcab1ca6f736714750a76dcf22 • f977f1f35f4cc915d93c583804aea111402026629b26d01b28430bcc3eaad98d • 6d5b4e6c24c52cb3cf59f165a5d591d7ce19757fad66f6863917079a1d960e09 iktok[.]com surfaced during Filescan.io analysis of http://tiktok[.]com (OSINT flagged it as a malicious resource, SHA-256 URL: 1ab36b825f349bd687bfcfa07a8baccea8b6312528e06dfe2b369a0eedec379c) Both iktok[.]com and titkok[.]com domains frequently resolve/redirect to survey-smiles[.]com (reported in some OSINT sources as associated with LokiBot infrastructure at 199.59.243[.]228:80). Do not interact with these domains outside isolated environments. 9. Reporting & Response Multiple contacts to @tiktok_us (chat, email, BBB claim) → limited response ("use in-app support"), claim closed. Shared with Kaspersky and a Microsoft contact (who reviewed Hybrid Analysis uploads and requested a VM connection for further analysis). No definitive false-positive confirmation received. 10. Current Status Root cause remains unresolved from my perspective. Artifacts shared for visibility and potential correlation if others have observed similar behavior. 11. Notes I am not a security researcher. This archive reflects personal observations and third-party analysis outputs collected while managing a business seller account.

2
2
685
🚨 TikTok Seller US – Observed Auto-Download Behavior (June 2024 – Jan 2026) This post summarizes reproducible observations, collected artifacts, and third-party analysis results related to auto-downloaded files observed while logging into the official TikTok Seller US platform beginning in June 2024. This is not an attribution claim. The goal is documentation and correlation in case others observed similar behavior. 1. Environment & Context • Platform: seller-us[.]tiktok[.]com (official TikTok Seller US) • Login flow: tiktok[.]com → Seller Center → Login with TikTok • Browsers: Google Chrome, Microsoft Edge • Antivirus: Kaspersky (sole engine flagging at the time) • Devices: Primary work computer (bookmarked URL); separate spare laptop (fully updated, manual URL entry) 2. Initial Observation (late June 2024) During login, Kaspersky displayed repeated quarantine pop-ups. After multiple occurrences, detections were identified as: HEUR:Trojan.Script.Generic Detections occurred when: • Logging into Seller Center • Clicking affiliate links inside Seller Central (see profile banner screenshot for log showing seller-us[.]tiktok[.]com and affiliate-us[.]tiktok[.]com subdomains) TikTok support contacted June 28, 2024 (rep response: “this is quite alarming”) 3. Reproduction Same behavior replicated on spare laptop (unused for years, fully updated before testing, manual URL entry) Consistent File 7 Trojan detection across both machines and browsers. 4. Artifacts 11 .blob files auto-downloaded into IndexedDB folder, named sequentially: a, b, c, 2–9. Primary detected files: File 7: c026d2ae1d2439cc7200d0085b955cb0b8a53a80bf9c9585daac129041c4e716 File 8: 8a333b62d5c4580137ccd33ebbecb65b6fae4c45c78007c3becdef6beb95e067 All uploaded to VirusTotal and Hybrid Analysis 5. Capture Session (July 4, 2024) Traces screen recording per Kaspersky request → detection shifted to File 8. Archive permissions altered (SYSTEM user removed). Undetected files disappeared shortly after. System instability observed after session (high data usage notification → mouse unresponsive → forced shutdown required). Clock remained stuck on July 4 when restarted >1 month later. Files reappeared on reboot. 6. Analysis Results Early VT scans (July–Dec 2024): THOR YARA matches on both files (Linux script indicators, Base64/bash combos, Java ProcessBuilder, Through the Wire components). Jan 2026 reanalysis: Match to EXPL_SUSP_JS_POC_Dec25 → indicators from React Server RCE PoC (CVE-2025-55182). 7. Sandbox Behavior (File 7) CAPE/Zenbox: Executed as .hta via mshta.exe. Dropped additional .hta files. Interacted with browser cookies/cache/history. Locale/geofencing checks, anti-VM evasion. Memory contained RCE/XSS payloads with callback attempts to boe-i18n.oast-row.byted-dast[.]com (ByteDance internal DAST subdomain, paths for bash/python/nodejs/groovy/etc.). 8. Related Domains Observed Four .blob files contained references to titkok[.]com • 1a8b473ea7c8139c85cd21e74d3b7f1c7f1d500d791c69fe01fa5e3200d534c0 • dd2f1ae3942d4ea1a78de292220134d23ec52fbcab1ca6f736714750a76dcf22 • f977f1f35f4cc915d93c583804aea111402026629b26d01b28430bcc3eaad98d • 6d5b4e6c24c52cb3cf59f165a5d591d7ce19757fad66f6863917079a1d960e09 iktok[.]com surfaced during Filescan.io analysis of http://tiktok[.]com (OSINT flagged it as a malicious resource, SHA-256 URL: 1ab36b825f349bd687bfcfa07a8baccea8b6312528e06dfe2b369a0eedec379c) Both iktok[.]com and titkok[.]com domains frequently resolve/redirect to survey-smiles[.]com (reported in some OSINT sources as associated with LokiBot infrastructure at 199.59.243[.]228:80). Do not interact with these domains outside isolated environments. 9. Reporting & Response Multiple contacts to @tiktok_us (chat, email, BBB claim) → limited response ("use in-app support"), claim closed. Shared with Kaspersky and a Microsoft contact (who reviewed Hybrid Analysis uploads and requested a VM connection for further analysis). No definitive false-positive confirmation received. 10. Current Status Root cause remains unresolved from my perspective. Artifacts shared for visibility and potential correlation if others have observed similar behavior. 11. Notes I am not a security researcher. This archive reflects personal observations and third-party analysis outputs collected while managing a business seller account.

2
2
685
Regarding the boe-i18n.oast-row.byted-dast[.]com callback observed in TikTok Seller sandbox memory (File 7, CAPE/Zenbox): virustotal.com/gui/file/c026… Public reporting from early 2025 documents threat actors abusing very similar byted-dast OAST subdomains for data exfiltration in malicious PyPI packages (typosquatting campaigns harvesting hostname/username/current dir). GBHackers summary (with IOCs): gbhackers.com/hackers-weapon… The pattern overlap (oast-row.byted-dast variants) is notable. Malicious OAST Endpoints: • gbv6crrcecvsm77b41bxoih8wz2rqie7.oastify[.]com • sbfwstspuutiarcjzptfenn9u0dsxhjlu.oast[.]fun • dnipqouebm-psl[.]cn.oast-cn.byted-dast[.]com • oqvignkp58-psl.i18n.oast-row.byted-dast[.]com • kc0262r8oypagq3e8f89uaqmodu4i16q.oastify[.]com Sharing for awareness/correlation.
1
207
July 4, 2024 screen recording: Logging into official TikTok Seller US (seller-us-accounts[.]tiktok[.]com/account login flow with “Login with TikTok”) → File 8 detected as Trojan during the Kaspersky trace/recording session. (File 8 auto-downloads at the 1:22 mark)
1
336
MSE retweeted
Critical Security Vulnerability in React Server Components CVE-2025-55182 and rated CVSS 10.0 The vulnerability is present in versions 19.0, 19.1.0, 19.1.1, and 19.2.0 of: react-server-dom-webpack react-server-dom-parcel react-server-dom-turbopack react.dev/blog/2025/12/03/cr…
17
130
556
153,796
Files 7 and 8 match THOR YARA rule EXPL_SUSP_JS_POC_Dec25 → CVE-2025-55182 React2Shell RCE. Still unresolved since July ’24. File 7: c026d2ae1d2439cc7200d0085b955cb0b8a53a80bf9c9585daac129041c4e716 File 8: 8a333b62d5c4580137ccd33ebbecb65b6fae4c45c78007c3becdef6beb95e067
6 Dec 2024
💻 This year, on July 4, 2024, while logging into the TikTok Seller US website, 11 unauthorized files auto-downloaded onto my computer. File 8 was detected as a Trojan by Kaspersky. At the time, I was running trace files and a screen recording to provide evidence for Kaspersky. However, I was unable to access the saved zip archive containing the screen recording and trace files due to missing permissions. Shortly afterward, all undetected files disappeared from the folder. Following this, my computer began making a loud noise, and I noticed a high data usage notification in the top-right corner of my screen. When I tried to scroll toward the notification, my mouse immediately froze. In response, I powered off the computer and removed the battery. Over a month later, when I turned the computer back on, the system clock was stuck on July 4, 2024. Upon further investigation, I discovered that both the SYSTEM and my username were missing from the permissions on the zip file. After manually restoring the permissions, I regained access to the zip file and, to my surprise, the undetected files were visible again. I restored file 8 and transferred all 11 files to a USB drive while disconnected from the internet. On December 1, 2024, I successfully uploaded the Trojan and the undetected files to analysis websites for further review. I am confident the files had disappeared earlier, as the same issue occurred on another laptop, but on this device, the files disappeared much faster. I suspect the malware may have detected that it was being analyzed. Below are the most recent results for each file. I urge @tiktok_us to investigate and address this critical security vulnerability on the TikTok Seller US website. Despite reaching out with evidence and detailed findings, I have yet to receive a direct response or confirmation that this issue has been resolved. Until TikTok provides transparency and a resolution, users of the Seller platform may remain at risk. Please prioritize user safety and cybersecurity by thoroughly investigating and addressing this matter. 🚨 File 8 detected as Trojan: SHA256: 8a333b62d5c4580137ccd33ebbecb65b6fae4c45c78007c3becdef6beb95e067 filescan.io/uploads/674d0bc2… (Suspicious, anti-vm) virustotal.com/gui/file/8a33… metadefender.com/results/has… 👀 Hashes of other undetected files in the same folder: File: a SHA256: 27ba4d61c5cc66e6aa44f8c5833dd852c84c13b8d5cce91fab1a5bdbb1af23d3 filescan.io/uploads/674d191d… File: b SHA256: f66f910a7a1d524e3fa59671b153ef853dffc788a74229164cb6268c419e525a filescan.io/uploads/674d1dbc… File: c SHA256: a4cbb4c983e8cccc7c8e59a45e9bb4930d496ce90ccc62ac48da1d9fc16eb315 filescan.io/uploads/674d2d89… 🤨 File: 2 (No threat, but valid Bitcoin address detected) SHA256: c08a231039ccc18f97a87f95e3d150ca74e8bd896b4d400922e9f773fbff1b7c filescan.io/uploads/674d27ef… File: 3 SHA256: 7bca7fe838f17ed6f5ee0071cdd7fc24fc246fd1e74182a2198c2c95ea2c847f filescan.io/uploads/674d26f3… File: 4 SHA256: 6ab2820513708ea96f22dc8d040853e20228c41516d9b3085e51d3fb3f8cb29c filescan.io/uploads/674d258a… File: 5 SHA256: 3870b0e775c2eb868efc062e5a33c187265ca6616ddbe50dd7421baca3ad0f43 filescan.io/uploads/674d2510… File: 6 SHA256: fd4bc9b7d765929a36d49aabd2b7b809419b08b7964f890a9c56cc47eb4aaa00 filescan.io/uploads/674d238a… 🚨 File: 7 (Suspicious) SHA256: dd2f1ae3942d4ea1a78de292220134d23ec52fbcab1ca6f736714750a76dcf22 filescan.io/uploads/674d1fc4… 🚨 File: 9 (Suspicious) SHA256: f977f1f35f4cc915d93c583804aea111402026629b26d01b28430bcc3eaad98d filescan.io/uploads/674d1485…
2
784
4 Jun 2025
VirusTotal Analysis: http://seller-us.tiktok[.]com 🔗 Behavior Report: virustotal.com/gui/file/1f40… Body SHA-256: 1f4016ac5c17b3c2ca7f26c404506e6a49007ccccc40a07f7b36e9f20e09aa80
17 May 2025
Filescan.io Analysis Report: http://seller-us[.]tiktok[.]com SHA-256: 57d049d73eb0dd36147e98b1904434b76712b296de7dd55dc95ca624c62d0ebd Report: filescan.io/uploads/68264d52… In total, I’ve uploaded 22 files to analysis websites. They came from two sets of 11 files that auto-downloaded from the TikTok Seller website. All of the files were located in the same IndexedDB folder. One file in each set was flagged as a Trojan: file 7 from the first set and file 8 from the second. These detections occurred on separate laptops. File 7 auto-downloaded multiple times on both my work computer and a spare computer that I hadn’t used in years. I fully updated the spare computer before using it to upload the files to analysis websites. File 7 was identified as a Trojan several times using Google Chrome, and file 8 was identified as a Trojan using Microsoft Edge while running traces and a screen recording for Kaspersky. Here are all the hashes from both sets: 🚩 File 7 Detection: File: a SHA-256:fd4bc9b7d765929a36d49aabd2b7b809419b08b7964f890a9c56cc47eb4aaa00 File: b SHA-256:7837e04be61ed8aa047f18a6f0fab961df831486d5171e00862bd4c4bfdee463 File: c SHA-256:1a8b473ea7c8139c85cd21e74d3b7f1c7f1d500d791c69fe01fa5e3200d534c0 File: 2 SHA-256:7da7de149ac97a5305d82417020dde9cf43eb04394def20abf03c39cef86c11b File: 3 SHA-256:868df3dc1fe671790e1511e0d1aabb148e2fc15d5addb44af46ecc94eb082e1c File: 4 SHA-256:c08a231039ccc18f97a87f95e3d150ca74e8bd896b4d400922e9f773fbff1b7c File: 5 SHA-256:6ab2820513708ea96f22dc8d040853e20228c41516d9b3085e51d3fb3f8cb29c File: 6 SHA-256:7bca7fe838f17ed6f5ee0071cdd7fc24fc246fd1e74182a2198c2c95ea2c847f File: 7 (Trojan) SHA-256:c026d2ae1d2439cc7200d0085b955cb0b8a53a80bf9c9585daac129041c4e716 File: 8 SHA-256:cecbcc5ca9be1c81d31875fc841a8f98a5d96490345e9c7f50b0df57851e8445 File: 9 SHA-256:6d5b4e6c24c52cb3cf59f165a5d591d7ce19757fad66f6863917079a1d960e09 ➡️ Hybrid Analysis Collection: hybrid-analysis.com/file-col… 🚩 File 8 Detection: File: a SHA-256: 27ba4d61c5cc66e6aa44f8c5833dd852c84c13b8d5cce91fab1a5bdbb1af23d3 File: b SHA-256: f66f910a7a1d524e3fa59671b153ef853dffc788a74229164cb6268c419e525a File: c SHA-256: a4cbb4c983e8cccc7c8e59a45e9bb4930d496ce90ccc62ac48da1d9fc16eb315 File: 2 (YARA Match: Valid Bitcoin address detected) SHA-256: c08a231039ccc18f97a87f95e3d150ca74e8bd896b4d400922e9f773fbff1b7c File: 3 SHA-256: 7bca7fe838f17ed6f5ee0071cdd7fc24fc246fd1e74182a2198c2c95ea2c847f File: 4 SHA-256: 6ab2820513708ea96f22dc8d040853e20228c41516d9b3085e51d3fb3f8cb29c File: 5 SHA-256: 3870b0e775c2eb868efc062e5a33c187265ca6616ddbe50dd7421baca3ad0f43 File: 6 SHA-256: fd4bc9b7d765929a36d49aabd2b7b809419b08b7964f890a9c56cc47eb4aaa00 File: 7 SHA-256: dd2f1ae3942d4ea1a78de292220134d23ec52fbcab1ca6f736714750a76dcf22 File: 8 (Trojan, Anti-VM) SHA-256: 8a333b62d5c4580137ccd33ebbecb65b6fae4c45c78007c3becdef6beb95e067 File: 9 SHA-256: f977f1f35f4cc915d93c583804aea111402026629b26d01b28430bcc3eaad98d ➡️ Hybrid Analysis Collection: hybrid-analysis.com/file-col…
1
5
971
6 Jun 2025
VirusTotal Analysis: http://seller-us.tiktok[.]com 🔗 Behavior Report: virustotal.com/gui/file/37ae… Body SHA-256: 37ae20a09e8b52224131235733b87da02f2be09155767ebe0b04fa8c0d146b4f
4
203
1 Mar 2025
The final URL for titkok[.]com and iktok[.]com sometimes resolves to survey-smiles[.]com, which appears to be malicious. It's worth noting that tikok[.]com and titok[.]com share some of the same IPs, which might suggest they are related. I initially encountered iktok[.]com while analyzing http://tiktok[.]com with filescan.io. OSINT detected iktok as a malicious resource: filescan.io/uploads/6754c249… I discovered titkok[.]com within four files, (hashes below) which automatically downloaded from the official TikTok seller US website upon login: • 1a8b473ea7c8139c85cd21e74d3b7f1c7f1d500d791c69fe01fa5e3200d534c0 • dd2f1ae3942d4ea1a78de292220134d23ec52fbcab1ca6f736714750a76dcf22 • f977f1f35f4cc915d93c583804aea111402026629b26d01b28430bcc3eaad98d • 6d5b4e6c24c52cb3cf59f165a5d591d7ce19757fad66f6863917079a1d960e09 Hybrid Analysis shows these domains exhibit varied redirection behavior, for instance: • titkok[.]com redirected to oduwow[.]com then digitdsk[.]xyz: hybrid-analysis.com/sample/2… VirusTotal 1/94 detections: virustotal.com/gui/domain/ti… • iktok[.]com redirected to mcafee[.]com: hybrid-analysis.com/sample/6… VirusTotal 8/94 detections: virustotal.com/gui/domain/ik… • tikok[.]com redirected to https://getstarted.tiktok[.]com: hybrid-analysis.com/sample/e… • and during this analysis, tikok[.]com redirected to https://www.totalav[.]com: hybrid-analysis.com/sample/e… VirusTotal 2/94 detections: virustotal.com/gui/domain/ti…
21 Jan 2025
Some of the files that auto-downloded from TikTok Seller website contain titkok domain: virustotal.com/gui/domain/ti… 🚫 Do not visit this website. It’s related to survey-smiles which appears to be malicious: virustotal.com/gui/domain/su…
3
4
4,906
30 May 2025
Serving IP for survey-smiles confirmed by @SarlackLab as a #LokiBot C2: 199.59.243[.]228:80
29 May 2025
#lokibot #C2 server 199.59.243[.]228:80 confirmed 2025-05-29
1
2
593
17 May 2025
Filescan.io Analysis Report: http://seller-us[.]tiktok[.]com SHA-256: 57d049d73eb0dd36147e98b1904434b76712b296de7dd55dc95ca624c62d0ebd Report: filescan.io/uploads/68264d52… In total, I’ve uploaded 22 files to analysis websites. They came from two sets of 11 files that auto-downloaded from the TikTok Seller website. All of the files were located in the same IndexedDB folder. One file in each set was flagged as a Trojan: file 7 from the first set and file 8 from the second. These detections occurred on separate laptops. File 7 auto-downloaded multiple times on both my work computer and a spare computer that I hadn’t used in years. I fully updated the spare computer before using it to upload the files to analysis websites. File 7 was identified as a Trojan several times using Google Chrome, and file 8 was identified as a Trojan using Microsoft Edge while running traces and a screen recording for Kaspersky. Here are all the hashes from both sets: 🚩 File 7 Detection: File: a SHA-256:fd4bc9b7d765929a36d49aabd2b7b809419b08b7964f890a9c56cc47eb4aaa00 File: b SHA-256:7837e04be61ed8aa047f18a6f0fab961df831486d5171e00862bd4c4bfdee463 File: c SHA-256:1a8b473ea7c8139c85cd21e74d3b7f1c7f1d500d791c69fe01fa5e3200d534c0 File: 2 SHA-256:7da7de149ac97a5305d82417020dde9cf43eb04394def20abf03c39cef86c11b File: 3 SHA-256:868df3dc1fe671790e1511e0d1aabb148e2fc15d5addb44af46ecc94eb082e1c File: 4 SHA-256:c08a231039ccc18f97a87f95e3d150ca74e8bd896b4d400922e9f773fbff1b7c File: 5 SHA-256:6ab2820513708ea96f22dc8d040853e20228c41516d9b3085e51d3fb3f8cb29c File: 6 SHA-256:7bca7fe838f17ed6f5ee0071cdd7fc24fc246fd1e74182a2198c2c95ea2c847f File: 7 (Trojan) SHA-256:c026d2ae1d2439cc7200d0085b955cb0b8a53a80bf9c9585daac129041c4e716 File: 8 SHA-256:cecbcc5ca9be1c81d31875fc841a8f98a5d96490345e9c7f50b0df57851e8445 File: 9 SHA-256:6d5b4e6c24c52cb3cf59f165a5d591d7ce19757fad66f6863917079a1d960e09 ➡️ Hybrid Analysis Collection: hybrid-analysis.com/file-col… 🚩 File 8 Detection: File: a SHA-256: 27ba4d61c5cc66e6aa44f8c5833dd852c84c13b8d5cce91fab1a5bdbb1af23d3 File: b SHA-256: f66f910a7a1d524e3fa59671b153ef853dffc788a74229164cb6268c419e525a File: c SHA-256: a4cbb4c983e8cccc7c8e59a45e9bb4930d496ce90ccc62ac48da1d9fc16eb315 File: 2 (YARA Match: Valid Bitcoin address detected) SHA-256: c08a231039ccc18f97a87f95e3d150ca74e8bd896b4d400922e9f773fbff1b7c File: 3 SHA-256: 7bca7fe838f17ed6f5ee0071cdd7fc24fc246fd1e74182a2198c2c95ea2c847f File: 4 SHA-256: 6ab2820513708ea96f22dc8d040853e20228c41516d9b3085e51d3fb3f8cb29c File: 5 SHA-256: 3870b0e775c2eb868efc062e5a33c187265ca6616ddbe50dd7421baca3ad0f43 File: 6 SHA-256: fd4bc9b7d765929a36d49aabd2b7b809419b08b7964f890a9c56cc47eb4aaa00 File: 7 SHA-256: dd2f1ae3942d4ea1a78de292220134d23ec52fbcab1ca6f736714750a76dcf22 File: 8 (Trojan, Anti-VM) SHA-256: 8a333b62d5c4580137ccd33ebbecb65b6fae4c45c78007c3becdef6beb95e067 File: 9 SHA-256: f977f1f35f4cc915d93c583804aea111402026629b26d01b28430bcc3eaad98d ➡️ Hybrid Analysis Collection: hybrid-analysis.com/file-col…
2
3
2,067
27 May 2025
Filescan.io Analysis Report: http://seller-us-accounts[.]tiktok[.]com SHA-256: 92f0f82b094e7c7523d4b734ef787c8d9bc2000f4e199e484e965eb8f1267400 Report: filescan.io/uploads/6834b311…
1
254
9 May 2025
File 7, which auto-downloaded from TikTok Seller and was detected by Kaspersky as a Trojan, was recently executed in VirusTotal’s sandbox: virustotal.com/gui/file/c026… Hash: c026d2ae1d2439cc7200d0085b955cb0b8a53a80bf9c9585daac129041c4e716
2
1,101
21 Apr 2025
I know I’ve been alerting the public about a Trojan auto-downloading from the TikTok Seller website for almost 10 months now. 🤦🏻‍♀️ For context, Kaspersky detected a Trojan after I logged in. I later discovered 10 other .blob files in the same IndexedDB folder that went undetected and eventually disappeared. I reported this issue to TikTok, Kaspersky, and Microsoft right away. The TikTok Seller rep I chatted with at the time said the Trojan was alarming, which made me even more alarmed. They opened a case and said I’d get an email, but I never did. I found two support emails and sent more evidence to TikTok, still no reply. So I filed a BBB claim. TikTok responded only to say they do not support this type of request through the BBB and that I should use their in-app support. I explained that I didn’t feel safe logging into their app or website. They basically repeated the same message, and the BBB closed my claim. I also shared the issue on TikTok’s official Reddit page, and they banned me. As for Kaspersky, they asked me to run traces and a screen recording. I did, but after saving them, I couldn’t open or upload the zip file. I didn’t know why at the time, so I emailed Kaspersky about it and told them that file 8 was detected this time. (not 7) Later, my laptop made a loud noise, and I saw “High Data Usage” for the first time ever. When I tried to scroll toward it, my mouse froze. Thinking my computer might be compromised, I shut it down and removed the battery. I updated Kaspersky, and when they finally responded, they told me to upload the trace files and screen recording to their portal along with file 8, which wasn’t helpful considering the situation. Not long after, news broke that Kaspersky was being banned in the U.S., and I was advised not to trust them. During this time, someone I know at Microsoft’s MSRC reached out. They found the information and code interesting enough to investigate, so they submitted it for analysis, and asked me to connect to a VM for them. I didn’t hear back for months, and now I’m told they’re still skeptical, but also can’t confirm it’s a false positive. I was told that I need to decode the code and show factual, reproducible evidence, but the thing is, I’m not a researcher, I’m just a user. But I’ve gathered concerning indicators using analysis tools, and that should be enough to warrant investigation, especially considering the platform involved. I was also advised to reach out to HackerOne or a bug bounty hunter. But I’m not in this for a bounty. I’m not trying to prove myself as a security researcher. I’m just a deeply concerned user reporting what appears to be an undetected Trojan that auto-downloads after logging into the TikTok Seller US website. I don’t know if the issue has been quietly resolved, but it still hasn’t been publicly acknowledged or confirmed to be a false positive, and that makes me uneasy. Someone even commented over a month ago that it looks like I was part of a botnet for laundering. I can’t prove that, but if true, it’s hard to believe I’m the only one affected by it. From my point of view, this is most likely malware. But if it’s not, I welcome anyone who can help confirm it’s a false positive. Either way, I appreciate you for hearing me out. Even if you’re skeptical, I understand. But cybersecurity is a collaboration, and I’m asking for your help, not just for one user, but for all who could be affected if this is actually malware or part of a botnet.
1
3
1,791
16 Apr 2025
🚩 File 9, one of 11 .blob files that auto-downloaded after logging into the @tiktok_us Seller website, dropped a dangerous file, ~WRD0002.doc. Hybrid Analysis report from April 6, 2025, shows the most indicators I’ve seen yet, 101 total, including spyware, encryption, network activity, persistence, and evasion. Both files scored 50/100 but were marked clean by antivirus scans, suggesting possible evasion of standard security tools. ~WRD0002.doc (SHA256: bba92ee4de0f4db3d3a8d503ad2a019dfb70132944c4f54f901901dfe2fe72fa): hybrid-analysis.com/sample/b… File 9 (SHA256: 6d5b4e6c24c52cb3cf59f165a5d591d7ce19757fad66f6863917079a1d960e09): hybrid-analysis.com/sample/6…
3
957
24 Mar 2025
March 23, 2025 @filescan_itsec report on https://www1[.]survey-smiles[.]com/bIlhWoeSp.js flags https://analytics[.]tiktok[.]com/i18n/pixel/events.js as an IOC. 🔗 filescan.io/uploads/67e0a4d0…
1 Mar 2025
The final URL for titkok[.]com and iktok[.]com sometimes resolves to survey-smiles[.]com, which appears to be malicious. It's worth noting that tikok[.]com and titok[.]com share some of the same IPs, which might suggest they are related. I initially encountered iktok[.]com while analyzing http://tiktok[.]com with filescan.io. OSINT detected iktok as a malicious resource: filescan.io/uploads/6754c249… I discovered titkok[.]com within four files, (hashes below) which automatically downloaded from the official TikTok seller US website upon login: • 1a8b473ea7c8139c85cd21e74d3b7f1c7f1d500d791c69fe01fa5e3200d534c0 • dd2f1ae3942d4ea1a78de292220134d23ec52fbcab1ca6f736714750a76dcf22 • f977f1f35f4cc915d93c583804aea111402026629b26d01b28430bcc3eaad98d • 6d5b4e6c24c52cb3cf59f165a5d591d7ce19757fad66f6863917079a1d960e09 Hybrid Analysis shows these domains exhibit varied redirection behavior, for instance: • titkok[.]com redirected to oduwow[.]com then digitdsk[.]xyz: hybrid-analysis.com/sample/2… VirusTotal 1/94 detections: virustotal.com/gui/domain/ti… • iktok[.]com redirected to mcafee[.]com: hybrid-analysis.com/sample/6… VirusTotal 8/94 detections: virustotal.com/gui/domain/ik… • tikok[.]com redirected to https://getstarted.tiktok[.]com: hybrid-analysis.com/sample/e… • and during this analysis, tikok[.]com redirected to https://www.totalav[.]com: hybrid-analysis.com/sample/e… VirusTotal 2/94 detections: virustotal.com/gui/domain/ti…
2
1,405
21 Mar 2025
dnssense.com/post/dnssense-h… The article from DNSSense, published on November 12, 2023, and titled “DNSSense has discovered a new type of malicious domain that no other security vendor has yet detected,” delves into the company’s groundbreaking identification of a previously undetected variant of the “Survey-smiles[.]com” malware, a notorious threat that hijacks web browsers by redirecting users to “http://www1.survey-smiles[.]com/” whenever they use the address bar on a new webpage, persisting even with browser add-ons disabled. While most security vendors can block the known Survey-smiles[.]com domain, DNSSense’s AI-powered tool, Cyber X-Ray, uncovered a new evolution of this attack linked to over 650,000 domains, distinguished by their ability to redirect users to varying addresses on each visit and return a “Status Code 400 (Bad Request Error)” with a “survey-smiles[.]com” endpoint when subjected to a HEAD request—traits that had evaded other detection systems. Cyber X-Ray’s innovative, association-based approach analyzes hundreds of security features across internet assets like domains, IPs, and SSL certificates to spot patterns of malicious behavior, setting it apart from traditional blacklist-reliant tools and enabling this unique discovery. The article also highlights a broader trend observed by Cyber X-Ray: a near-100% surge in malicious “[.]ru” (Russia) and “[.]ua” (Ukraine) domains over the prior three months, signaling a rising cyber threat landscape. DNSSense positions this finding as evidence of the limitations of conventional defenses against evolving threats, advocating for proactive, AI-driven solutions like theirs to bolster organizational cybersecurity. By detailing this case, the article not only warns of the adaptability of malware like Survey-smiles[.]com but also underscores DNSSense’s leadership in DNS security, suggesting that their technology fills critical gaps left by other vendors as of November 2023.
2
378