Temu icon

base.apk

Temu

40.71 MB

Analyzed: 2026-05-17 17:48 UTC

APK Security & Privacy Score

Security scoring uses multi-engine scan signals and APK indicators. Privacy scoring uses requested permissions and network endpoint patterns.

Security Scan-weighted
99/100
Threat scan clean Modern target SDK
Privacy Permissions & network
75/100
HTTP URLs found Possible tracking
85/100
Good
Overall trust

Facts

Threat scan 0/75 flagged, 0 suspicious
Permissions 11 requested
Network strings 143 URLs (2 HTTP, 141 HTTPS)
Target SDK 35
Certificate Valid until 2047-08-06 (21 years, suspicious)

Warnings

Found 2 HTTP URL strings (unencrypted).
Possible analytics/tracking domains found: app-measurement.com, app.adjust.com, app.adjust.net.in, app.adjust.world, pagead2.googlesyndication.com
Package Name com.einnovation.temu
Version Code 45002
Version Name 4.50.1
Application Name com.baogong.WhaleCoApplication
Debuggable No
Allow Backup No
Min SDK Android 21 (Lollipop)
Target SDK Android 35 (Android 15)
Supported ABIs
Universal

Certificate & Signer

Valid From 2022-08-12 08:12:04
Valid To 2047-08-06 08:12:04
Serial Number 6eb80f8b
Thumbprint 2e0bf701b484205cd6bacae5bba5572e13214a60
Issuer: C 65
Issuer: CN whaleco
Issuer: DN C:65, CN:whaleco, L:Singapore, O:einnovation, ST:Singapore, OU:einnovation
Issuer: L Singapore
Issuer: O einnovation
Issuer: OU einnovation
Issuer: ST Singapore
Subject: C 65
Subject: CN whaleco
Subject: DN C:65, CN:whaleco, L:Singapore, O:einnovation, ST:Singapore, OU:einnovation
Subject: L Singapore
Subject: O einnovation
Subject: OU einnovation
Subject: ST Singapore

Security Scan

0 /75
✓ Clean
Scanned by 75 security vendors
Last scan: 2026-05-16 17:43 UTC
Malicious
0
Suspicious
0
Harmless
0
Undetected
59
Timeout
3
Failure
3

Scan Providers

75 vendors
ALYac failure
No result reported
Engine 2.0.0.10
APEX type-unsupported
No result reported
Engine 6.779
AVG undetected
No result reported
Engine 23.9.8494.0
Acronis undetected
No result reported
Engine 1.2.0.121
AhnLab-V3 undetected
No result reported
Engine 3.30.0.10666
Alibaba undetected
No result reported
Engine 0.3.0.5
Antiy-AVL undetected
No result reported
Engine 3.0
Arcabit undetected
No result reported
Engine 2025.0.0.23
Avast undetected
No result reported
Engine 23.9.8494.0
Avast-Mobile undetected
No result reported
Engine 260515-00
Avira undetected
No result reported
Engine 8.3.3.24
BitDefender undetected
No result reported
Engine 7.2
BitDefenderFalx undetected
No result reported
Engine 2.0.936
Bkav failure
No result reported
Engine 8.2.40(8338)
CAT-QuickHeal undetected
No result reported
Engine 22.00
CMC undetected
No result reported
Engine 2.4.2022.1
CTX undetected
No result reported
Engine 2024.8.29.1
ClamAV timeout
No result reported
Engine 1.5.2.0
CrowdStrike undetected
No result reported
Engine 1.0
Cylance type-unsupported
No result reported
Engine 3.0.0.0
Cynet type-unsupported
No result reported
Engine 4.0.3.4
DeepInstinct type-unsupported
No result reported
Engine 5.0.0.8
DrWeb undetected
No result reported
Engine 7.0.75.2070
ESET-NOD32 undetected
No result reported
Engine 18.2.18.0
Elastic type-unsupported
No result reported
Engine 4.0.261
Emsisoft undetected
No result reported
Engine 2024.8.0.61147
F-Secure undetected
No result reported
Engine 18.10.1547.307
Fortinet undetected
No result reported
Engine 7.0.30.0
GData undetected
No result reported
Engine GD:27.44567AVA:64.31256
Google undetected
No result reported
Engine 1778947250
Gridinsoft undetected
No result reported
Engine 1.0.245.174
Ikarus undetected
No result reported
Engine 6.4.16.0
Jiangmin undetected
No result reported
Engine 16.0.100
K7AntiVirus undetected
No result reported
Engine 14.52.59526
K7GW undetected
No result reported
Engine 14.52.59524
Kaspersky undetected
No result reported
Engine 22.0.1.28
Kingsoft undetected
No result reported
Engine None
Lionic undetected
No result reported
Engine 8.16
Malwarebytes undetected
No result reported
Engine 3.1.0.235
MaxSecure undetected
No result reported
Engine 1.0.0.1
McAfeeD undetected
No result reported
Engine 1.2.0.14532
MicroWorld-eScan undetected
No result reported
Engine 14.0.409.0
Microsoft undetected
No result reported
Engine 1.1.26030.3008
NANO-Antivirus undetected
No result reported
Engine 1.0.170.26895
Paloalto type-unsupported
No result reported
Engine 0.9.0.1003
Panda undetected
No result reported
Engine 4.6.4.2
Rising undetected
No result reported
Engine 25.0.0.28
SUPERAntiSpyware undetected
No result reported
Engine 5.6.0.1032
Sangfor undetected
No result reported
Engine 2.22.3.0
SentinelOne type-unsupported
No result reported
Engine 7.6.2.19
Skyhigh failure
No result reported
Sophos undetected
No result reported
Engine 3.5.1.0
Symantec undetected
No result reported
Engine 1.22.0.0
SymantecMobileInsight undetected
No result reported
Engine 2.0
TACHYON undetected
No result reported
Engine 2026-05-16.02
Tencent undetected
No result reported
Engine 1.0.0.1
Trapmine type-unsupported
No result reported
Engine 4.0.12.0
TrellixENS timeout
No result reported
Engine 6.0.6.653
TrendMicro undetected
No result reported
Engine 24.550.0.1002
TrendMicro-HouseCall undetected
No result reported
Engine 24.550.0.1002
Trustlook undetected
No result reported
Engine 1.0
VBA32 undetected
No result reported
Engine 5.6.1
VIPRE undetected
No result reported
Engine 6.0.0.35
Varist undetected
No result reported
Engine 6.6.1.3
ViRobot undetected
No result reported
Engine 2014.3.20.0
VirIT timeout
No result reported
Webroot undetected
No result reported
Engine 1.9.0.8
Xcitium undetected
No result reported
Engine 38652
Yandex undetected
No result reported
Engine 5.5.2.24
Zillya undetected
No result reported
Engine 2.0.0.5603
ZoneAlarm undetected
No result reported
Engine 6.24-114820956
Zoner undetected
No result reported
Engine 2.2.2.0
alibabacloud type-unsupported
No result reported
Engine 2.2.0
huorong undetected
No result reported
Engine 5fb5e6f:5fb5e6f:d24df83:d24df83
tehtris type-unsupported
No result reported

File Signatures

SHA-256 9576bf220933ef044fec562b72fccc0e2ec11f728f4f47e006ca623dbf2ce0ff
MD5 a34ad202f01bfede761ab2f9f9bab49f
SHA-1 836f62d8403c8f7d6b30388c13c2964e84724064
SSDEEP 393216:6eIfG5goQYR7xUweUiyfG2JyzgHgmQyaqmnT:6y/QYfeUEmQ3qmnT
TLSH T1E9973712BA22DE22D4BD87398CA6C3D27336BD45EF4753673206B76CAD732C5AE45180
VHASH ac224f4fbdae1624aa8a00d94b203f72
PERMHASH 065c56f0df528086d1332f68ad76fdf137e3d736bbbe13d7a9f91b98a4c920c7

File Intelligence

Type Description Android Human-friendly file type name based on multiple detection methods.
Type Extension apk Most likely file extension inferred from the content.
Type Tag android Primary type tag assigned by the classifier.
Type Tags executable, mobile, android, apk Additional type tags that describe the file content.
Magic Zip archive data, at least v0.0 to extract, compression method=deflate File signature result from magic bytes inspection.
Magika APK File type predicted by Magika (ML-based file type detection).
TrID Android Package (42.8%), Java Archive (21.4%), Sweet Home 3D Design (generic) (16.6%), Konfabulator widget (12.6%), ZIP compressed archive (6.3%) TrID file type guesses with probabilities.
dhash 00003c1c1e1e1500 Perceptual hash used to compare visual similarity of files.
raw md5 4b1ba9647c24f21e20ed44048f9b2084 Raw MD5 hash of the file contents.
extensions xml (915), png (62), dex (5), json (5), ttf (2), l0 (1), mp3 (1), pem (1), prof (1), profm (1), s (1), webp (1), zip (1) File extensions found inside the APK and how many of each.
file types XML (915), PNG (62), unknown (15), DEX (5), JSON (1), MP3 (1), ZIP (1) Detected embedded file types and their counts.
highest datetime 1981-01-01 01:01:02 UTC Latest timestamp found among files inside the archive.
lowest datetime 1981-01-01 01:01:02 UTC Earliest timestamp found among files inside the archive.
num children 2689 Number of files contained within the archive.
type APK Container type detected for the analyzed file.
uncompressed size 34 MB Estimated total size of all files after extraction.

Deep Manifest Analysis

Activity Intents (9)

com.baogong.activity.ContainerActivity
Actions
com.einnovation.whaleco.ACTION_CONTAINER_ACTIVITY com.einnovation.whaleco.ACTION_CONTAINER_ACTIVITY
Categories
android.intent.category.DEFAULT
com.baogong.app_push_permission.OtpReceiverActivity
Actions
com.whatsapp.otp.OTP_RETRIEVED com.whatsapp.otp.OTP_RETRIEVED
Categories
android.intent.category.DEFAULT
com.baogong.login.app_auth.activity.KakaoAuthCustomTabActivity
Actions
View Activity Action: Display the data to the user. android.intent.action.VIEW
Categories
android.intent.category.DEFAULT android.intent.category.BROWSABLE
com.baogong.login.app_auth.activity.LineAuthCallBackActivity
Actions
View Activity Action: Display the data to the user. android.intent.action.VIEW
android.support.customtabs.action.CustomTabsService android.support.customtabs.action.CustomTabsService
Categories
android.intent.category.DEFAULT android.intent.category.BROWSABLE
com.baogong.login.app_auth.activity.TwitterAuthCustomTabActivity
Actions
View Activity Action: Display the data to the user. android.intent.action.VIEW
Categories
android.intent.category.DEFAULT android.intent.category.BROWSABLE
com.baogong.splash.activity.MainFrameActivity
Actions
Main Activity Action: Start as a main entry point, does not expect to android.intent.action.MAIN
View Activity Action: Display the data to the user. android.intent.action.VIEW
Send Activity Action: Deliver some data to someone else. android.intent.action.SEND
Categories
android.intent.category.LAUNCHER android.intent.category.DEFAULT android.intent.category.BROWSABLE
com.braintreepayments.api.BraintreeDeepLinkActivity
Actions
View Activity Action: Display the data to the user. android.intent.action.VIEW
Categories
android.intent.category.DEFAULT android.intent.category.BROWSABLE
com.einnovation.whaleco.pay.auth.braintree.BraintreeCallbackActivity
Actions
View Activity Action: Display the data to the user. android.intent.action.VIEW
Categories
android.intent.category.DEFAULT android.intent.category.BROWSABLE
com.facebook.CustomTabActivity
Actions
View Activity Action: Display the data to the user. android.intent.action.VIEW
Categories
android.intent.category.DEFAULT android.intent.category.BROWSABLE

Service Intents (2)

com.baogong.push.WhaleCoFirebaseMessagingService
Actions
Firebase messaging event Action used by Firebase to deliver a push message to the app. com.google.firebase.MESSAGING_EVENT
Firebase messaging service Handles push notifications and data messages from Firebase Cloud Messaging. com.google.firebase.messaging.FirebaseMessagingService
Actions
Firebase messaging event Action used by Firebase to deliver a push message to the app. com.google.firebase.MESSAGING_EVENT

Receiver Intents (10)

com.baogong.app_push_permission.OtpErrReceiver
Actions
com.whatsapp.otp.OTP_ERROR com.whatsapp.otp.OTP_ERROR
com.baogong.app_push_permission.OtpReceiver
Actions
com.whatsapp.otp.OTP_RETRIEVED com.whatsapp.otp.OTP_RETRIEVED
com.baogong.app_shortcuts.LocaleChangedReceiver
Actions
Locale Changed Broadcast Action: The current device's locale has changed. android.intent.action.LOCALE_CHANGED
com.baogong.widget.provider.FarmlandWidget
Actions
android.appwidget.action.APPWIDGET_UPDATE android.appwidget.action.APPWIDGET_UPDATE
com.baogong.widget.provider.FishlandWidget
Actions
android.appwidget.action.APPWIDGET_UPDATE android.appwidget.action.APPWIDGET_UPDATE
com.facebook.AuthenticationTokenManager$CurrentAuthenticationTokenChangedBroadcastReceiver
Actions
com.facebook.sdk.ACTION_CURRENT_AUTHENTICATION_TOKEN_CHANGED com.facebook.sdk.ACTION_CURRENT_AUTHENTICATION_TOKEN_CHANGED
com.facebook.CurrentAccessTokenExpirationBroadcastReceiver
Actions
com.facebook.sdk.ACTION_CURRENT_ACCESS_TOKEN_CHANGED com.facebook.sdk.ACTION_CURRENT_ACCESS_TOKEN_CHANGED
com.google.firebase.iid.FirebaseInstanceIdReceiver
Actions
com.google.android.c2dm.intent.RECEIVE com.google.android.c2dm.intent.RECEIVE
com.whaleco.widget.logistics.LogisticsWidgetProvider
Actions
android.appwidget.action.APPWIDGET_UPDATE android.appwidget.action.APPWIDGET_UPDATE
com.whaleco.widget.search.SearchWidgetProvider
Actions
android.appwidget.action.APPWIDGET_UPDATE android.appwidget.action.APPWIDGET_UPDATE

Requested Permissions (11)

have full network access Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. android.permission.INTERNET
view Wi-Fi connections Allows the app to view information about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices. android.permission.ACCESS_WIFI_STATE
view network connections Allows the app to view information about network connections such as which networks exist and are connected. android.permission.ACCESS_NETWORK_STATE
control vibration Allows the app to control the vibrator. android.permission.VIBRATE
keep car screen turned on Allows the app to keep the car screen turned on. android.permission.WAKE_LOCK
com.google.android.gms.permission.AD_ID Custom app or vendor permission (not publicly documented). com.google.android.gms.permission.AD_ID
Install Referrer service Allows Google Play to bind to the app's Install Referrer service for install attribution. com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE
android.permission.POST_NOTIFICATIONS Custom app or vendor permission (not publicly documented). android.permission.POST_NOTIFICATIONS
Cloud messaging receive Allows the app to receive push messages via Google/Firebase Cloud Messaging. com.google.android.c2dm.permission.RECEIVE
access approximate location only in the foreground This app can get your approximate location from location services while the app is in use. Location services for your device must be turned on for the app to get location. android.permission.ACCESS_COARSE_LOCATION
access precise location only in the foreground This app can get your precise location from location services while the app is in use. Location services for your device must be turned on for the app to get location. This may increase battery usage. android.permission.ACCESS_FINE_LOCATION

Uses Features (11)

Bluetooth Feature for {@link #getSystemAvailableFeatures} and android.hardware.bluetooth
Camera Feature for {@link #getSystemAvailableFeatures} and android.hardware.camera
Camera Autofocus Feature for {@link #getSystemAvailableFeatures} and android.hardware.camera.autofocus
Location Feature for {@link #getSystemAvailableFeatures} and android.hardware.location
Location Gps Feature for {@link #getSystemAvailableFeatures} and android.hardware.location.gps
Location Network Feature for {@link #getSystemAvailableFeatures} and android.hardware.location.network
Microphone Feature for {@link #getSystemAvailableFeatures} and android.hardware.microphone
Screen Portrait Feature for {@link #getSystemAvailableFeatures} and android.hardware.screen.portrait
Touchscreen Feature for {@link #getSystemAvailableFeatures} and android.hardware.touchscreen
Wifi Feature for {@link #getSystemAvailableFeatures} and android.hardware.wifi
Leanback Feature for {@link #getSystemAvailableFeatures} and android.software.leanback

Activities (27)

com.einnovation.temu.pay.impl.base.container.PaymentContainerActivity
com.baogong.activity.ContainerActivity
com.baogong.activity.ContainerSplitActivity
com.baogong.activity.ContainerMaskActivity
com.baogong.activity.SplitHolderActivity
com.baogong.app_login.LoginActivity
com.facebook.FacebookActivity
com.facebook.CustomTabActivity
com.baogong.login.app_auth.activity.KakaoAuthCustomTabActivity
com.baogong.login.app_auth.activity.TwitterAuthCustomTabActivity
com.baogong.login.app_auth.activity.LineAuthResolverActivity
com.baogong.login.app_auth.activity.LineAuthCallBackActivity
com.baogong.app_push_permission.OtpReceiverActivity
com.baogong.splash.activity.MainFrameActivity
com.einnovation.whaleco.pay.auth.base.PaymentSdkActivity
com.einnovation.whaleco.pay.auth.braintree.BraintreeCallbackActivity
androidx.credentials.playservices.HiddenActivity
androidx.credentials.playservices.IdentityCredentialApiHiddenActivity
com.braintreepayments.api.BraintreeDeepLinkActivity
com.braintreepayments.api.GooglePayActivity
com.facebook.CustomTabMainActivity
com.google.android.gms.auth.api.signin.internal.SignInHubActivity
com.google.android.gms.common.api.GoogleApiActivity
com.google.android.play.core.common.PlayCoreDialogWrapperActivity
com.baogong.home.activity.LauncherActivity
com.whaleco.web_container.customtab_browser.BrowserCustomTabActivity
com.whaleco.safemode.strategy.FailSafeActivity

Services (38)

androidx.room.MultiInstanceInvalidationService
androidx.credentials.playservices.CredentialProviderMetadataHolder
com.baogong.push.WhaleCoFirebaseMessagingService
com.google.firebase.components.ComponentDiscoveryService
com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService
com.einnovation.temu.work.impl.background.SystemJobService
com.google.android.gms.auth.api.signin.RevocationBoundService
com.google.android.gms.measurement.AppMeasurementService
com.google.android.gms.measurement.AppMeasurementJobService
Firebase messaging service Handles push notifications and data messages from Firebase Cloud Messaging. com.google.firebase.messaging.FirebaseMessagingService
com.whaleco.apm.crash.CrashReportIntentService
com.whaleco.apm.helper.MainDaemonService
com.whaleco.apm.helper.PushHelpService
com.whaleco.ipc_adapter.service.MainProcessIPCService
com.whaleco.ipc_adapter.service.LongLinkProcessIPCService
com.whaleco.net_push.service.PushService
com.whaleco.safemode.FailSafeService
org.chromium.content.app.PrivilegedProcessService0
org.chromium.content.app.PrivilegedProcessService1
org.chromium.content.app.PrivilegedProcessService2
org.chromium.content.app.PrivilegedProcessService3
org.chromium.content.app.PrivilegedProcessService4
org.chromium.content.app.PrivilegedProcessService5
org.chromium.content.app.PrivilegedProcessService6
org.chromium.content.app.PrivilegedProcessService7
org.chromium.content.app.PrivilegedProcessService8
org.chromium.content.app.PrivilegedProcessService9
org.chromium.content.app.PrivilegedProcessServiceFallback0
org.chromium.content.app.PrivilegedProcessServiceFallback1
org.chromium.content.app.PrivilegedProcessServiceFallback2
org.chromium.content.app.PrivilegedProcessServiceFallback3
org.chromium.content.app.PrivilegedProcessServiceFallback4
org.chromium.content.app.PrivilegedProcessServiceFallback5
org.chromium.content.app.PrivilegedProcessServiceFallback6
org.chromium.content.app.PrivilegedProcessServiceFallback7
org.chromium.content.app.PrivilegedProcessServiceFallback8
org.chromium.content.app.PrivilegedProcessServiceFallback9

Broadcast Receivers (14)

com.baogong.app_baog_share.ShareAppChooserReceiver com.baogong.app_baog_share.ShareAppChooserReceiver
com.baogong.app_push_permission.OtpReceiver com.baogong.app_push_permission.OtpReceiver
com.baogong.app_push_permission.OtpErrReceiver com.baogong.app_push_permission.OtpErrReceiver
com.baogong.app_shortcuts.LocaleChangedReceiver com.baogong.app_shortcuts.LocaleChangedReceiver
com.baogong.widget.provider.FarmlandWidget com.baogong.widget.provider.FarmlandWidget
com.baogong.widget.provider.FishlandWidget com.baogong.widget.provider.FishlandWidget
com.google.firebase.iid.FirebaseInstanceIdReceiver com.google.firebase.iid.FirebaseInstanceIdReceiver
com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver
com.baogong.push.DeleteNotificationReceiver com.baogong.push.DeleteNotificationReceiver
com.facebook.CurrentAccessTokenExpirationBroadcastReceiver com.facebook.CurrentAccessTokenExpirationBroadcastReceiver
com.facebook.AuthenticationTokenManager$CurrentAuthenticationTokenChangedBroadcastReceiver com.facebook.AuthenticationTokenManager$CurrentAuthenticationTokenChangedBroadcastReceiver
com.google.android.gms.measurement.AppMeasurementReceiver com.google.android.gms.measurement.AppMeasurementReceiver
com.whaleco.widget.search.SearchWidgetProvider com.whaleco.widget.search.SearchWidgetProvider
com.whaleco.widget.logistics.LogisticsWidgetProvider com.whaleco.widget.logistics.LogisticsWidgetProvider

Content Providers (4)

com.facebook.FacebookContentProvider
com.baogong.app_base_user.auth.AuthNotifyProvider
com.facebook.internal.FacebookInitProvider
com.whaleco.temu.fileprovider.BGFileProvider

URL Endpoints (149)

http://apache.org/xml/features/disallow-doctype-decl http://otter http://xml.org/sax/features/external-general-entities http://xml.org/sax/features/external-parameter-entities http://xml.org/sax/features/namespaces https://#SID#.cdn4.forter.com/mob/v3/#SID#/prop.json?t=#TS#&s=#BS#&u=#UID#&r=#RT#&seed=#SEED#&bn=#BNUMBER# https://.facebook.com https://accounts.google.com/o/oauth2/revoke?token= https://aimg.kwcdn.com/material-put/1e1918bb488/1564679f-37f7-4efd-a278-d645e8ac5546.png https://aimg.kwcdn.com/material-put/1e1918bb488/1aa1de1b-3050-4528-9b50-f4a93d06c056.png https://aimg.kwcdn.com/material-put/1e1918bb488/7c77285c-813e-430f-9a75-376bee1765e9.png https://aimg.kwcdn.com/material-put/1e1918bb488/aa287bfb-95e0-4430-a8db-a56328623b64.png https://aimg.kwcdn.com/material-put/1e1918bb488/b922785d-e97d-4dc3-9b93-78779ca7757b.png https://aimg.kwcdn.com/material-put/1e1918bb488/e05f145f-dd68-4b7d-a934-62509cc3c7da.png https://aimg.kwcdn.com/material-put/1e1918bb488/ecb88dc1-5535-4205-b7b1-c07f981ae65f.png https://aimg.kwcdn.com/material-put/1e1918bb488/fefa4ff9-3b6f-452c-90ab-5762e365575a.png https://aimg.kwcdn.com/shark-push/2019505e764/f98240e0-4f5f-49d0-bd4a-a4dbfc608b3e_72x32.png https://aimg.kwcdn.com/upload_aimg/address/1752da7d-33e5-4aeb-bafb-564215ddb1bb.png https://aimg.kwcdn.com/upload_aimg/address/1e3b49be-aa33-4456-a553-41d121922206.png https://aimg.kwcdn.com/upload_aimg/address/a679be6c-80a8-4582-b92b-4e61fb2865ce.png

Submission Details

Submitted At 2026-05-17
First Submission 2026-05-17
Last Submission 2026-05-17
Stored Until 2026-06-16