File name:

tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe

Full analysis: https://app.any.run/tasks/e0438616-b5db-47d0-9387-682090a422db
Verdict: Malicious activity
Analysis date: February 02, 2026, 09:32:27
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto
generic
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

C3B3A4B7AB65D615DE9BA8C15E4F89C1

SHA1:

5A14336B835ECAEB94DCA70732FB67150431B764

SHA256:

37AE7A2416F72E6EC7309515B090162D19F315326A3C7E768E5FFE7DC0DA8AC9

SSDEEP:

98304:BU49BpfNOL0IZNiGzFc4x0FwrkklxxeGkMu7GPR4i+1Sb6Ieexk7eLSTDdlsru2L:WtAwY9wAK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • GENERIC has been found (auto)

      • app_package_d_8e3aaa439e.exe (PID: 9184)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe (PID: 5048)
      • app_package_d_8e3aaa439e.exe (PID: 9184)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe (PID: 5048)
      • app_package_d_8e3aaa439e.exe (PID: 9184)
    • Executable content was dropped or overwritten

      • tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe (PID: 5048)
      • app_package_d_8e3aaa439e.exe (PID: 9184)
    • Process drops legitimate windows executable

      • app_package_d_8e3aaa439e.exe (PID: 9184)
    • The process drops C-runtime libraries

      • app_package_d_8e3aaa439e.exe (PID: 9184)
  • INFO

    • Checks supported languages

      • tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe (PID: 5048)
      • app_package_d_8e3aaa439e.exe (PID: 9184)
    • Creates files in the program directory

      • tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe (PID: 5048)
      • app_package_d_8e3aaa439e.exe (PID: 9184)
    • Create files in a temporary directory

      • tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe (PID: 5048)
      • app_package_d_8e3aaa439e.exe (PID: 9184)
    • Reads the computer name

      • tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe (PID: 5048)
      • app_package_d_8e3aaa439e.exe (PID: 9184)
    • Creates files or folders in the user directory

      • tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe (PID: 5048)
    • The sample compiled with english language support

      • tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe (PID: 5048)
      • app_package_d_8e3aaa439e.exe (PID: 9184)
    • There is functionality for taking screenshot (YARA)

      • app_package_d_8e3aaa439e.exe (PID: 9184)
      • tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe (PID: 5048)
    • The sample compiled with chinese language support

      • app_package_d_8e3aaa439e.exe (PID: 9184)
    • Drops script file

      • app_package_d_8e3aaa439e.exe (PID: 9184)
    • Checks proxy server information

      • slui.exe (PID: 8428)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:15 22:26:14+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 473088
UninitializedDataSize: 16384
EntryPoint: 0x338f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
151
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start tiktok_live_studio_downloader-v0.0.1-wid-93a8avl6nug.exe #GENERIC app_package_d_8e3aaa439e.exe slui.exe tiktok_live_studio_downloader-v0.0.1-wid-93a8avl6nug.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
5048"C:\Users\admin\AppData\Local\Temp\tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe" C:\Users\admin\AppData\Local\Temp\tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\tiktok_live_studio_downloader-v0.0.1-wid-93a8avl6nug.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
8428C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
8508"C:\Users\admin\AppData\Local\Temp\tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe" C:\Users\admin\AppData\Local\Temp\tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\tiktok_live_studio_downloader-v0.0.1-wid-93a8avl6nug.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
9184"C:\Users\admin\AppData\Local\app_shell_cache_d_8311\app_package_d_8e3aaa439e.exe" /S /D="C:\Program Files\TikTok LIVE Studio"C:\Users\admin\AppData\Local\app_shell_cache_d_8311\app_package_d_8e3aaa439e.exe
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe
User:
admin
Company:
TikTok Pte. Ltd.
Integrity Level:
HIGH
Version:
1.12.0
Modules
Images
c:\users\admin\appdata\local\app_shell_cache_d_8311\app_package_d_8e3aaa439e.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
4 414
Read events
4 407
Write events
7
Delete events
0

Modification events

(PID) Process:(5048) tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exeKey:HKEY_CURRENT_USER\SOFTWARE\tiktoklivestudio
Operation:writeName:PresetInstallDir
Value:
C:\Program Files\TikTok LIVE Studio
(PID) Process:(5048) tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exeKey:HKEY_CURRENT_USER\SOFTWARE\tiktoklivestudio
Operation:writeName:PresetShortcut
Value:
1
(PID) Process:(5048) tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exeKey:HKEY_CURRENT_USER\SOFTWARE\tiktoklivestudio
Operation:writeName:PresetChannelID
Value:
webapp
(PID) Process:(5048) tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exeKey:HKEY_CURRENT_USER\SOFTWARE\tiktoklivestudio
Operation:writeName:PresetWid
Value:
7602196066511635990
(PID) Process:(5048) tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exeKey:HKEY_CURRENT_USER\SOFTWARE\tiktoklivestudio
Operation:writeName:PresetAdTrack
Value:
v0.0.1-wid-93A8AVl6nUG
(PID) Process:(5048) tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\tiktoklivestudio
Operation:writeName:ChannelID
Value:
webapp
(PID) Process:(9184) app_package_d_8e3aaa439e.exeKey:HKEY_CLASSES_ROOT\live-studio-app\installerName
Operation:writeName:adTrack
Value:
v0.0.1-wid-93A8AVl6nUG
Executable files
447
Suspicious files
231
Text files
1 710
Unknown types
1

Dropped files

PID
Process
Filename
Type
5048tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exeC:\Users\admin\AppData\Local\app_shell_cache_d_8311\app_package_d_8e3aaa439e.exe
MD5:
SHA256:
5048tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exeC:\Users\admin\AppData\Local\Temp\nsb5E1C.tmp\nsis_plugin.dllexecutable
MD5:433FC9E482B833919D7D1DB1675410BA
SHA256:64394700665C3330C758571327AD4100C018DEA5D6438BC309066FC44DCFB988
5048tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exeC:\Users\admin\AppData\Local\Temp\nsb5E1C.tmp\res.zipcompressed
MD5:8DC45B79B5661B28B3394DC3833649D9
SHA256:D0032E6817699107FD9644AEE5767276F661F1FCA34AB13E52E47CFBC753C9E7
5048tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exeC:\Users\admin\AppData\Local\Temp\nsb5E1C.tmp\System.dllexecutable
MD5:257BC7B323EF78B5266A22B4E94294B0
SHA256:A75258EC5DA5846D9A89D87A8DF56E6073F8F18C8D5C270D1B0D8CD8FA879EBE
5048tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exeC:\Users\admin\AppData\Local\Temp\nsb5E1C.tmp\shell_downloader_pro.dllexecutable
MD5:34CB96BA3B82510FD8B957588A258A6E
SHA256:104B54E25DA025384B0A1C448771B40A734D624BE24D40CDAAAB09DC7D0994A7
5048tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exeC:\Users\admin\AppData\Local\Temp\nsb5E1C.tmp\StdUtils.dllexecutable
MD5:3A724EBFC55C517213B896516B4AD554
SHA256:B80BAE69E50876685900A1B00A37964923EE2DD08B28CD7C8AF88DFA633BD573
9184app_package_d_8e3aaa439e.exeC:\Users\admin\AppData\Local\Temp\nsk1835.tmp\System.dllexecutable
MD5:0D7AD4F45DC6F5AA87F606D0331C6901
SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA
9184app_package_d_8e3aaa439e.exeC:\Users\admin\AppData\Local\Temp\nsk1835.tmp\nsis_plugin.dllexecutable
MD5:2183DBECD97C8172B65A55860896F76F
SHA256:16002F0202699136933D3E68D09C9D4305AB5306AF9FDF043F7C8540EF51408D
9184app_package_d_8e3aaa439e.exeC:\Users\admin\AppData\Local\Temp\nsk1835.tmp\res.zipcompressed
MD5:A99714CDFA00E09393A146131AF14D32
SHA256:F464BE54A36C0F284B3F96C4E6C6B2E9FB3AAF6621725C0943DF30467AD4F147
9184app_package_d_8e3aaa439e.exeC:\Users\admin\AppData\Local\Temp\nsk1835.tmp\StdUtils.dllexecutable
MD5:632B17050D2C9D1F11D201BFA6014FAE
SHA256:D55AE4160BAC37ED10DB05F297573F16846A4F03CE06E197723F27439D407605
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
23
TCP/UDP connections
39
DNS requests
28
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
356
svchost.exe
POST
200
20.190.159.64:443
https://login.live.com/RST2.srf
US
xml
10.3 Kb
whitelisted
8124
svchost.exe
GET
200
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=0&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
text
5.63 Kb
whitelisted
356
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
8124
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
5048
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe
POST
200
2.16.238.136:443
https://maliva-mcs.byteoversea.com/v1/json
NL
text
14 b
unknown
9184
app_package_d_8e3aaa439e.exe
POST
200
2.16.238.140:443
https://maliva-mcs.byteoversea.com/v1/json
NL
text
14 b
unknown
6500
SIHClient.exe
GET
200
23.59.18.102:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
US
binary
409 b
whitelisted
9184
app_package_d_8e3aaa439e.exe
POST
200
2.16.238.140:443
https://maliva-mcs.byteoversea.com/v1/json
NL
text
14 b
unknown
9184
app_package_d_8e3aaa439e.exe
POST
200
2.16.238.140:443
https://maliva-mcs.byteoversea.com/v1/json
NL
text
14 b
unknown
9184
app_package_d_8e3aaa439e.exe
POST
200
2.16.238.140:443
https://maliva-mcs.byteoversea.com/v1/json
NL
text
14 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
8124
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7428
RUXIMICS.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5568
SearchApp.exe
2.16.241.198:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
5048
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe
2.21.65.76:443
tron-sg.bytelemon.com
AKAMAI-ASN1
NL
whitelisted
5048
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe
2.16.238.136:443
maliva-mcs.byteoversea.com
AKAMAI-ASN1
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.201.78
whitelisted
self.events.data.microsoft.com
  • 20.189.173.9
  • 20.42.72.131
whitelisted
www.bing.com
  • 2.16.241.198
  • 2.16.241.227
  • 2.16.241.197
  • 2.16.241.200
  • 2.16.241.226
  • 2.16.241.199
  • 2.16.241.202
  • 2.16.241.203
  • 2.16.241.207
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
tron-sg.bytelemon.com
  • 2.21.65.76
  • 2.21.65.91
whitelisted
maliva-mcs.byteoversea.com
  • 2.16.238.136
  • 2.16.238.144
  • 2.16.238.140
  • 2.16.238.142
  • 2.16.238.139
  • 2.16.238.137
  • 2.16.238.145
  • 2.16.238.141
  • 2.16.238.143
  • 2.16.238.134
  • 2.16.238.135
  • 2.16.238.163
  • 2.16.238.160
  • 2.16.238.161
whitelisted
login.live.com
  • 20.190.159.64
  • 40.126.31.129
  • 20.190.159.129
  • 20.190.159.71
  • 40.126.31.128
  • 40.126.31.73
  • 20.190.159.130
  • 20.190.159.131
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.42
whitelisted

Threats

PID
Process
Class
Message
8124
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
Process
Message
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe
[0202/043250.244:INFO:atom_auto_updater.cc(65)] [atom_auto_updater] inner init done.
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe
[0202/043250.291:INFO:atom_auto_updater.cc(179)] [atom_auto_updater] check update url: https://tron-sg.bytelemon.com/api/sdk/check_update?pid=7393277106664249610&uid=&branch=studio/release/stable&buildId=
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe
[0202/043250.525:INFO:atom_auto_updater.cc(205)] [atom_auto_updater] on check update finish.
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe
[0202/043250.525:INFO:shell_downloader_pro.cc(251)] ShellDownloaderPro::OnCheckUpdateFinish
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe
checkBoxDesktopShortcut status:1
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe
[0202/043257.659:INFO:atom_auto_updater.cc(299)] [atom_auto_updater] download url: https://www.tiktok.com/tos-live-studio/releases/281638405/1.12.0/win32-x64/tiktok_live_studio-v1.12.0.exe
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe
exec
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe
[0202/043257.659:INFO:atom_auto_updater.cc(375)] [atom_auto_updater] download file: https://www.tiktok.com/tos-live-studio/releases/281638405/1.12.0/win32-x64/tiktok_live_studio-v1.12.0.exe
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe
[0202/043330.443:INFO:http_client.cc(187)] [atom_auto_updater] download result:1
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe
[0202/043330.443:INFO:http_client.cc(310)] [atom_auto_updater] check file md5: 48E9C480