| File name: | tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe |
| Full analysis: | https://app.any.run/tasks/e0438616-b5db-47d0-9387-682090a422db |
| Verdict: | Malicious activity |
| Analysis date: | February 02, 2026, 09:32:27 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections |
| MD5: | C3B3A4B7AB65D615DE9BA8C15E4F89C1 |
| SHA1: | 5A14336B835ECAEB94DCA70732FB67150431B764 |
| SHA256: | 37AE7A2416F72E6EC7309515B090162D19F315326A3C7E768E5FFE7DC0DA8AC9 |
| SSDEEP: | 98304:BU49BpfNOL0IZNiGzFc4x0FwrkklxxeGkMu7GPR4i+1Sb6Ieexk7eLSTDdlsru2L:WtAwY9wAK |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:12:15 22:26:14+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 26624 |
| InitializedDataSize: | 473088 |
| UninitializedDataSize: | 16384 |
| EntryPoint: | 0x338f |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 5048 | "C:\Users\admin\AppData\Local\Temp\tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe" | C:\Users\admin\AppData\Local\Temp\tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
| 8428 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 8508 | "C:\Users\admin\AppData\Local\Temp\tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe" | C:\Users\admin\AppData\Local\Temp\tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 9184 | "C:\Users\admin\AppData\Local\app_shell_cache_d_8311\app_package_d_8e3aaa439e.exe" /S /D="C:\Program Files\TikTok LIVE Studio" | C:\Users\admin\AppData\Local\app_shell_cache_d_8311\app_package_d_8e3aaa439e.exe | tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | ||||||||||||
User: admin Company: TikTok Pte. Ltd. Integrity Level: HIGH Version: 1.12.0 Modules
| |||||||||||||||
| (PID) Process: | (5048) tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\tiktoklivestudio |
| Operation: | write | Name: | PresetInstallDir |
Value: C:\Program Files\TikTok LIVE Studio | |||
| (PID) Process: | (5048) tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\tiktoklivestudio |
| Operation: | write | Name: | PresetShortcut |
Value: 1 | |||
| (PID) Process: | (5048) tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\tiktoklivestudio |
| Operation: | write | Name: | PresetChannelID |
Value: webapp | |||
| (PID) Process: | (5048) tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\tiktoklivestudio |
| Operation: | write | Name: | PresetWid |
Value: 7602196066511635990 | |||
| (PID) Process: | (5048) tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\tiktoklivestudio |
| Operation: | write | Name: | PresetAdTrack |
Value: v0.0.1-wid-93A8AVl6nUG | |||
| (PID) Process: | (5048) tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\tiktoklivestudio |
| Operation: | write | Name: | ChannelID |
Value: webapp | |||
| (PID) Process: | (9184) app_package_d_8e3aaa439e.exe | Key: | HKEY_CLASSES_ROOT\live-studio-app\installerName |
| Operation: | write | Name: | adTrack |
Value: v0.0.1-wid-93A8AVl6nUG | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5048 | tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | C:\Users\admin\AppData\Local\app_shell_cache_d_8311\app_package_d_8e3aaa439e.exe | — | |
MD5:— | SHA256:— | |||
| 5048 | tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | C:\Users\admin\AppData\Local\Temp\nsb5E1C.tmp\nsis_plugin.dll | executable | |
MD5:433FC9E482B833919D7D1DB1675410BA | SHA256:64394700665C3330C758571327AD4100C018DEA5D6438BC309066FC44DCFB988 | |||
| 5048 | tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | C:\Users\admin\AppData\Local\Temp\nsb5E1C.tmp\res.zip | compressed | |
MD5:8DC45B79B5661B28B3394DC3833649D9 | SHA256:D0032E6817699107FD9644AEE5767276F661F1FCA34AB13E52E47CFBC753C9E7 | |||
| 5048 | tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | C:\Users\admin\AppData\Local\Temp\nsb5E1C.tmp\System.dll | executable | |
MD5:257BC7B323EF78B5266A22B4E94294B0 | SHA256:A75258EC5DA5846D9A89D87A8DF56E6073F8F18C8D5C270D1B0D8CD8FA879EBE | |||
| 5048 | tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | C:\Users\admin\AppData\Local\Temp\nsb5E1C.tmp\shell_downloader_pro.dll | executable | |
MD5:34CB96BA3B82510FD8B957588A258A6E | SHA256:104B54E25DA025384B0A1C448771B40A734D624BE24D40CDAAAB09DC7D0994A7 | |||
| 5048 | tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | C:\Users\admin\AppData\Local\Temp\nsb5E1C.tmp\StdUtils.dll | executable | |
MD5:3A724EBFC55C517213B896516B4AD554 | SHA256:B80BAE69E50876685900A1B00A37964923EE2DD08B28CD7C8AF88DFA633BD573 | |||
| 9184 | app_package_d_8e3aaa439e.exe | C:\Users\admin\AppData\Local\Temp\nsk1835.tmp\System.dll | executable | |
MD5:0D7AD4F45DC6F5AA87F606D0331C6901 | SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA | |||
| 9184 | app_package_d_8e3aaa439e.exe | C:\Users\admin\AppData\Local\Temp\nsk1835.tmp\nsis_plugin.dll | executable | |
MD5:2183DBECD97C8172B65A55860896F76F | SHA256:16002F0202699136933D3E68D09C9D4305AB5306AF9FDF043F7C8540EF51408D | |||
| 9184 | app_package_d_8e3aaa439e.exe | C:\Users\admin\AppData\Local\Temp\nsk1835.tmp\res.zip | compressed | |
MD5:A99714CDFA00E09393A146131AF14D32 | SHA256:F464BE54A36C0F284B3F96C4E6C6B2E9FB3AAF6621725C0943DF30467AD4F147 | |||
| 9184 | app_package_d_8e3aaa439e.exe | C:\Users\admin\AppData\Local\Temp\nsk1835.tmp\StdUtils.dll | executable | |
MD5:632B17050D2C9D1F11D201BFA6014FAE | SHA256:D55AE4160BAC37ED10DB05F297573F16846A4F03CE06E197723F27439D407605 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
356 | svchost.exe | POST | 200 | 20.190.159.64:443 | https://login.live.com/RST2.srf | US | xml | 10.3 Kb | whitelisted |
8124 | svchost.exe | GET | 200 | 51.124.78.146:443 | https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=0&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2 | US | text | 5.63 Kb | whitelisted |
356 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | binary | 471 b | whitelisted |
8124 | svchost.exe | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | NL | binary | 825 b | whitelisted |
5048 | tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | POST | 200 | 2.16.238.136:443 | https://maliva-mcs.byteoversea.com/v1/json | NL | text | 14 b | unknown |
9184 | app_package_d_8e3aaa439e.exe | POST | 200 | 2.16.238.140:443 | https://maliva-mcs.byteoversea.com/v1/json | NL | text | 14 b | unknown |
6500 | SIHClient.exe | GET | 200 | 23.59.18.102:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | US | binary | 409 b | whitelisted |
9184 | app_package_d_8e3aaa439e.exe | POST | 200 | 2.16.238.140:443 | https://maliva-mcs.byteoversea.com/v1/json | NL | text | 14 b | unknown |
9184 | app_package_d_8e3aaa439e.exe | POST | 200 | 2.16.238.140:443 | https://maliva-mcs.byteoversea.com/v1/json | NL | text | 14 b | unknown |
9184 | app_package_d_8e3aaa439e.exe | POST | 200 | 2.16.238.140:443 | https://maliva-mcs.byteoversea.com/v1/json | NL | text | 14 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
8124 | svchost.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
7428 | RUXIMICS.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6768 | MoUsoCoreWorker.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5568 | SearchApp.exe | 2.16.241.198:443 | www.bing.com | AKAMAI-ASN1 | NL | whitelisted |
— | — | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
— | — | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
5048 | tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | 2.21.65.76:443 | tron-sg.bytelemon.com | AKAMAI-ASN1 | NL | whitelisted |
5048 | tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | 2.16.238.136:443 | maliva-mcs.byteoversea.com | AKAMAI-ASN1 | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
tron-sg.bytelemon.com |
| whitelisted |
maliva-mcs.byteoversea.com |
| whitelisted |
login.live.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
8124 | svchost.exe | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |
Process | Message |
|---|---|
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | [0202/043250.244:INFO:atom_auto_updater.cc(65)] [atom_auto_updater] inner init done.
|
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | [0202/043250.291:INFO:atom_auto_updater.cc(179)] [atom_auto_updater] check update url: https://tron-sg.bytelemon.com/api/sdk/check_update?pid=7393277106664249610&uid=&branch=studio/release/stable&buildId=
|
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | [0202/043250.525:INFO:atom_auto_updater.cc(205)] [atom_auto_updater] on check update finish.
|
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | [0202/043250.525:INFO:shell_downloader_pro.cc(251)] ShellDownloaderPro::OnCheckUpdateFinish
|
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | checkBoxDesktopShortcut status:1
|
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | [0202/043257.659:INFO:atom_auto_updater.cc(299)] [atom_auto_updater] download url: https://www.tiktok.com/tos-live-studio/releases/281638405/1.12.0/win32-x64/tiktok_live_studio-v1.12.0.exe
|
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | exec |
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | [0202/043257.659:INFO:atom_auto_updater.cc(375)] [atom_auto_updater] download file: https://www.tiktok.com/tos-live-studio/releases/281638405/1.12.0/win32-x64/tiktok_live_studio-v1.12.0.exe
|
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | [0202/043330.443:INFO:http_client.cc(187)] [atom_auto_updater] download result:1
|
tiktok_live_studio_downloader-v0.0.1-wid-93A8AVl6nUG.exe | [0202/043330.443:INFO:http_client.cc(310)] [atom_auto_updater] check file md5: 48E9C480
|