09c998cc8badece7f47ebf6b52ed84a7c5337320f53f7fc36a0ec2933218a866

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2025-Dec-15 03:23:26
Detected languages English - United States
TLS Callbacks 4 callback(s) detected.
Debug artifacts app_shell_launcher.exe.pdb
FileDescription TikTok LIVE Studio Launcher
ProductName TikTok LIVE Studio
CompanyName TikTok Pte. Ltd.
LegalCopyright Copyright © 2026 TikTok Pte. Ltd.
FileVersion 1.35.2
ProductVersion 1.35.2.0

Plugin Output

Info Matching compiler(s): Microsoft Visual C++ 6.0 - 8.0
Suspicious Strings found in the binary may indicate undesirable behavior: Accesses the WMI:
  • ROOT\CIMV2
Contains domain names:
  • api.toutiaoapi.com
  • blink.net
  • byteoversea.com
  • https://api.toutiaoapi.com
  • https://maliva-mcs.byteoversea.com
  • https://mcs.zijieapi.com
  • https://www.tiktok.com
  • https://www.tiktok.com/studio/download
  • maliva-mcs.byteoversea.com
  • mcs.byteoversea.com
  • mcs.zijieapi.com
  • openssl.org
  • tiktok.com
  • toutiaoapi.com
  • www.tiktok.com
  • zijieapi.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExA
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • FindWindowW
  • CreateToolhelp32Snapshot
Code injection capabilities (PowerLoader):
  • FindWindowW
  • GetWindowLongW
Can access the registry:
  • RegCloseKey
  • RegCreateKeyExW
  • RegOpenKeyExW
  • RegQueryValueExW
  • RegSetValueExW
Possibly launches other programs:
  • CreateProcessAsUserW
  • ShellExecuteA
  • CreateProcessW
Can create temporary files:
  • CreateFileA
  • CreateFileW
  • GetTempPathW
Has Internet access capabilities:
  • WinHttpAddRequestHeaders
  • WinHttpCloseHandle
  • WinHttpConnect
  • WinHttpOpen
  • WinHttpOpenRequest
  • WinHttpQueryDataAvailable
  • WinHttpReadData
  • WinHttpReceiveResponse
  • WinHttpSendRequest
  • WinHttpSetOption
Functions related to the privilege level:
  • DuplicateTokenEx
  • OpenProcessToken
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • OpenProcess
  • Process32FirstW
  • Process32NextW
  • WriteProcessMemory
Changes object ACLs:
  • SetNamedSecurityInfoW
  • SetSecurityInfo
Can take screenshots:
  • CreateCompatibleDC
  • FindWindowW
  • GetDC
Info The PE is digitally signed. Signer: TikTok Pte. Ltd.
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Safe VirusTotal score: 0/71 (Scanned on 2026-09-02 09:18:32) All the AVs think this file is safe.

Hashes

MD5 d7745172c444fe3df9764cc73fb47044 🔍
SHA1 b2b2896a3eb60dbbb53d6352dcddfc28bae49631 🔍
SHA256 09c998cc8badece7f47ebf6b52ed84a7c5337320f53f7fc36a0ec2933218a866 🔍
SHA3 021f9afee91200276d7e67bf4031931c73288b30f6a16565fb547f3643134d6f 🔍
SSDeep 24576:WVrSqn5jUAvQ7GRa9kG6eYj70x2HVroV+IS+IXDVfPbLxRyZnzcXSdTycY:krSqFUAvQaRAUjpJRydcXSdWcY 🔍
Imports Hash 3f1ca64f0b59ddb40416521761910631 🔍

DOS Header

e_magic MZ
e_cblp 0x78
e_cp 0x1
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0
e_ss 0
e_sp 0
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x78

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 7
TimeDateStamp 2025-Dec-15 03:23:26
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32
LinkerVersion 14.0
SizeOfCode 0x110e00
SizeOfInitializedData 0x3d400
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000E6270 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 0.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0x156000
SizeOfHeaders 0x400
Checksum 0x160cfb
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 7fb12d61a64a2c6e9563a6f90da62af9 🔍
SHA1 f60084a58c7cd1ba7edc22bb683967db8d7d6da9 🔍
SHA256 bd09e39522a6c8cb1d460608a12c2f6cf784e87845ea26d2fe5a6089e6ad38fe 🔍
SHA3 7d9172311c3693ee089003efa60674ef1a86384c3035eee4a9812f0ecdd67063 🔍
VirtualSize 0x110d28
VirtualAddress 0x1000
SizeOfRawData 0x110e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.71842

.rdata

MD5 bceb7488db4ad7cfa3f4afb7e0e7a71b 🔍
SHA1 25c74776533248d8e8c98819ccd750561473e3ee 🔍
SHA256 8c9b11a7b3f25193aebcbc0e751d51349e65b843a9a58a3f2cc9445fe8863a44 🔍
SHA3 cee4e769013574fc77caf1172847a98b538e9a06ff9b35cedb4f9a04576c292f 🔍
VirtualSize 0x255e4
VirtualAddress 0x112000
SizeOfRawData 0x25600
PointerToRawData 0x111200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.63915

.data

MD5 8e1dfc09bd719c6d282973ef9263074e 🔍
SHA1 27ff8bde94175f29f8979ce24dd77dff97008335 🔍
SHA256 f355eb387ff6d2683db3ccb444654a137acc701defa4c16b0873efa269c1dc8f 🔍
SHA3 6efffefce5668619cdc73bad8f78b4a55b0c091efca4920e597508f2761e1ece 🔍
VirtualSize 0x59ac
VirtualAddress 0x138000
SizeOfRawData 0x2600
PointerToRawData 0x136800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.67753

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x80
VirtualAddress 0x13e000
SizeOfRawData 0x200
PointerToRawData 0x138e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.tls

MD5 59ea3975c134ea7f8d86361cac73f02c 🔍
SHA1 47e57e2fea08f0dd007c0206f6789a8cf511b47f 🔍
SHA256 5a23d81795b311d0e09cf1ca431ae6cffc5879c59f787422b801ccc984c2eb0d 🔍
SHA3 4ef464cd4c46888e860c0f8a613b495b08626d84ebeca1ed5df0523dd450554c 🔍
VirtualSize 0xb9
VirtualAddress 0x13f000
SizeOfRawData 0x200
PointerToRawData 0x139000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.0611629

.rsrc

MD5 f76e198be56a3ed3e4e9a22054427b9d 🔍
SHA1 62eb8986ae228acf11ed4a191e7e509c97a00440 🔍
SHA256 46709051b954a1c197361a66cb8119b64f86627a7f8557fbe1a8724a25da0e73 🔍
SHA3 67533605981bf6435ac3cedcd838189340c0425f506b704fb4d9a5a7ba341b61 🔍
VirtualSize 0xbaa4
VirtualAddress 0x140000
SizeOfRawData 0xbc00
PointerToRawData 0x139200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.4773

.reloc

MD5 a8d947668234f706300aa826f4994326 🔍
SHA1 26163cc0e2aeb28381cf92c9e889b433faeeb708 🔍
SHA256 75f6d02829c1c5e31ff588f662ceab0f428c8886a73cb642d65ddfbef09cc2ad 🔍
SHA3 883c43899d038f25720f967ecf3e7cb25d207744baf0e1558ef0ed2ca6f29c12 🔍
VirtualSize 0x972c
VirtualAddress 0x14c000
SizeOfRawData 0x9800
PointerToRawData 0x144e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 6.68521

Imports

ADVAPI32.dll BuildTrusteeWithSidW
ConvertStringSidToSidW
CreateProcessAsUserW
DuplicateTokenEx
GetLengthSid
GetNamedSecurityInfoW
GetSecurityDescriptorControl
GetSecurityDescriptorDacl
GetSecurityDescriptorGroup
GetSecurityDescriptorOwner
GetSecurityDescriptorSacl
GetTokenInformation
IsValidAcl
IsValidSecurityDescriptor
IsValidSid
OpenProcessToken
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
SetEntriesInAclW
SetNamedSecurityInfoW
SetSecurityInfo
GDI32.dll CreateCompatibleBitmap
CreateCompatibleDC
DeleteDC
DeleteObject
SelectObject
OLEAUT32.dll SysAllocString
SysFreeString
VariantClear
VariantInit
SHELL32.dll CommandLineToArgvW
#680
SHGetFolderPathW
SHGetKnownFolderPath
SetCurrentProcessExplicitAppUserModelID
ShellExecuteA
ShellExecuteExW
USER32.dll AllowSetForegroundWindow
CallNextHookEx
CreateWindowExW
DefWindowProcW
DestroyWindow
DispatchMessageW
FindWindowExW
FindWindowW
GetActiveWindow
GetDC
GetDesktopWindow
GetDlgItem
GetMessageW
GetSystemMetrics
GetWindow
GetWindowLongW
GetWindowRect
GetWindowTextLengthW
GetWindowTextW
KillTimer
LoadCursorW
LoadIconW
LoadStringW
MessageBoxW
PostMessageW
PostQuitMessage
RegisterClassExW
ReleaseDC
ScreenToClient
SetDlgItemTextW
SetProcessDPIAware
SetTimer
SetWindowLongW
SetWindowPos
SetWindowsHookExW
ShowWindow
TranslateMessage
UnhookWindowsHookEx
UnregisterClassW
UpdateLayeredWindow
KERNEL32.dll AcquireSRWLockExclusive
AddVectoredExceptionHandler
AssignProcessToJobObject
CloseHandle
CompareStringW
CopyFileW
CreateDirectoryW
CreateEventW
CreateFileA
CreateFileMappingW
CreateFileW
CreateMutexW
CreateProcessW
CreateThread
CreateToolhelp32Snapshot
DecodePointer
DeleteCriticalSection
DeleteFileW
DeleteProcThreadAttributeList
DeviceIoControl
DosDateTimeToFileTime
DuplicateHandle
EncodePointer
EnterCriticalSection
EnumSystemLocalesW
ExitProcess
ExitThread
ExpandEnvironmentStringsW
FindClose
FindFirstFileExW
FindNextFileW
FindResourceExW
FindResourceW
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
FormatMessageW
FreeEnvironmentStringsW
FreeLibrary
FreeLibraryAndExitThread
FreeResource
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetConsoleMode
GetConsoleOutputCP
GetCurrentDirectoryW
GetCurrentProcess
GetCurrentProcessId
GetCurrentThread
GetCurrentThreadId
GetDateFormatW
GetDriveTypeW
GetEnvironmentStringsW
GetEnvironmentVariableW
GetExitCodeProcess
GetFileAttributesExW
GetFileAttributesW
GetFileInformationByHandle
GetFileSizeEx
GetFileType
GetFullPathNameW
GetLastError
GetLocalTime
GetLocaleInfoW
GetLongPathNameW
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleExW
GetModuleHandleW
GetNativeSystemInfo
GetOEMCP
GetProcAddress
GetProcessHeap
GetProcessId
GetProcessTimes
GetProductInfo
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemDirectoryW
GetSystemInfo
GetSystemTimeAsFileTime
GetTempPathW
GetThreadPriority
GetTickCount64
GetTickCount
GetTimeFormatW
GetTimeZoneInformation
GetUserDefaultLCID
GetUserDefaultLocaleName
GetVersionExW
GetWindowsDirectoryW
GlobalMemoryStatusEx
HeapAlloc
HeapDestroy
HeapFree
HeapReAlloc
HeapSize
InitOnceExecuteOnce
InitializeConditionVariable
InitializeCriticalSectionAndSpinCount
InitializeCriticalSectionEx
InitializeProcThreadAttributeList
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
IsValidLocale
IsWow64Process
K32GetModuleFileNameExW
LCMapStringW
LeaveCriticalSection
LoadLibraryExA
LoadLibraryExW
LoadResource
LocalFree
LockResource
MapViewOfFile
MoveFileW
MultiByteToWideChar
OpenProcess
OutputDebugStringA
OutputDebugStringW
Process32FirstW
Process32NextW
QueryPerformanceCounter
QueryPerformanceFrequency
QueryThreadCycleTime
RaiseException
ReadConsoleW
ReadFile
ReleaseSRWLockExclusive
RemoveDirectoryW
ReplaceFileW
RtlCaptureContext
RtlCaptureStackBackTrace
RtlUnwind
SetConsoleCtrlHandler
SetEndOfFile
SetEnvironmentVariableW
SetEvent
SetFileAttributesW
SetFilePointer
SetFilePointerEx
SetFileTime
SetHandleInformation
SetLastError
SetPriorityClass
SetStdHandle
SetThreadPriority
SetUnhandledExceptionFilter
SizeofResource
Sleep
SleepConditionVariableCS
SleepConditionVariableSRW
SystemTimeToFileTime
TerminateProcess
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
TryAcquireSRWLockExclusive
UnhandledExceptionFilter
UnmapViewOfFile
UpdateProcThreadAttribute
VirtualProtect
VirtualQuery
WaitForSingleObject
WaitForSingleObjectEx
WakeAllConditionVariable
WakeConditionVariable
WideCharToMultiByte
WriteConsoleW
WriteFile
WriteProcessMemory
ole32.dll CLSIDFromString
CoCreateInstance
CoInitialize
CoInitializeEx
CoRegisterInitializeSpy
CoRevokeInitializeSpy
CoSetProxyBlanket
CoTaskMemFree
CoUninitialize
IIDFromString
gdiplus.dll GdipAlloc
GdipCloneImage
GdipCreateBitmapFromScan0
GdipCreateFromHDC
GdipDeleteGraphics
GdipDisposeImage
GdipDrawImageRectI
GdipFree
GdipGetImageGraphicsContext
GdipGetImagePixelFormat
GdiplusShutdown
GdiplusStartup
WINHTTP.dll WinHttpAddRequestHeaders
WinHttpCloseHandle
WinHttpConnect
WinHttpOpen
WinHttpOpenRequest
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpReceiveResponse
WinHttpSendRequest
WinHttpSetOption
NETAPI32.dll Netbios
IPHLPAPI.DLL GetAdaptersAddresses
WINMM.dll timeGetTime
USERENV.dll CreateEnvironmentBlock
DestroyEnvironmentBlock
SHLWAPI.dll PathFileExistsW
PathMatchSpecW

Delayed Imports

GetHandleVerifier

Ordinal 1
Address 0x87060

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x254
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.53783
Detected Filetype PNG graphic file
MD5 71b796644976e52ffdc9f4df9ca46ebe 🔍
SHA1 65a0e70f33a53c1ecb5d82156ceea71c525fb905 🔍
SHA256 972a0c3e52d2c2f0ab056b0c91a50ac1c4bf74a966c55df58183d3c7a448b4e4 🔍
SHA3 485e9817f97972760f285d5f421b99f38836c0c573b452426563bd6b71c185b7 🔍

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x353
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.74714
Detected Filetype PNG graphic file
MD5 bd8da3c45ad06a0087e5fc28622b0575 🔍
SHA1 9a25f8300d5e79f9dd4a4e6ca34806dbed1aa912 🔍
SHA256 1ef61761b19997a14984e49e943b7b50831cd21f5862e7e0752fa668040fc685 🔍
SHA3 4b4ce4f860cfac98e2301baa9d928a1c4358858ecc6a39ae642231aa9d0155f9 🔍

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4b2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.80883
Detected Filetype PNG graphic file
MD5 91274837e7523bfdff9d8f400d023818 🔍
SHA1 5feff11378b52fc18856c78739cab3bfd2a6845f 🔍
SHA256 e7c3bb90ee872ab7b32cbf9067db0499d5e3a4337ac7fabf977a9bf9297b6b9c 🔍
SHA3 1e4cea3d4f2247356973a198dc82e7a842a3271a0399ea7c327da3ea1addbaf2 🔍

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x6ec
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.86355
Detected Filetype PNG graphic file
MD5 e6a599945699117cd3a60f562bfe3f46 🔍
SHA1 c77ec0d9999abb05076682cb2b9a7ed75685339e 🔍
SHA256 05a77a7ab5a290413257a89a908a613a33018afef1876784d8c6aeb108b485e5 🔍
SHA3 8207c44ca3f9065b157cd919a812ecad89a7f3b3c3475eb293934aa5dc44ab19 🔍

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x8f5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.89271
Detected Filetype PNG graphic file
MD5 39bfe5bce2163656d69f98efa412a632 🔍
SHA1 cc56d000b0dc58e83015c9b4b4920c7e0776c850 🔍
SHA256 e43b2032cb9c9fa416c3bc258322022728e60e0b664029a462c4d5c1a12ca7a0 🔍
SHA3 381f9e3247016afb416ea0212a027cf0547d780e16d097adbb8093633bb2a68d 🔍

6

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x127c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.93789
Detected Filetype PNG graphic file
MD5 88ad40bba164fd84338fc2876bd2f6a1 🔍
SHA1 789437e6a8f7db3cff96c9a5cb74101710901a04 🔍
SHA256 751935e18065d2e6b8b693732fc73059342deb893d1a46314296e0550b70a020 🔍
SHA3 c763cc43d4ae60f3defa38b203ebdb95b1574e7e1d5f1e3b96f1e5d9858b844b 🔍

7

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2654
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.94864
Detected Filetype PNG graphic file
MD5 374c411de27772bb6db07d6d4648a5b2 🔍
SHA1 2e463f7dd92cbf6e201ce8a1c467a2ec671045e2 🔍
SHA256 4945ea8c5de3673a8e6c6d3e942c907ae44e158407187e4f366161ea0ecff664 🔍
SHA3 d9a1a168c26fb2a09d64bd36581f711dedebf03ab24f681ebe55a74aad427e1a 🔍

13

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xfe
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.20242
MD5 1926e455f9421e9085c9b5039e371127 🔍
SHA1 76fde8fbcf16a3557b5982b243326c789daa6937 🔍
SHA256 5a1db84420c715ac7b21c81316d1ea2152e6775d51115494650399dfb7a1fef6 🔍
SHA3 c253333fcc1860a8441248f2ec2f36f6039dc7a3e5c3c7e51d3474ecaa07f637 🔍

14

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0xbc
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.22156
MD5 93d924502fe3d6bc4faea133a5e557b6 🔍
SHA1 b0b2e50e0bf28032c75cffb9aa1a655dcae7ae1d 🔍
SHA256 840cc4962246b7e80f50f73c02cab690164dd8631154898f7f3aa50c2fe6f432 🔍
SHA3 012b81a12e4aeeb10a525b846ca9145b3a02a6d2daa1379b71542528f5f962bf 🔍

19

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x4e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.29594
MD5 d6e6908b293eff7f2f025c4407744dcb 🔍
SHA1 3269e4643032b4844c5b8d7ba07aec985bedba51 🔍
SHA256 6d409b655b4453504f7548a3dadc307ed47add8c04fa9faef6b2cfb3944686d4 🔍
SHA3 edd0701c285e6dfb64d663b4528e829a68be1ed502b52b44d6ffb7bb66f7291d 🔍

26

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x24
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0.614369
MD5 1c23c671b858fb5f196bfe248b236a24 🔍
SHA1 fb5b0116cdf58e43b17ce119e6a3b645868612c2 🔍
SHA256 4aa4343af2857fa02201ca9c485b162eeeed8c6bb4b1936edad6386c9d8c1662 🔍
SHA3 dfbdaa3fb6752a2b935b759b48d85eb4a93af010d9e632ea7fe2c6175ae3bf2a 🔍

32

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.49593
MD5 694a1251a2f8b8df59dd8529d1464795 🔍
SHA1 6ca6e86a0eb8814d94dd74a7d6a45022762dff05 🔍
SHA256 2b45acf98c11d7343f7248edab5109609d1ece5752e3bf897406593b04f1ef9c 🔍
SHA3 a1ce7366ebcba097a6768dce795fb4fba580aaa0e65249005159bd4bccca8f2d 🔍

100

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x5a28
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.93307
Detected Filetype Zip Compressed Archive
MD5 ec0ef6e8aef83e263761b53626569573 🔍
SHA1 b9036c4b5fbf06d5f2b2772dc21f00d9d9218101 🔍
SHA256 56f999ab5e7fc436df980657987de24522ac2656925d1d38b5bed8c0aaefe081 🔍
SHA3 3b2e25aaa99a693eb1ec07c0866ee45394e99c74a8d47639e57925589fe719a3 🔍

0

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.64573
Detected Filetype Icon file
MD5 305bf7417f4854cd6f6b4f9e597fdd1f 🔍
SHA1 edab77a08bdb98502dbce05298e88faee53f9419 🔍
SHA256 d9aaa74b640bac9a1176d501d709d52d12ad26d018beeb988b78fc7e8aa2969e 🔍
SHA3 049faa0ceacedb844578d986006f8323004055279c781b13996df54e287d8876 🔍

1 (#2)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x2b4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.29406
MD5 9aa3faec488f3741e2ab4d12aa332619 🔍
SHA1 068845f20b0fdd995c6242cbd3fc48c8dcd537d7 🔍
SHA256 81ab6e255e880a1e068723b3793ae177bc9d83963397325de14f71e98f115739 🔍
SHA3 1c89abea856cd79df8dbb1c9f1d3697deb2fb4e93791467eb5b96833e30d58fe 🔍

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x256
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.08239
MD5 619740ddfa24b2c3165b7ca17c40dce4 🔍
SHA1 beef0405657a958c84bc8a8e9f15a17b2a9d31cb 🔍
SHA256 9fd368e01aa0f4377298573ee94af87a9bb8d0534e961d5860da5daac6faa36e 🔍
SHA3 91acc29c7322f85b3672ebc6c4913fe13096b876b5411f311ce9a21a14944088 🔍

String Table contents

8311
TikTok LIVE Studio
com.tiktok.livestudio.desktop
1
https://www.tiktok.com/studio/download
1
tiktoklivestudio
[""]
autorun
1
1
0
1
tiktoklivestudio_Mutex_Install
2
TikTok LIVE Studio Launcher.exe
1.0.0
1
8311
TikTok LIVE Studio
0
0
{"oversea":true,"cls_id":"{5DA6FD3E-637B-4E89-87DB-B4BD8D72D6B1}","iid":"{639AB3C3-3B11-43A3-8C7C-222698CAF2EC}","service_name":"LiveStudioElevationService","display_name":"Tiktok Live Studio ElevationService","reg_key":"SOFTWARE\\ByteDance\\TiktokLiveStudio"}

Version Info

Signature 0xfeef04bd
StructVersion 0
FileVersion 1.35.2.0
ProductVersion 1.35.2.0
FileFlags (EMPTY)
FileOs (EMPTY)
FileType VFT_APP
Language English - United States
FileDescription TikTok LIVE Studio Launcher
ProductName TikTok LIVE Studio
CompanyName TikTok Pte. Ltd.
LegalCopyright Copyright © 2026 TikTok Pte. Ltd.
FileVersion (#2) 1.35.2
ProductVersion (#2) 1.35.2.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2025-Dec-15 03:23:26
Version 0.0
SizeofData 51
AddressOfRawData 0x130c78
PointerToRawData 0x12fe78
Referenced File app_shell_launcher.exe.pdb

TLS Callbacks

StartAddressOfRawData 0x53f000
EndAddressOfRawData 0x53f0b8
AddressOfIndex 0x53a480
AddressOfCallbacks 0x532280
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x0049E4D0
0x004992D0
0x004BB700
0x0043BB40

Load Configuration

Size 0xc0
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x538040
SEHandlerTable 0x530cab
SEHandlerCount 156
GuardCFCheckFunctionPointer 5448204
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

Errors

Leave a comment

No comments yet.