090352bfe6398137cb4de9a378538977edb3711d1aa444b80e1861785d7cf015

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Aug-11 21:18:28
Detected languages English - United States
TLS Callbacks 6 callback(s) detected.
Debug artifacts electron.exe.pdb
CompanyName TikTok Pte. Ltd.
FileDescription TikTok LIVE Studio
FileVersion 1.35.2
InternalName TikTok LIVE Studio
LegalCopyright Copyright © 2026 TikTok Pte. Ltd.
OriginalFilename
ProductName TikTok LIVE Studio
ProductVersion 1.35.2.0
SquirrelAwareVersion 1

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Accesses the WMI:
  • ROOT\CIMV2
Contains domain names:
  • api.toutiaoapi.com
  • blink.net
  • byteoversea.com
  • https://api.toutiaoapi.com
  • https://maliva-mcs.byteoversea.com
  • https://mcs.zijieapi.com
  • maliva-mcs.byteoversea.com
  • mcs.byteoversea.com
  • mcs.zijieapi.com
  • openssl.org
  • toutiaoapi.com
  • zijieapi.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to MD5
Uses constants related to SHA1
Uses constants related to SHA256
Uses constants related to SHA512
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExA
  • LoadLibraryExW
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Code injection capabilities:
  • CreateRemoteThread
  • VirtualAlloc
  • VirtualAllocEx
  • WriteProcessMemory
Code injection capabilities (mapping injection):
  • CreateFileMappingW
  • CreateRemoteThread
  • MapViewOfFile
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • CreateFileA
  • CreateFileW
  • GetTempPathW
Memory manipulation functions often used by packers:
  • VirtualAlloc
  • VirtualAllocEx
  • VirtualProtect
  • VirtualProtectEx
Has Internet access capabilities:
  • WinHttpAddRequestHeaders
  • WinHttpCloseHandle
  • WinHttpConnect
  • WinHttpOpen
  • WinHttpOpenRequest
  • WinHttpQueryDataAvailable
  • WinHttpReadData
  • WinHttpReceiveResponse
  • WinHttpSendRequest
  • WinHttpSetOption
Enumerates local disk drives:
  • GetDriveTypeW
Manipulates other processes:
  • Process32FirstW
  • Process32NextW
  • ReadProcessMemory
  • WriteProcessMemory
Info The PE is digitally signed. Signer: TikTok Pte. Ltd.
Issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Safe VirusTotal score: 0/67 (Scanned on 2026-09-02 01:29:14) All the AVs think this file is safe.

Hashes

MD5 21410a0cab656725351dad0c423e2f29 🔍
SHA1 f4be9175869e6db93c5aa118c4a7c29dc96dd98d 🔍
SHA256 090352bfe6398137cb4de9a378538977edb3711d1aa444b80e1861785d7cf015 🔍
SHA3 5a76cf92134ddbf41c6f306bf7f92a9e3af6d777cc3bfbc5d63027f7844ef1d1 🔍
SSDeep 49152:Iq4Vu+QDK2tDkyHJ8v9ltjNoBVofGZTTSJ:oMDJtKoSJ 🔍
Imports Hash 5b6e450fe4ace42a7a382ee12838c24d 🔍

DOS Header

e_magic MZ
e_cblp 0x78
e_cp 0x1
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0
e_ss 0
e_sp 0
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x78

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 9
TimeDateStamp 2026-Aug-11 21:18:28
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x1b5200
SizeOfInitializedData 0x73600
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000017FD10 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.1
ImageVersion 0.0
SubsystemVersion 6.1
Win32VersionValue 0
SizeOfImage 0x23e000
SizeOfHeaders 0x400
Checksum 0x235541
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x800000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 cf04c453fdeb9af5bfa6710997df5234 🔍
SHA1 82d80f1d45f15effac121d37b2753a26b1d36c72 🔍
SHA256 5302139c6a5549b3c0d792f503d498b16c44d685117a447b48461d014eec692d 🔍
SHA3 1434a4ffb5f3051df7ac04f0a76adc40cbb0a0f317a094cceada6021a5e26792 🔍
VirtualSize 0x1b515a
VirtualAddress 0x1000
SizeOfRawData 0x1b5200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.54919

.rdata

MD5 a4aaed6c72a19f48cf6a6c0011b765b5 🔍
SHA1 541c56330167e26b3f87d6a6cdaad618489b1e83 🔍
SHA256 7f80c563c8923158a6979a3c3fed2e891d4c65967ba12478caf6565cad525835 🔍
SHA3 fee0d702b68e3d9ec0c9853a3884dc112d7cb4d48313ab533c3eca9871b5ddae 🔍
VirtualSize 0x47268
VirtualAddress 0x1b7000
SizeOfRawData 0x47400
PointerToRawData 0x1b5600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.52085

.data

MD5 6083c9a7f866b0f64ff8199822bbbbee 🔍
SHA1 b150f109259b5b6751529fd8b790db03d42cf228 🔍
SHA256 8430d42471871b6b11910ba7ff255c6843c0afb999ef410eeeea41daa0aeb68d 🔍
SHA3 86eeb8bf0afe62e6e9fc99c268444107231f7551821d6cce0d3a49c9ec570ec1 🔍
VirtualSize 0x1d72c
VirtualAddress 0x1ff000
SizeOfRawData 0xee00
PointerToRawData 0x1fca00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.38178

.pdata

MD5 ebab347151427555e8e86956ef7085a8 🔍
SHA1 e0e2e5aa631f75b3ead60fd1e9379d3a2b352ee1 🔍
SHA256 47b848ef0e95c88df2dbf3ceefc84aeb34be3ebd602e6719c364752afa7be2d1 🔍
SHA3 7ba850c47f0e2de16212d1e75896395d783900d57d432da6ecede1d5770708b6 🔍
VirtualSize 0xf030
VirtualAddress 0x21d000
SizeOfRawData 0xf200
PointerToRawData 0x20b800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.14336

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0x22d000
SizeOfRawData 0x200
PointerToRawData 0x21aa00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.tls

MD5 f906e3049df964bc6dff08d2dfd55c60 🔍
SHA1 b97fdc8b38fda5270e1c65aee3119b2168d385ed 🔍
SHA256 7a85899d5100b75d309100762c8d88dd097eb0d8b40eb838e180718905072e7a 🔍
SHA3 93997005f78eb87132a2ecd2bc8bb1d60f2dbde4b7a87f659188b1ffb3cc3e62 🔍
VirtualSize 0x201
VirtualAddress 0x22e000
SizeOfRawData 0x400
PointerToRawData 0x21ac00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.164376

_RDATA

MD5 32b4507fd0f3406a5b5e822bea3001d0 🔍
SHA1 7495899c08b22bd7b6eb7cd43652712bf14bf1f9 🔍
SHA256 018a7c2f7db660fc9ad5934bd7238686ceb020a8ca234b2c2d0f5ff65ed3c523 🔍
SHA3 56ac2be2164fd28d6a91b083c8c341a8d4792232f8c2004eedefdc224159ca54 🔍
VirtualSize 0x1f4
VirtualAddress 0x22f000
SizeOfRawData 0x200
PointerToRawData 0x21b000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.17621

.rsrc

MD5 497244952eb100d2aa2bf4887d404017 🔍
SHA1 4ef6fb245a605b5645b40c28d8bdcb945047d597 🔍
SHA256 1e745d7433ba7d4022230bf8617771300f039b778c754e0034daf203121052ef 🔍
SHA3 9855b1994f4926676780fe1c103137bb60d22ec33b4b4c42a3ecd1e952b431f5 🔍
VirtualSize 0xbda4
VirtualAddress 0x230000
SizeOfRawData 0xbe00
PointerToRawData 0x21b200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.48785

.reloc

MD5 023d7314d46c39a318c5a4216fc250f8 🔍
SHA1 c5c77cc2099e2e43208221ef5cac5ba66a21ad72 🔍
SHA256 2b4e612b6e13808c8014ca29d4807a543d12a113f35b35b24fe0e414fe869a94 🔍
SHA3 fe117a90a21b28a1a88e2586328602a06e4d4c50d5940380bd044daeb14dbe7f 🔍
VirtualSize 0x1a18
VirtualAddress 0x23c000
SizeOfRawData 0x1c00
PointerToRawData 0x227000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.33009

Imports

OLEAUT32.dll SysAllocString
SysFreeString
VariantClear
VariantInit
KERNEL32.dll AcquireSRWLockExclusive
AllocConsole
AssignProcessToJobObject
AttachConsole
CloseHandle
CompareStringW
CopyFileW
CreateDirectoryW
CreateEventW
CreateFileA
CreateFileMappingW
CreateFileW
CreateIoCompletionPort
CreateJobObjectW
CreateMutexW
CreateProcessW
CreateRemoteThread
CreateThread
CreateToolhelp32Snapshot
DebugBreak
DecodePointer
DeleteCriticalSection
DeleteFileW
DeleteProcThreadAttributeList
DeviceIoControl
DosDateTimeToFileTime
DuplicateHandle
EncodePointer
EnterCriticalSection
EnumSystemLocalesEx
EnumSystemLocalesW
ExitProcess
ExitThread
ExpandEnvironmentStringsW
FindClose
FindFirstFileExW
FindNextFileW
FindResourceExW
FindResourceW
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
FormatMessageW
FreeEnvironmentStringsW
FreeLibrary
FreeLibraryAndExitThread
FreeResource
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetConsoleMode
GetConsoleOutputCP
GetCurrentDirectoryW
GetCurrentProcess
GetCurrentProcessId
GetCurrentProcessorNumber
GetCurrentThread
GetCurrentThreadId
GetDateFormatW
GetDriveTypeW
GetEnvironmentStringsW
GetEnvironmentVariableW
GetExitCodeProcess
GetFileAttributesExW
GetFileAttributesW
GetFileInformationByHandle
GetFileSizeEx
GetFileType
GetFullPathNameW
GetLastError
GetLocalTime
GetLocaleInfoW
GetLongPathNameW
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleExW
GetModuleHandleW
GetNativeSystemInfo
GetOEMCP
GetProcAddress
GetProcessHandleCount
GetProcessHeap
GetProcessHeaps
GetProcessId
GetProcessTimes
GetProductInfo
GetQueuedCompletionStatus
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemDirectoryW
GetSystemInfo
GetSystemTimeAsFileTime
GetTempPathW
GetThreadId
GetThreadPriority
GetTickCount
GetTimeFormatW
GetTimeZoneInformation
GetUserDefaultLCID
GetUserDefaultLangID
GetUserDefaultLocaleName
GetVersionExW
GetWindowsDirectoryW
GlobalMemoryStatusEx
HeapAlloc
HeapDestroy
HeapFree
HeapReAlloc
HeapSetInformation
HeapSize
InitOnceExecuteOnce
InitializeConditionVariable
InitializeCriticalSectionAndSpinCount
InitializeCriticalSectionEx
InitializeProcThreadAttributeList
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
IsValidLocale
IsWow64Process
K32GetModuleInformation
LCMapStringW
LeaveCriticalSection
LoadLibraryExA
LoadLibraryExW
LoadLibraryW
LoadResource
LocalFree
LockResource
MapViewOfFile
MultiByteToWideChar
OutputDebugStringA
OutputDebugStringW
PostQueuedCompletionStatus
Process32FirstW
Process32NextW
QueryInformationJobObject
QueryPerformanceCounter
QueryPerformanceFrequency
QueryThreadCycleTime
RaiseException
ReadConsoleW
ReadFile
ReadProcessMemory
RegisterWaitForSingleObject
ReleaseMutex
ReleaseSRWLockExclusive
RemoveDirectoryW
ResetEvent
RtlCaptureContext
RtlCaptureStackBackTrace
RtlLookupFunctionEntry
RtlPcToFileHeader
RtlUnwind
RtlUnwindEx
RtlVirtualUnwind
SetCurrentDirectoryW
SetDllDirectoryW
SetEndOfFile
SetEnvironmentVariableW
SetEvent
SetFileAttributesW
SetFilePointer
SetFilePointerEx
SetFileTime
SetHandleInformation
SetInformationJobObject
SetLastError
SetStdHandle
SetThreadAffinityMask
SetThreadPriority
SetUnhandledExceptionFilter
SizeofResource
Sleep
SleepConditionVariableCS
SleepConditionVariableSRW
SystemTimeToFileTime
TerminateJobObject
TerminateProcess
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
TryAcquireSRWLockExclusive
UnhandledExceptionFilter
UnmapViewOfFile
UnregisterWaitEx
UpdateProcThreadAttribute
VerSetConditionMask
VerifyVersionInfoW
VirtualAlloc
VirtualAllocEx
VirtualFree
VirtualFreeEx
VirtualProtect
VirtualProtectEx
VirtualQuery
WaitForSingleObject
WaitForSingleObjectEx
WakeAllConditionVariable
WakeConditionVariable
WideCharToMultiByte
WriteConsoleW
WriteFile
WriteProcessMemory
WINHTTP.dll WinHttpAddRequestHeaders
WinHttpCloseHandle
WinHttpConnect
WinHttpOpen
WinHttpOpenRequest
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpReceiveResponse
WinHttpSendRequest
WinHttpSetOption
gdiplus.dll GdipAlloc
GdipCloneImage
GdipCreateBitmapFromScan0
GdipCreateFromHDC
GdipDeleteGraphics
GdipDisposeImage
GdipDrawImageRectI
GdipFree
GdipGetImageGraphicsContext
GdipGetImagePixelFormat
GdiplusShutdown
GdiplusStartup
IPHLPAPI.DLL GetAdaptersAddresses
WINMM.dll timeBeginPeriod
timeEndPeriod
timeGetTime
USERENV.dll CreateEnvironmentBlock
DestroyEnvironmentBlock
ntdll.dll RtlInitUnicodeString
tt_crash_reporter_dylib.dll (delay-loaded) TTCrashReporterInit
TTCrashReporterSetExeFolder
TTCrashReporterTestStub

Delayed Imports

Attributes 0x1
Name tt_crash_reporter_dylib.dll
ModuleHandle 0x20d938
DelayImportAddressTable 0x20d978
DelayImportNameTable 0x1e8fe8
BoundDelayImportTable 0
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

?kFuseWire@electron@@3QBDB

Ordinal 1
Address 0x1c8880

AmdPowerXpressRequestHighPerformance

Ordinal 2
Address 0x1ffda4

Cr_z_adler32

Ordinal 3
Address 0xa4ab0

Cr_z_adler32_combine

Ordinal 4
Address 0xa4ac0

Cr_z_adler32_z

Ordinal 5
Address 0xa47a0

Cr_z_crc32

Ordinal 6
Address 0xa45b0

Cr_z_crc32_combine

Ordinal 7
Address 0xa45e0

Cr_z_crc32_combine_gen

Ordinal 8
Address 0xa46d0

Cr_z_crc32_combine_op

Ordinal 9
Address 0xa4760

Cr_z_crc32_z

Ordinal 10
Address 0xa3e70

Cr_z_get_crc_table

Ordinal 11
Address 0xa3e60

Cr_z_zError

Ordinal 12
Address 0xa3e40

Cr_z_zlibCompileFlags

Ordinal 13
Address 0xa3e30

Cr_z_zlibVersion

Ordinal 14
Address 0xa3e20

GetHandleVerifier

Ordinal 15
Address 0xb2a30

IsSandboxedProcess

Ordinal 16
Address 0xa9850

NvOptimusEnablement

Ordinal 17
Address 0x1ffda0

TtFusesGetFuseWire

Ordinal 18
Address 0x20430

1

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x254
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.53783
Detected Filetype PNG graphic file
MD5 71b796644976e52ffdc9f4df9ca46ebe 🔍
SHA1 65a0e70f33a53c1ecb5d82156ceea71c525fb905 🔍
SHA256 972a0c3e52d2c2f0ab056b0c91a50ac1c4bf74a966c55df58183d3c7a448b4e4 🔍
SHA3 485e9817f97972760f285d5f421b99f38836c0c573b452426563bd6b71c185b7 🔍

2

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x353
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.74714
Detected Filetype PNG graphic file
MD5 bd8da3c45ad06a0087e5fc28622b0575 🔍
SHA1 9a25f8300d5e79f9dd4a4e6ca34806dbed1aa912 🔍
SHA256 1ef61761b19997a14984e49e943b7b50831cd21f5862e7e0752fa668040fc685 🔍
SHA3 4b4ce4f860cfac98e2301baa9d928a1c4358858ecc6a39ae642231aa9d0155f9 🔍

3

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x4b2
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.80883
Detected Filetype PNG graphic file
MD5 91274837e7523bfdff9d8f400d023818 🔍
SHA1 5feff11378b52fc18856c78739cab3bfd2a6845f 🔍
SHA256 e7c3bb90ee872ab7b32cbf9067db0499d5e3a4337ac7fabf977a9bf9297b6b9c 🔍
SHA3 1e4cea3d4f2247356973a198dc82e7a842a3271a0399ea7c327da3ea1addbaf2 🔍

4

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x6ec
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.86355
Detected Filetype PNG graphic file
MD5 e6a599945699117cd3a60f562bfe3f46 🔍
SHA1 c77ec0d9999abb05076682cb2b9a7ed75685339e 🔍
SHA256 05a77a7ab5a290413257a89a908a613a33018afef1876784d8c6aeb108b485e5 🔍
SHA3 8207c44ca3f9065b157cd919a812ecad89a7f3b3c3475eb293934aa5dc44ab19 🔍

5

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x8f5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.89271
Detected Filetype PNG graphic file
MD5 39bfe5bce2163656d69f98efa412a632 🔍
SHA1 cc56d000b0dc58e83015c9b4b4920c7e0776c850 🔍
SHA256 e43b2032cb9c9fa416c3bc258322022728e60e0b664029a462c4d5c1a12ca7a0 🔍
SHA3 381f9e3247016afb416ea0212a027cf0547d780e16d097adbb8093633bb2a68d 🔍

6

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x127c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.93789
Detected Filetype PNG graphic file
MD5 88ad40bba164fd84338fc2876bd2f6a1 🔍
SHA1 789437e6a8f7db3cff96c9a5cb74101710901a04 🔍
SHA256 751935e18065d2e6b8b693732fc73059342deb893d1a46314296e0550b70a020 🔍
SHA3 c763cc43d4ae60f3defa38b203ebdb95b1574e7e1d5f1e3b96f1e5d9858b844b 🔍

7

Type RT_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x2654
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.94864
Detected Filetype PNG graphic file
MD5 374c411de27772bb6db07d6d4648a5b2 🔍
SHA1 2e463f7dd92cbf6e201ce8a1c467a2ec671045e2 🔍
SHA256 4945ea8c5de3673a8e6c6d3e942c907ae44e158407187e4f366161ea0ecff664 🔍
SHA3 d9a1a168c26fb2a09d64bd36581f711dedebf03ab24f681ebe55a74aad427e1a 🔍

13

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x64
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.64953
MD5 803ee43a87c3257d04eee9e9b5f18038 🔍
SHA1 228c5e2ba3081d76b329411305e4fc23c6ef2d81 🔍
SHA256 e252851c77381de477b8b19af497d5a3c67653e59c8dace60413e6d579918d04 🔍
SHA3 a94fb9ee4021f4416d83e1ee6386c44723757e452e8c41b29e3770c264d841d2 🔍

14

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x58
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.48836
MD5 8d161634f4944a210de353527833552d 🔍
SHA1 b12e2562fcd2a106d3ed3da100d24a0b227108bf 🔍
SHA256 50cb9c04840bd38e94e218e06324c69e3ce91e5f5c87dcdea15c2cca4c8ea77f 🔍
SHA3 23cb3ba45c2ff073a4835a370219e845e05a33d25d3c7ab2c8218d37849bfd41 🔍

19

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x50
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.21444
MD5 67b65a89b16fcd2cc103023e9669f8b2 🔍
SHA1 538890935fb7d9b9015751b2ba27f9df31193dcc 🔍
SHA256 65b31b1b296266d6d5726d0c6a09bd2bd845962c028f57c37cfb8723285a4e50 🔍
SHA3 594985bec065b40755f2fc6d33d1e117295fda1059a6b146758cf31fd89c049b 🔍

26

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x24
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0.614369
MD5 1c23c671b858fb5f196bfe248b236a24 🔍
SHA1 fb5b0116cdf58e43b17ce119e6a3b645868612c2 🔍
SHA256 4aa4343af2857fa02201ca9c485b162eeeed8c6bb4b1936edad6386c9d8c1662 🔍
SHA3 dfbdaa3fb6752a2b935b759b48d85eb4a93af010d9e632ea7fe2c6175ae3bf2a 🔍

32

Type RT_STRING
Language English - United States
Codepage Latin 1 / Western European
Size 0x228
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.49593
MD5 694a1251a2f8b8df59dd8529d1464795 🔍
SHA1 6ca6e86a0eb8814d94dd74a7d6a45022762dff05 🔍
SHA256 2b45acf98c11d7343f7248edab5109609d1ece5752e3bf897406593b04f1ef9c 🔍
SHA3 a1ce7366ebcba097a6768dce795fb4fba580aaa0e65249005159bd4bccca8f2d 🔍

100

Type RT_RCDATA
Language English - United States
Codepage Latin 1 / Western European
Size 0x5a28
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.93307
Detected Filetype Zip Compressed Archive
MD5 ec0ef6e8aef83e263761b53626569573 🔍
SHA1 b9036c4b5fbf06d5f2b2772dc21f00d9d9218101 🔍
SHA256 56f999ab5e7fc436df980657987de24522ac2656925d1d38b5bed8c0aaefe081 🔍
SHA3 3b2e25aaa99a693eb1ec07c0866ee45394e99c74a8d47639e57925589fe719a3 🔍

1 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage Latin 1 / Western European
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.64573
Detected Filetype Icon file
MD5 305bf7417f4854cd6f6b4f9e597fdd1f 🔍
SHA1 edab77a08bdb98502dbce05298e88faee53f9419 🔍
SHA256 d9aaa74b640bac9a1176d501d709d52d12ad26d018beeb988b78fc7e8aa2969e 🔍
SHA3 049faa0ceacedb844578d986006f8323004055279c781b13996df54e287d8876 🔍

1 (#3)

Type RT_VERSION
Language English - United States
Codepage Latin 1 / Western European
Size 0x33c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.38468
MD5 411f5208c72a4886dd967d37105bb138 🔍
SHA1 db5d7d964de8294064c4a8dd538d997439bf3afa 🔍
SHA256 a93ca7fd2ec70bf7db38111339efd12b1c40594f6ef9842252044cd5d7e602a6 🔍
SHA3 8f6982489cd3552556a465c2770f9a8fd620d0427036dc75bf010947aa6e6c71 🔍

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage Latin 1 / Western European
Size 0x5ce
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.33954
MD5 decd2d457d0a9efbf4f317ca20fdcd86 🔍
SHA1 06dba9cb5ec0c07bc5b66f31c149ea5a570c3db4 🔍
SHA256 45f2a9711939f63490964f8b6611d5d84a58b847e2e6607f23bf6c16ec8cceb7 🔍
SHA3 241203e87af4d3eb016e8bf87586aaffdff41d1d8543ed97c61cbd2a10a6d03e 🔍

String Table contents

0
electron
0
0
default_app_shell_app
[]
0
1
0
0
0
app_shell_launcher
1.0.0
0
0
default_app_shell_name
0
0
{"oversea":true,"cls_id":"{5DA6FD3E-637B-4E89-87DB-B4BD8D72D6B1}","iid":"{639AB3C3-3B11-43A3-8C7C-222698CAF2EC}","service_name":"LiveStudioElevationService","display_name":"Tiktok Live Studio ElevationService","reg_key":"SOFTWARE\\ByteDance\\TiktokLiveStudio"}

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 1.35.2.0
ProductVersion 1.35.2.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName TikTok Pte. Ltd.
FileDescription TikTok LIVE Studio
FileVersion (#2) 1.35.2
InternalName TikTok LIVE Studio
LegalCopyright Copyright © 2026 TikTok Pte. Ltd.
OriginalFilename
ProductName TikTok LIVE Studio
ProductVersion (#2) 1.35.2.0
SquirrelAwareVersion 1
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-11 21:18:28
Version 0.0
SizeofData 41
AddressOfRawData 0x1e7448
PointerToRawData 0x1e5a48
Referenced File electron.exe.pdb

TLS Callbacks

StartAddressOfRawData 0x14022e000
EndAddressOfRawData 0x14022e200
AddressOfIndex 0x14020dd70
AddressOfCallbacks 0x1401e8e58
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_16BYTES
Callbacks 0x00000001400E6970
0x000000014014E0D0
0x00000001400DE3A0
0x000000014014D470
0x000000014003A980
0x00000001401193F0

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1401ff040
GuardCFCheckFunctionPointer 5370711360
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

Errors

Leave a comment

No comments yet.