294d13b4c6b02ff0b65fab4c8344fb12

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2020-Dec-16 19:09:22

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • compnerd.org
Suspicious The PE is possibly packed. Unusual section name found: .gehcont
Unusual section name found: .sw5asty
Unusual section name found: .sw5bltn
Unusual section name found: .sw5cptr
Unusual section name found: .sw5entr
Unusual section name found: .sw5flmd
Unusual section name found: .sw5hash
Unusual section name found: .sw5prt
Unusual section name found: .sw5prtc
Unusual section name found: .sw5repl
Unusual section name found: .sw5reps
Unusual section name found: .sw5rfst
Unusual section name found: .sw5tymd
Unusual section name found: .sw5tyrf
Unusual section name found: swiftast
Safe VirusTotal score: 0/67 (Scanned on 2022-04-22 19:30:59) All the AVs think this file is safe.

Hashes

MD5 294d13b4c6b02ff0b65fab4c8344fb12
SHA1 95525bb09084e2fdaf5301335e1ecff1dd323700
SHA256 714f0e8b8b0f949bad25145620eaba60fe3002a93053f16adf87d28be583599b
SHA3 820ecada8f382e26effc8fd6a4da65b6a189ea539c2c664b26f6b28446625aec
SSDeep 384:hnz2Jokgv+Jjf0gKERsOkydbK4kFfnpq+pd/C/6REkYfsg8mp9hneKorl+NkIwN:sJokS+p0JEGO/dbQNUiRsB8mp9vxWB
Imports Hash 4625816843e2520ffd2256903126de69

DOS Header

e_magic MZ
e_cblp 0x78
e_cp 0x1
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0
e_ss 0
e_sp 0
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x78

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 21
TimeDateStamp 2020-Dec-16 19:09:22
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x2400
SizeOfInitializedData 0x6c00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000002904 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x1c000
SizeOfHeaders 0x600
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 03cb2868d9d77f791119641192507a5e
SHA1 a58a5756fc9f828685b5b91d01dd2b41351c4abc
SHA256 c0704aff6b836a283538c4504d4e843b1cbcebede4163d2dcdc63751d9afea20
SHA3 e3cf1c26665315e13652ddd31274265075aa5843897107495996358a13d9a27f
VirtualSize 0x2306
VirtualAddress 0x1000
SizeOfRawData 0x2400
PointerToRawData 0x600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 5.54167

.rdata

MD5 aceff964b75118ef9af809a6cc350242
SHA1 3f28a2af336e26cd7bfad7bb4d7bdb03f0e15d83
SHA256 aa2aae43af3e53124fa1f77c9f97232778a6a6123e9282da5ed6d81230b548fd
SHA3 d4c99a763847ea35bf90e768d9ca44a7eb57e4e6d69ba300bf1add53d0013b7a
VirtualSize 0x10f4
VirtualAddress 0x4000
SizeOfRawData 0x1200
PointerToRawData 0x2a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.22064

.data

MD5 080fb4df41392a0bf9d06cfa96544903
SHA1 9beac2c975c3707d20ab4bdc226ba13bc477656c
SHA256 698b05be867ef8fb4a52177609d28aa915052e1cbc9ae4970b3204eec09bd4c0
SHA3 658f862cc6d5e13fe95fff90acceab19a1a46be6d8c234904c55da83bd20063b
VirtualSize 0x1b0
VirtualAddress 0x6000
SizeOfRawData 0x200
PointerToRawData 0x3c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.464663

.pdata

MD5 756024283b6eb774b96d250b52689bfa
SHA1 19c5a4c11db9fab2143a00fe6d9357d16a702866
SHA256 c173a33cc9d22de7f876d06a4b8892cc8b87b9ebc7153467d35bc660abe4b605
SHA3 6cbe668a5d82af60850f189fa21ed25cae4d9bd11160ca424a4bb3e79e420278
VirtualSize 0x174
VirtualAddress 0x7000
SizeOfRawData 0x200
PointerToRawData 0x3e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.80477

.00cfg

MD5 8a25cfdd749857649c0e3f78bdb757fa
SHA1 3f1b41a0ec2aa68dc003bc86627f5f0362c5856f
SHA256 df9babdc9886be5ac686574802caacca5d81a85029acc274dd9addd86b9ee859
SHA3 62358b711952a837b71a2445858c44aca79a51252f5504eb9d3e53a6de8204ec
VirtualSize 0x28
VirtualAddress 0x8000
SizeOfRawData 0x200
PointerToRawData 0x4000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.309155

.gehcont

MD5 88a0d6c507dcb728b4ed32f1bc7c467c
SHA1 ef3cf8c7068b0f8b7d63fee9dbf2c0ca1bc2aad2
SHA256 bd593205e0358eca47916489ce53db94580b006711a7f456acc91c782bc5582c
SHA3 da318217fd6e805f390219e8c949414625af2aa686f0cb44c26714f61066d20f
VirtualSize 0x8
VirtualAddress 0x9000
SizeOfRawData 0x200
PointerToRawData 0x4200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.0407808

.sw5asty

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x10
VirtualAddress 0xa000
SizeOfRawData 0x200
PointerToRawData 0x4400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0

.sw5bltn

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x10
VirtualAddress 0xb000
SizeOfRawData 0x200
PointerToRawData 0x4600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0

.sw5cptr

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x10
VirtualAddress 0xc000
SizeOfRawData 0x200
PointerToRawData 0x4800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0

.sw5entr

MD5 a61d86b16b4ccdd8e67504b2167fbdfc
SHA1 41b4b6c8aaf1f9a086acc24ce8e0663f5a333fee
SHA256 1e222f389360748c3ed0b8a1ea6ee2c511fa20a921fdd5e8204ae8c2e7b0933e
SHA3 801cb20514713294a5eb1a345c24aac888256a57b457bd2fc0d1bc300839fcb3
VirtualSize 0x4
VirtualAddress 0xd000
SizeOfRawData 0x200
PointerToRawData 0x4a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.0572566

.sw5flmd

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x10
VirtualAddress 0xe000
SizeOfRawData 0x200
PointerToRawData 0x4c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0

.sw5hash

MD5 27b032423381494009214b8cc8f45c97
SHA1 1d16ecf3dc19b00ae6f68f2ebfb58d24e9d342d9
SHA256 69196a98a3103ef0e88035cfe4d335ec3190fadbcc41caf1e19a0fb1944ccbc1
SHA3 91f4876985f7ec6b9a3e6092d2a30adb6fcbdf73cd6b87136801a6c95dc72691
VirtualSize 0x10
VirtualAddress 0xf000
SizeOfRawData 0x200
PointerToRawData 0x4e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.325622

.sw5prt

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x10
VirtualAddress 0x10000
SizeOfRawData 0x200
PointerToRawData 0x5000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0

.sw5prtc

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x10
VirtualAddress 0x11000
SizeOfRawData 0x200
PointerToRawData 0x5200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0

.sw5repl

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x10
VirtualAddress 0x12000
SizeOfRawData 0x200
PointerToRawData 0x5400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0

.sw5reps

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x10
VirtualAddress 0x13000
SizeOfRawData 0x200
PointerToRawData 0x5600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0

.sw5rfst

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x10
VirtualAddress 0x14000
SizeOfRawData 0x200
PointerToRawData 0x5800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0

.sw5tymd

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x10
VirtualAddress 0x15000
SizeOfRawData 0x200
PointerToRawData 0x5a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0

.sw5tyrf

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x10
VirtualAddress 0x16000
SizeOfRawData 0x200
PointerToRawData 0x5c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0

swiftast

MD5 42c7a00f0642bbe7c6b16419ec6203d1
SHA1 9820954881bfe082fbf6c866c4f7dae7d7c0abeb
SHA256 05b879e00d9764cd569363a3111a1ec4938e18235b490012fd68501fbae69197
SHA3 321cba79b0d862f2747d37122bbd90ea142136724ad7e211f308b5368d791076
VirtualSize 0x35f0
VirtualAddress 0x17000
SizeOfRawData 0x3600
PointerToRawData 0x5e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.62207

.reloc

MD5 2e0be0d75ad1319dbeacc595f3d26a14
SHA1 386ce1636387f01d64714bdc2423aca8fcbc3a2a
SHA256 38ea3dafeeeb5faab7edcd272a111806f6eebfc7c9e50b2689a6511d622e78dc
SHA3 60ff57d9609341c23e79970b505197b0e11a3701b886bbe8a905a2e4be4abb88
VirtualSize 0x34
VirtualAddress 0x1b000
SizeOfRawData 0x200
PointerToRawData 0x9400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.607338

Imports

swiftSwiftOnoneSupport.dll $sSayxSicigSS_Tg5
$ss27_allocateUninitializedArrayySayxG_BptBwlFyp_Tg5
swiftCore.dll $sSJ2eeoiySbSJ_SJtFZ
$sSJ38_builtinExtendedGraphemeClusterLiteral17utf8CodeUnitCount7isASCIISJBp_BwBi1_tcfC
$sSJySJs7UnicodeO6ScalarVcfC
$sSS10startIndexSS0B0Vvg
$sSS21_builtinStringLiteral17utf8CodeUnitCount7isASCIISSBp_BwBi1_tcfC
$sSS5index_8offsetBySS5IndexVAD_SitF
$sSSN
$sSSySJSS5IndexVcig
$sSSySSSJcfC
$sSaMa
$sSbyS2bcfC
$sSiN
$sSis17FixedWidthIntegersMc
$ss11CommandLineO9argumentsSaySSGvgZ
$ss17FixedWidthIntegerPsEyxSgSScfC
$ss17_assertionFailure__4file4line5flagss5NeverOs12StaticStringV_A2HSus6UInt32VtF
$ss5print_9separator10terminatoryypd_S2StF
$ss7UnicodeO6ScalarVyADSgSicfC
$sypN
swift_addNewDSOImage
swift_bridgeObjectRelease
swift_getWitnessTable
swift_release
KERNEL32.dll GetCurrentProcessId
GetCurrentThreadId
GetModuleHandleW
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
QueryPerformanceCounter
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
SetUnhandledExceptionFilter
UnhandledExceptionFilter
VCRUNTIME140.dll __C_specific_handler
__current_exception
__current_exception_context
memset
api-ms-win-crt-runtime-l1-1-0.dll __p___argc
__p___argv
_c_exit
_cexit
_configure_narrow_argv
_crt_atexit
_exit
_get_initial_narrow_environment
_initialize_narrow_environment
_initialize_onexit_table
_initterm
_initterm_e
_register_onexit_function
_register_thread_local_exe_atexit_callback
_seh_filter_exe
_set_app_type
exit
terminate
api-ms-win-crt-stdio-l1-1-0.dll __p__commode
_set_fmode
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
api-ms-win-crt-heap-l1-1-0.dll _set_new_mode

Delayed Imports

$s8winSwift24integerToCharacterString3valSJSi_tF

Ordinal 1
Address 0x1350

$s8winSwift4argsSaySSGvp

Ordinal 2
Address 0x6108

$s8winSwift8validate5guessSbSS_tF

Ordinal 3
Address 0x13d0

main

Ordinal 4
Address 0x1200

Version Info

TLS Callbacks

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x140006010

RICH Header

Errors

[*] Warning: 1 invalid export(s) not shown.