d2bf0ca4b417e9bd8c60c761e4bcd7df

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2021-Sep-25 21:56:47
Detected languages English - United States
FileDescription UnstoppableSwap
FileVersion 1.0.0-rc.11
LegalCopyright
ProductName UnstoppableSwap
ProductVersion 1.0.0-rc.11

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • http://nsis.sf.net
  • http://nsis.sf.net/NSIS_Error
  • nsis.sf.net
Suspicious The PE is an NSIS installer Unusual section name found: .ndata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Can access the registry:
  • RegCreateKeyExW
  • RegEnumKeyW
  • RegQueryValueExW
  • RegSetValueExW
  • RegCloseKey
  • RegDeleteValueW
  • RegDeleteKeyW
  • RegOpenKeyExW
  • RegEnumValueW
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Changes object ACLs:
  • SetFileSecurityW
Can shut the system down or lock the screen:
  • ExitWindowsEx
Suspicious The file contains overlay data. 12387970 bytes of data starting at offset 0xce00.
The overlay data has an entropy of 7.99998 and is possibly compressed or encrypted.
Overlay data amounts for 99.5761% of the executable.
Suspicious VirusTotal score: 2/71 (Scanned on 2025-01-10 13:38:55) Bkav: W32.AIDetectMalware
Cylance: Unsafe

Hashes

MD5 d2bf0ca4b417e9bd8c60c761e4bcd7df
SHA1 298b0086dbe3e7a100db1485c89855a84bc53300
SHA256 669aa4be00073ed98acc77d0e1359ab9669b70fa1d495dd9e64cb1f1875b84ed
SHA3 15ac5dbf5201ff1afc68a18e27b7cd5fc6a5ed90e7b5e68899c802f7bdc07342
SSDeep 196608:ndpGFk1XvCc0xYYRaqaLxU6H+WQsniVjeIDdIH9D2A+bkts4UqFRgqaGPPG:nnZdKc0xJaFbHBjniVjnErtswFCt
Imports Hash 61259b55b8912888e90f516ca08dc514

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xd8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2021-Sep-25 21:56:47
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 6.0
SizeOfCode 0x6800
SizeOfInitializedData 0x22a00
SizeOfUninitializedData 0x800
AddressOfEntryPoint 0x00003640 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x8000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 6.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x5e000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 6f5abe9eeda26ee84b3c1ed1a6c82001
SHA1 55517dc6ad93689679677d152abfdd1ce20f1135
SHA256 6683c31450d22725f8046313577f87ed284052143421d41ca971ebf03a732b4a
SHA3 0166ffe9450ef9b8cd85513de36173358cc6d06134a32f515f12aa858073020f
VirtualSize 0x6676
VirtualAddress 0x1000
SizeOfRawData 0x6800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.41746

.rdata

MD5 8c5edfd8ff9cc0135e197611be38ca18
SHA1 dc4f14d019cad6646b38852dfb7370532acafebc
SHA256 95df72950424a97746c83c619f9aa736879b408a87751927b5d41994e8183a9c
SHA3 b74f8f6ea5fb7e429da44419f9d163743fd38ce97f3b9819fb2397744d42dad2
VirtualSize 0x139a
VirtualAddress 0x8000
SizeOfRawData 0x1400
PointerToRawData 0x6c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.14107

.data

MD5 4b2421975c21b032f7ea000f5e7f9fbf
SHA1 f45486287d474fdcafc99c24e37c4eb61bf613b3
SHA256 f05daf3c91cc357d04794a740f21eaaeb870f250877e3a6dc498c5c3046cb414
SHA3 03ddd58bddd9af320b79e443521aae041b4098e328b842349f29c2bda6bdb122
VirtualSize 0x20378
VirtualAddress 0xa000
SizeOfRawData 0x600
PointerToRawData 0x8000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.11058

.ndata

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x2e000
VirtualAddress 0x2b000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rsrc

MD5 6c2b0944f746f2a29ff3ed67fc39d176
SHA1 64ffd25ff0be8d5fdfc8e6fadcfc879492204cc9
SHA256 1e527c8818370362610cb6a853daa56a5838bc8a8f8f63db2667e7cc9742fea1
SHA3 138468ce670c2b9bd61ac63146a1b78343d9f3f77885b4c715522018c94cb8f6
VirtualSize 0x4690
VirtualAddress 0x59000
SizeOfRawData 0x4800
PointerToRawData 0x8600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.89094

Imports

ADVAPI32.dll RegCreateKeyExW
RegEnumKeyW
RegQueryValueExW
RegSetValueExW
RegCloseKey
RegDeleteValueW
RegDeleteKeyW
AdjustTokenPrivileges
LookupPrivilegeValueW
OpenProcessToken
SetFileSecurityW
RegOpenKeyExW
RegEnumValueW
SHELL32.dll SHGetSpecialFolderLocation
SHFileOperationW
SHBrowseForFolderW
SHGetPathFromIDListW
ShellExecuteExW
SHGetFileInfoW
ole32.dll OleInitialize
OleUninitialize
CoCreateInstance
IIDFromString
CoTaskMemFree
COMCTL32.dll #17
ImageList_Create
ImageList_Destroy
ImageList_AddMasked
USER32.dll GetClientRect
EndPaint
DrawTextW
IsWindowEnabled
DispatchMessageW
wsprintfA
CharNextA
CharPrevW
MessageBoxIndirectW
GetDlgItemTextW
SetDlgItemTextW
GetSystemMetrics
FillRect
AppendMenuW
TrackPopupMenu
OpenClipboard
SetClipboardData
CloseClipboard
IsWindowVisible
CallWindowProcW
GetMessagePos
CheckDlgButton
LoadCursorW
SetCursor
GetSysColor
SetWindowPos
GetWindowLongW
PeekMessageW
SetClassLongW
GetSystemMenu
EnableMenuItem
GetWindowRect
ScreenToClient
EndDialog
RegisterClassW
SystemParametersInfoW
CreateWindowExW
GetClassInfoW
DialogBoxParamW
CharNextW
ExitWindowsEx
DestroyWindow
CreateDialogParamW
SetTimer
SetWindowTextW
PostQuitMessage
SetForegroundWindow
ShowWindow
wsprintfW
SendMessageTimeoutW
FindWindowExW
IsWindow
GetDlgItem
SetWindowLongW
LoadImageW
GetDC
ReleaseDC
EnableWindow
InvalidateRect
SendMessageW
DefWindowProcW
BeginPaint
EmptyClipboard
CreatePopupMenu
GDI32.dll SetBkMode
SetBkColor
GetDeviceCaps
CreateFontIndirectW
CreateBrushIndirect
DeleteObject
SetTextColor
SelectObject
KERNEL32.dll GetExitCodeProcess
WaitForSingleObject
GetModuleHandleA
GetProcAddress
GetSystemDirectoryW
lstrcatW
Sleep
lstrcpyA
WriteFile
GetTempFileNameW
lstrcmpiA
RemoveDirectoryW
CreateProcessW
CreateDirectoryW
GetLastError
CreateThread
GlobalLock
GlobalUnlock
GetDiskFreeSpaceW
WideCharToMultiByte
lstrcpynW
lstrlenW
SetErrorMode
GetVersionExW
GetCommandLineW
GetTempPathW
GetWindowsDirectoryW
SetEnvironmentVariableW
CopyFileW
ExitProcess
GetCurrentProcess
GetModuleFileNameW
GetFileSize
CreateFileW
GetTickCount
MulDiv
SetFileAttributesW
GetFileAttributesW
SetCurrentDirectoryW
MoveFileW
GetFullPathNameW
GetShortPathNameW
SearchPathW
CompareFileTime
SetFileTime
CloseHandle
lstrcmpiW
lstrcmpW
ExpandEnvironmentStringsW
GlobalFree
GlobalAlloc
GetModuleHandleW
LoadLibraryExW
MoveFileExW
FreeLibrary
WritePrivateProfileStringW
GetPrivateProfileStringW
lstrlenA
MultiByteToWideChar
ReadFile
SetFilePointer
FindClose
FindNextFileW
FindFirstFileW
DeleteFileW

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.26612
MD5 0ec0a0948a526b9c7eebe39bb02b6b0b
SHA1 867b304f20fd74abeb5c30515837f1c41cd3bf8f
SHA256 d442adb90ba296c7e617d2f58d6fa6f308bcd8ef65e5e9c66db4dd27f93fcfbe
SHA3 5bc458755a2ca5c7475620389d9b6b67952973c4366c6777d45c969b8bc67cd4

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.9993
MD5 6b224e01af48ec8e4c17a59d9534e885
SHA1 de787d2a1e840618ba2c7eb69d28f6966c404d1d
SHA256 50279c9885b490e74b49ac0273940b6e0891b62fc9ffb5c52e35422a694f248b
SHA3 71b543301bccda64ba61a27873c952890233e0cbec10e0b59245fc303bcfadbc

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.24459
MD5 ca82d899b1d402941b5c92ed9028cd95
SHA1 fb329ec4455d5caf1753305debcc14ab6ebb9015
SHA256 9da1013c864092e49c2676b3ba68a0d4513457d77d251730ed73cc5f4a4813b1
SHA3 768277223731ffdcb799e50961d0afccf23bbae54118d53b834617ccbd0c5cd9

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.01502
MD5 05e60fd47096a729dda2aaa4ab05ebc7
SHA1 de8ec9b484fa4f565b14f55503c9cd95231b633b
SHA256 61f762babde9942f43ee97154b8734efeed0632a6ea778dc395793ae3e3e7507
SHA3 f8ba0d4a91389414904cc66226099f27f482055e90ba449e2396193f139713d8

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.16057
MD5 d9ee3a2962251a241bce41b0524cfc0e
SHA1 2ba919aaa7237367a158e4b95385ab1ee07643d8
SHA256 69e6579a37fcaec037634e7fecbfc6a26093ea81dc4bd555d8a12187d2cd0866
SHA3 a1699668464f7edf9a748dfc264f9d30e3c69a228be0a18cade30c14aa6c77ba

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.34146
MD5 53482d364aa2d4ae7ca05199dad7651a
SHA1 ccb213408acc7f5ddb94753e6410be23aab5cedd
SHA256 ff06189b43a5c1d6cc5d1b7cbf6ab56b1157ec52807945d652274a211462cba5
SHA3 60659e39ef3f267c267093f8bc4c87ed61eea4ef96ac0f583184f580844573e5

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.04232
MD5 636ad42555a835e3a94209043df4a45a
SHA1 c878613bda5cba6cb5769846e60229890c5df248
SHA256 491e52ded039ec6684277e6f1f820e288763ae6d20e682bcfffb6cee4518ac23
SHA3 4b79e60727e0f7be7495c59fb949e22bd753cff6e145e4694257a21a7b5dba8c

103

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x120
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56193
MD5 db6dd0434da4d7cac564518725167e09
SHA1 a65a1367d7cd96450f089a8f8108239bbcea9f5b
SHA256 c50631fc1f8425a95fd1edcc8e730d339e193a38f18d42372c32847a5ad2c016
SHA3 4e3be5455c51e1cb04836e318cb69ecdffd2deadd0f338d4bc985d8f5ca653ff

105

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x202
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.73893
MD5 386770584473e271f23dced36427f4ff
SHA1 d14ce95f784b35e4e3ebee535476ebcd3e380c19
SHA256 425b8270f7ca42a927eae6bea468acf414a3e4b58b5ba2c56aaae4d1b2c11014
SHA3 db13e5969376b27e8443eebff685230e2b74685aeb2fba73973f06e5cddc8662

106

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.91148
MD5 fa83652660409e90e0db9731ad2adb17
SHA1 0a8f0af67723c87fe26ccf676b8e19ec6357b4dc
SHA256 4a55bd714f5d50cd8eabba10e57f0618f1842717dcfa582d73a917b1933cd1d4
SHA3 5b3e1cb25be7a2dbae4f08f0d4794ed23dbd6ea37a3f9702be12dba588f42a7b

107

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xa0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.52183
MD5 6ffba239dcfcab2080195f23947b70aa
SHA1 bcda1ca8ee9bb9878bde83aa06c670bb5a4d5843
SHA256 a7e5ea849cb343e9b58de221aeb25c9dd4a3748070bfba879a30c4265fc39023
SHA3 a75544b4c3fcbcb32fe4e02d1a631e045b2e58516aa1065bb96cce681aea7030

111

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xee
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.92767
MD5 1db3e4c32b9560257ddf3506fef9dd3f
SHA1 6666e0c8336456cfacec71d84415c6516e9e2673
SHA256 587a03198c39f990e77691056bb5705e21374281862ce06de94c68172f50f763
SHA3 30ca0affc3f1d2ef8b37f2103db7581caaf88548823fb3ae1d308fae9738dab4

103 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.6691
Detected Filetype Icon file
MD5 e624f041c921d299a6da3a8c5f48f989
SHA1 ffa07c86ac3dac45398ee07b26610dfb5c99d8ea
SHA256 fed46e06346fb8f64b14c18408a82caf955929ac0e65151630539dc5bd194584
SHA3 b51d47dbe9cbe18b1f520275504256022a827f919672b081943ae45cd4ff44c9

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x200
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.1909
MD5 ee44421d6481257b909a6648554e75a3
SHA1 449ac1c72efb6089172a6f1b91212f06bf1b9511
SHA256 cf6822b400aa6cc1af5883b1f3c7d03fd7918503d0607719443ff08ab7d6dca5
SHA3 cfa544812c60ffb0c14da8de6dc6bbdb71e738ed4695f14b0869a4c653242140

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x548
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.28651
MD5 74bd1c9761bde4540e0ce44a22adc8d9
SHA1 3887d7d5641fa941e4a7045496a6b67d45ddda7b
SHA256 5fe6e1123b916d49e917b7b90ba08196b2eaf5919b6b54ca2287a47070a49d63
SHA3 04345f5c159bd835d0f660688bc78b3cdd1695e1dc6555b44cc684a29af0dc20

Version Info

Signature 0xfeef04bd
StructVersion 0
FileVersion 1.0.0.0
ProductVersion 1.0.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
FileDescription UnstoppableSwap
FileVersion (#2) 1.0.0-rc.11
LegalCopyright
ProductName UnstoppableSwap
ProductVersion (#2) 1.0.0-rc.11
Resource LangID English - United States

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0xd26650e9
Unmarked objects 0
C objects (VS2003 (.NET) build 4035) 2
Total imports 165
Imports (VS2003 (.NET) build 4035) 15
48 (9044) 10
Resource objects (VS98 SP6 cvtres build 1736) 1

Errors

[*] Warning: Section .ndata has a size of 0!
<-- -->