Gridinsoft Logo
File Icon

The Swift.exe (swift-new) File Analysis

Technical Analysis

File Name Swift.exe
File Type
Win32 EXE
Magic Bytes MS-DOS executable PE32+ executable (GUI) x86-64, for MS Windows, MZ for MS-DOS
SSDEEP Hash
393216:H4TWihKOqnU9jpjI9JT4YNIGiapB89/9RQXuab0TlRVnK2UvWiDYY:YNqiI9llNIdapBqFUdDYY
Scanner Version 1.0.220.174
Database Version 2025-07-18 03:00:32 UTC

Suspicious File Detected

Detected by 13 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
18%
Detection Rate
20,255,260
File Size (bytes)
13/72
Engines Detected
2025-07-18
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
0033b392c5624d739c95af6cbb56d778
SHA1
837df1989cbb4887f067d8faf167e13a437162f4
SHA256
90bc42881701c5be22be13b4f962708f09cb7b2e3a4623473da5e17550ee4b1f
SHA512
0930d1cd2d5baffa8ec2a817c5a9e3ce63684906dbdf63b1c073d013071f7f99b807a6c1116538d1444fbb05010085310c23c76cf497dc7c2eb9b09722ef2049
ImpHash
27d1d2d05684f98ecd5681b9b60151b9

Security Engines with Detections (13 of 72)

Bkav
W64.AIDetectMalware Malicious
Elastic
malicious (high confidence) Malicious
Skyhigh
Artemis Malicious
Cylance
Unsafe Malicious
Symantec
ML.Attribute.HighConfidence Malicious
Paloalto
generic.ml Malicious
McAfeeD
ti!90BC42881701 Malicious
Trapmine
malicious.moderate.ml.score Malicious
Webroot
Win.Backdoor.Xworm Malicious
Microsoft
HackTool:Win32/Malgent!MSR Malicious
TrellixENS
Artemis!0033B392C562 Malicious
Fortinet
W32/PossibleThreat Malicious
DeepInstinct
MALICIOUS Malicious
59 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 344c130d20b26e802ca02eef66055cca
Fuzzy: cfcfb46cc9bd8210a71eb5734fcaffd2
dHash: 00004484d6d100c0
Image Base 0x140000000
Entry Point 0x143a45000
Compilation Time 2025-07-16 16:08:26
Checksum 0x0135b83e (Actual: 0x0135b83e)
OS Version 6.0
PEiD Signatures MS-DOS executable PE32+ executable (GUI) x86-64, for MS Windows, MZ for MS-DOS
Digital Signature No valid SignedData structure was found.
Imports 35 libraries
Exports 0 functions
Resources 26 Resources
Sections 14 Sections

Version Information

CompanyName swift
FileVersion 0.1.0
ProductName swift-new
FileDescription swift-new
ProductVersion 0.1.0
Translation 0x0000 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
0x00001000 16,066,460 bytes 3,678,208 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 4702BD07CF56DDFB0D818FBEB050C1F4
0x00f54000 7,969,100 bytes 2,936,320 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D0FF3B4641AF74CAB8E6C286000D0810
0x016ee000 114,648 bytes 6,144 bytes 7.96 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 636399953AA264F764FB0EE41CFF7F06
0x0170a000 1,011,708 bytes 328,704 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 75162C07CD1416C1731B3241F95D1B5C
0x01801000 11,264 bytes 9,216 bytes 7.86 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ F1EFED73CDB1C4C4C4ECCDD689ED17AB
0x01804000 101,728 bytes 21,504 bytes 7.98 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 2904FCA9F990D7361BB955B6AF0A49F3
.idata 0x0181d000 4,096 bytes 2,560 bytes 4.31 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE E9A0C92AA559C653ABAFA9DC56494C09
.tls 0x0181e000 4,096 bytes 1,024 bytes 0.29 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 099F204BD5E6E5720DCE39ADB0B44718
.rsrc 0x0181f000 17,408 bytes 17,408 bytes 6.84 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 01F963D0768FE3AC85BC6D23A4B971A1
.themida 0x01824000 22,528,000 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.loadcon 0x02da0000 4,096 bytes 512 bytes 0.63 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 3934C66C4B618BFFE0C44051EEA97B12
.boot 0x02da1000 13,252,096 bytes 13,252,096 bytes 7.96 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 200685E254C7FFBA1EAF1D6EAEAA8708
.init 0x03a45000 512 bytes 512 bytes 2.70 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 2A549C5EC6656718301411EF3C34B331
.reloc 0x03a46000 4,096 bytes 28 bytes 3.16 (Normal) IMAGE_SCN_MEM_READ 111371776B3A1136056D4BEA7B17D32C
Entropy Analysis Alert

7 section(s) with high entropy (≥7.5) detected - possible packing/encryption

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 26 (15,672 bytes)
Resource Type Count Total Size Percentage
RT_ICON 6 9,574 bytes
61.1%
RT_DIALOG 7 1,704 bytes
10.9%
RT_STRING 5 66 bytes
0.4%
RT_RCDATA 5 3,219 bytes
20.5%
RT_GROUP_ICON 1 90 bytes
0.6%
RT_VERSION 1 468 bytes
3%
RT_MANIFEST 1 551 bytes
3.5%

Certificate Chain Analysis

Certificate Information
Product swift-new
Description swift-new
File Version 0.1.0

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
13 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware