d6976755acbd2419f13f04ef3665759be519873d11f40c3886fa45967f3a96d4

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2026-Aug-26 21:34:48
Detected languages English - United States
Debug artifacts C:\Users\adamd\OneDrive\Documents\femware\src\build\CLAUDEAI.pdb

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • SoundBible.com
  • adobe.com
  • assetdelivery.roblox.com
  • crl.microsoft.com
  • discord.com
  • en.wikipedia.org
  • fontstruct.com
  • http://crl.microsoft.com
  • http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0
  • http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0X
  • http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
  • http://en.wikipedia.org
  • http://en.wikipedia.org/wiki/MIT_License
  • http://ns.adobe.com
  • http://ns.adobe.com/tiff/1.0/
  • http://ns.adobe.com/xap/1.0/
  • http://ns.adobe.com/xap/1.0/mm/
  • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
  • http://purl.org
  • http://www.gimp.org
  • http://www.gimp.org/xmp/
  • http://www.microsoft.com
  • http://www.microsoft.com/Typography
  • http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0
  • http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0
  • http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
  • http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0
  • http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0a
  • http://www.microsoft.com/pkiops/docs/primarycps.htm0
  • http://www.styleseven.comFreeware
  • http://www.styleseven.comSmallest
  • http://www.w3.org
  • http://www.w3.org/1999/02/22-rdf-syntax-ns#
  • https://assetdelivery.roblox.com
  • https://assetdelivery.roblox.com/v1/asset/?id
  • https://discord.gg
  • https://fontstruct.com
  • https://fontstruct.comparasiticSpong
  • https://fontstruct.comparasiticSponge
  • https://offsets.imtheo.lol
  • https://offsets.imtheo.lol/
  • inkscape.org
  • microsoft.com
  • ns.adobe.com
  • roblox.com
  • wikipedia.org
  • www.gimp.org
  • www.inkscape.org
  • www.microsoft.com
  • www.w3.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA1
Uses known Mersenne Twister constants
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryA
  • GetProcAddress
  • LoadLibraryExW
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
  • CreateToolhelp32Snapshot
  • FindWindowA
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
  • ShellExecuteA
Uses functions commonly found in keyloggers:
  • CallNextHookEx
  • GetForegroundWindow
  • GetAsyncKeyState
Has Internet access capabilities:
  • WinHttpOpen
  • WinHttpReadData
  • WinHttpOpenRequest
  • WinHttpCloseHandle
  • WinHttpSendRequest
  • WinHttpConnect
  • WinHttpReceiveResponse
Manipulates other processes:
  • OpenProcess
  • Process32NextW
  • Process32FirstW
  • ReadProcessMemory
Can take screenshots:
  • FindWindowA
  • GetDC
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 8dd584ba5620d7b5b9fb8aabe2582c82 🔍
SHA1 9b3d17758a48f6ffe4f7993222ea5a90c11f97ce 🔍
SHA256 d6976755acbd2419f13f04ef3665759be519873d11f40c3886fa45967f3a96d4 🔍
SHA3 a9777d810c661f11976d57e9422b1839fb049a1703820b42beaba83267ea8297 🔍
SSDeep 98304:z3YEHGcpQWJ2o/Y7mgTm05AwJHE6hGLYklZqL9PlFH:FHGl8ng7PAmkzL/ZqL1lF 🔍
Imports Hash 6fa084a369dd9bb6729cf3dff8d557d0 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x118

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Aug-26 21:34:48
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x1dc200
SizeOfInitializedData 0x341e00
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000019FC50 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x524000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 b555f279dcabbf0e8b3a8ff1f1dc3011 🔍
SHA1 afaea5f4373f1b235f0f61a9cd2fc6cb54592ff3 🔍
SHA256 ecfe8c67d419985f36ae3272794b209b925aab43bd83196f03ed6d8ee3d17543 🔍
SHA3 0455074739cebad86fc0df670be87a6d5764d926abcedf0e3abbf9b6a32dcf30 🔍
VirtualSize 0x1dc19c
VirtualAddress 0x1000
SizeOfRawData 0x1dc200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.52881

.rdata

MD5 9f3af96aa4e1b93df906a6562a3807cf 🔍
SHA1 f5db930cf13b505b6a018ae7e0de56c9e593933d 🔍
SHA256 414a214f4a2b4807f1bea80294e2e3d5af5bc389be65c75a0ed8fb7208b51e47 🔍
SHA3 ab13faa682b6d52a6b020dadbd1bf00345525c520716d3aa42441397749bf6c5 🔍
VirtualSize 0x16f3d0
VirtualAddress 0x1de000
SizeOfRawData 0x16f400
PointerToRawData 0x1dc600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.5551

.data

MD5 a1149bea992e0b020dd9945b0037a5b2 🔍
SHA1 42bc91664f820181a44bd7db2a381656788613ff 🔍
SHA256 379c6d657b39f754f01bc77a0cc525903209510ac3311a5e530ca66de73b1099 🔍
SHA3 c6df715f78e4f223a44f17a9c5fad22ceb239f30cbd411ab383992bcc710f1f2 🔍
VirtualSize 0x1bd7a4
VirtualAddress 0x34e000
SizeOfRawData 0x1b6200
PointerToRawData 0x34ba00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 5.72694

.pdata

MD5 5412cbe9862d5cebc937d7ac068c9b78 🔍
SHA1 5da9d85ad159b5819ad9648b6b06434579b07ef9 🔍
SHA256 de355b8716b2584b8af0ae799caac18834651cf7d447194c13f1ef5535c455e3 🔍
SHA3 941345eac1bc6702d9d995742fdba09a35252d0106755a0f568e30cb2e71a40a 🔍
VirtualSize 0x1317c
VirtualAddress 0x50c000
SizeOfRawData 0x13200
PointerToRawData 0x501c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.25728

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0x520000
SizeOfRawData 0x200
PointerToRawData 0x514e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 2b1272d032e085b8ce6880a7c3063060 🔍
SHA1 14cc98e63df1d72ff58a14ec17382c88332f2f0b 🔍
SHA256 782306a41edb84c7e2f9981baeb09e0ee91ff0323f77629207dcd75f33bdbda3 🔍
SHA3 ff3833adee54f7b0ee3e1ed523513e427e287eb6a616bddee84c29c0dd9a0f3b 🔍
VirtualSize 0x1e8
VirtualAddress 0x521000
SizeOfRawData 0x200
PointerToRawData 0x515000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.77204

.reloc

MD5 f513ff18b49b25dcd07882188b2dabe1 🔍
SHA1 fa401d7ad695c497d549dc32da120a204e986bf8 🔍
SHA256 8e678568fa5544004021da361ce5269ca5538e3969a54da1b8eba4217878f045 🔍
SHA3 93b4122d74e727e3aa3457a2e8c9912fa5bc46b9fe8f34765c2e4a291f4749c4 🔍
VirtualSize 0x1b38
VirtualAddress 0x522000
SizeOfRawData 0x1c00
PointerToRawData 0x515200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.39214

Imports

WINHTTP.dll WinHttpOpen
WinHttpReadData
WinHttpOpenRequest
WinHttpCloseHandle
WinHttpSendRequest
WinHttpConnect
WinHttpReceiveResponse
COMDLG32.dll GetOpenFileNameA
d3d11.dll D3D11CreateDeviceAndSwapChain
ntdll.dll RtlPcToFileHeader
RtlLookupFunctionEntry
RtlCaptureContext
VerSetConditionMask
RtlUnwindEx
RtlUnwind
RtlVirtualUnwind
KERNEL32.dll GetModuleHandleA
GetLocaleInfoA
MultiByteToWideChar
LoadLibraryA
QueryPerformanceFrequency
GetProcAddress
FreeLibrary
QueryPerformanceCounter
GlobalAlloc
GlobalFree
GlobalLock
WideCharToMultiByte
GlobalUnlock
Sleep
ReadFile
WriteFile
PeekNamedPipe
GetTickCount64
GetLastError
CreateFileA
CloseHandle
GetCurrentProcessId
SwitchToThread
GetConsoleWindow
Module32Next
GetProcessId
Module32First
OpenProcess
CreateToolhelp32Snapshot
Process32NextW
Process32FirstW
lstrcmpiW
SetThreadPriority
GetCurrentThread
ReadProcessMemory
SetPriorityClass
SetConsoleTitleA
GetCurrentProcess
CreateThread
QueryFullProcessImageNameW
GetExitCodeProcess
GetFileSizeEx
HeapAlloc
HeapReAlloc
HeapFree
GetProcessHeap
MapViewOfFile
UnmapViewOfFile
CreateFileMappingA
VirtualProtect
ReadConsoleW
GetConsoleMode
SetFilePointerEx
GetFileType
UnhandledExceptionFilter
SetStdHandle
GetCommandLineW
GetCommandLineA
GetStdHandle
GetModuleFileNameW
IsProcessorFeaturePresent
TerminateProcess
ExitProcess
FreeLibraryAndExitThread
ExitThread
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
SetLastError
InitializeSListHead
GetSystemTimeAsFileTime
GetStartupInfoW
SetUnhandledExceptionFilter
GetStringTypeW
GetCPInfo
DecodePointer
EncodePointer
DeleteCriticalSection
InitializeCriticalSectionEx
LeaveCriticalSection
EnterCriticalSection
LCMapStringEx
GetFileInformationByHandleEx
GetModuleHandleW
AreFileApisANSI
CreateFile2
SetFileInformationByHandle
GetFileAttributesExW
CreateFileW
HeapSize
WriteConsoleW
SetEndOfFile
FindNextFileW
FindFirstFileExW
FindFirstFileW
LoadLibraryExW
SetEnvironmentVariableW
FreeEnvironmentStringsW
GetEnvironmentStringsW
FindClose
CompareStringW
LCMapStringW
GetLocaleInfoW
IsDebuggerPresent
GetOEMCP
GetACP
IsValidCodePage
CreateProcessW
WaitForSingleObject
GetConsoleOutputCP
FlushFileBuffers
EnumSystemLocalesW
GetUserDefaultLCID
GetSystemTimePreciseAsFileTime
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
GetCurrentThreadId
ReleaseSRWLockShared
AcquireSRWLockShared
SleepConditionVariableSRW
RaiseException
FreeLibraryWhenCallbackReturns
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
GetModuleHandleExW
InitOnceComplete
InitOnceBeginInitialize
FormatMessageA
WakeAllConditionVariable
LocalFree
GetLocaleInfoEx
CreateDirectoryW
IsValidLocale
USER32.dll MonitorFromPoint
GetWindowRect
DestroyWindow
SetWindowPos
GetSystemMetrics
SetWindowLongA
SetWindowDisplayAffinity
MessageBoxA
DefWindowProcA
CreateWindowExA
SetLayeredWindowAttributes
PeekMessageA
UnregisterClassA
PostQuitMessage
RegisterClassExA
UpdateWindow
GetMessageA
DispatchMessageA
CallNextHookEx
SetWindowsHookExA
UnhookWindowsHookEx
TranslateMessage
GetWindowThreadProcessId
IsWindow
EnumWindows
ShowWindow
SetForegroundWindow
FindWindowA
SendInput
OpenClipboard
CloseClipboard
EmptyClipboard
GetClipboardData
SetClipboardData
GetKeyState
GetMessageExtraInfo
LoadCursorA
GetDC
ScreenToClient
GetCapture
ClientToScreen
TrackMouseEvent
GetKeyboardLayout
GetForegroundWindow
SetCapture
SetCursor
GetClientRect
IsWindowUnicode
ReleaseCapture
SetCursorPos
ReleaseDC
GetCursorPos
GetAsyncKeyState
GDI32.dll GetDeviceCaps
SHELL32.dll SHGetFolderPathA
ShellExecuteW
ShellExecuteA
D3DCOMPILER_47.dll D3DCompile
dwmapi.dll DwmExtendFrameIntoClientArea
IMM32.dll ImmReleaseContext
ImmGetContext
ImmSetCompositionWindow
ImmSetCandidateWindow
WINMM.dll PlaySoundA
timeBeginPeriod

Delayed Imports

1

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x188
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.89623
MD5 b8e76ddb52d0eb41e972599ff3ca431b 🔍
SHA1 fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍
SHA256 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍
SHA3 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍

Version Info

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-26 21:34:48
Version 0.0
SizeofData 89
AddressOfRawData 0x32b02c
PointerToRawData 0x32962c
Referenced File C:\Users\adamd\OneDrive\Documents\femware\src\build\CLAUDEAI.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Aug-26 21:34:48
Version 0.0
SizeofData 20
AddressOfRawData 0x32b088
PointerToRawData 0x329688

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Aug-26 21:34:48
Version 0.0
SizeofData 1052
AddressOfRawData 0x32b09c
PointerToRawData 0x32969c

IMAGE_DEBUG_TYPE_ILTCG

Characteristics 0
TimeDateStamp 2026-Aug-26 21:34:48
Version 0.0
SizeofData 0
AddressOfRawData 0
PointerToRawData 0

TLS Callbacks

StartAddressOfRawData 0x14032b500
EndAddressOfRawData 0x14032b558
AddressOfIndex 0x140504a38
AddressOfCallbacks 0x1401de9d0
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x14034e380

RICH Header

XOR Key 0x5fa0ae2a
Unmarked objects 0
C++ objects (33145) 191
C objects (33145) 43
ASM objects (33145) 25
253 (35721) 1
C objects (35721) 19
ASM objects (35721) 14
C++ objects (35721) 105
C objects (VS2022 Update 7 (17.7.0-3) compiler 32822) 27
Imports (33145) 25
Total imports 257
C++ objects (LTCG) (36256) 75
ASM objects (36256) 1
Resource objects (36256) 1
Linker (36256) 1

Errors

Leave a comment

No comments yet.