| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Aug-26 21:34:48 |
| Detected languages |
English - United States
|
| Debug artifacts |
C:\Users\adamd\OneDrive\Documents\femware\src\build\CLAUDEAI.pdb
|
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to CRC32
Uses constants related to SHA1 Uses known Mersenne Twister constants |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| MD5 | 8dd584ba5620d7b5b9fb8aabe2582c82 🔍 |
|---|---|
| SHA1 | 9b3d17758a48f6ffe4f7993222ea5a90c11f97ce 🔍 |
| SHA256 | d6976755acbd2419f13f04ef3665759be519873d11f40c3886fa45967f3a96d4 🔍 |
| SHA3 | a9777d810c661f11976d57e9422b1839fb049a1703820b42beaba83267ea8297 🔍 |
| SSDeep | 98304:z3YEHGcpQWJ2o/Y7mgTm05AwJHE6hGLYklZqL9PlFH:FHGl8ng7PAmkzL/ZqL1lF 🔍 |
| Imports Hash | 6fa084a369dd9bb6729cf3dff8d557d0 🔍 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2026-Aug-26 21:34:48 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x1dc200 |
| SizeOfInitializedData | 0x341e00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x000000000019FC50 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x524000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| MD5 | b555f279dcabbf0e8b3a8ff1f1dc3011 🔍 |
|---|---|
| SHA1 | afaea5f4373f1b235f0f61a9cd2fc6cb54592ff3 🔍 |
| SHA256 | ecfe8c67d419985f36ae3272794b209b925aab43bd83196f03ed6d8ee3d17543 🔍 |
| SHA3 | 0455074739cebad86fc0df670be87a6d5764d926abcedf0e3abbf9b6a32dcf30 🔍 |
| VirtualSize | 0x1dc19c |
| VirtualAddress | 0x1000 |
| SizeOfRawData | 0x1dc200 |
| PointerToRawData | 0x400 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
|
| Entropy | 6.52881 |
| MD5 | 9f3af96aa4e1b93df906a6562a3807cf 🔍 |
|---|---|
| SHA1 | f5db930cf13b505b6a018ae7e0de56c9e593933d 🔍 |
| SHA256 | 414a214f4a2b4807f1bea80294e2e3d5af5bc389be65c75a0ed8fb7208b51e47 🔍 |
| SHA3 | ab13faa682b6d52a6b020dadbd1bf00345525c520716d3aa42441397749bf6c5 🔍 |
| VirtualSize | 0x16f3d0 |
| VirtualAddress | 0x1de000 |
| SizeOfRawData | 0x16f400 |
| PointerToRawData | 0x1dc600 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.5551 |
| MD5 | a1149bea992e0b020dd9945b0037a5b2 🔍 |
|---|---|
| SHA1 | 42bc91664f820181a44bd7db2a381656788613ff 🔍 |
| SHA256 | 379c6d657b39f754f01bc77a0cc525903209510ac3311a5e530ca66de73b1099 🔍 |
| SHA3 | c6df715f78e4f223a44f17a9c5fad22ceb239f30cbd411ab383992bcc710f1f2 🔍 |
| VirtualSize | 0x1bd7a4 |
| VirtualAddress | 0x34e000 |
| SizeOfRawData | 0x1b6200 |
| PointerToRawData | 0x34ba00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 5.72694 |
| MD5 | 5412cbe9862d5cebc937d7ac068c9b78 🔍 |
|---|---|
| SHA1 | 5da9d85ad159b5819ad9648b6b06434579b07ef9 🔍 |
| SHA256 | de355b8716b2584b8af0ae799caac18834651cf7d447194c13f1ef5535c455e3 🔍 |
| SHA3 | 941345eac1bc6702d9d995742fdba09a35252d0106755a0f568e30cb2e71a40a 🔍 |
| VirtualSize | 0x1317c |
| VirtualAddress | 0x50c000 |
| SizeOfRawData | 0x13200 |
| PointerToRawData | 0x501c00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 6.25728 |
| MD5 | bf619eac0cdf3f68d496ea9344137e8b 🔍 |
|---|---|
| SHA1 | 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍 |
| SHA256 | 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍 |
| SHA3 | 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍 |
| VirtualSize | 0x100 |
| VirtualAddress | 0x520000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x514e00 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
|
| Entropy | 0 |
| MD5 | 2b1272d032e085b8ce6880a7c3063060 🔍 |
|---|---|
| SHA1 | 14cc98e63df1d72ff58a14ec17382c88332f2f0b 🔍 |
| SHA256 | 782306a41edb84c7e2f9981baeb09e0ee91ff0323f77629207dcd75f33bdbda3 🔍 |
| SHA3 | ff3833adee54f7b0ee3e1ed523513e427e287eb6a616bddee84c29c0dd9a0f3b 🔍 |
| VirtualSize | 0x1e8 |
| VirtualAddress | 0x521000 |
| SizeOfRawData | 0x200 |
| PointerToRawData | 0x515000 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
|
| Entropy | 4.77204 |
| MD5 | f513ff18b49b25dcd07882188b2dabe1 🔍 |
|---|---|
| SHA1 | fa401d7ad695c497d549dc32da120a204e986bf8 🔍 |
| SHA256 | 8e678568fa5544004021da361ce5269ca5538e3969a54da1b8eba4217878f045 🔍 |
| SHA3 | 93b4122d74e727e3aa3457a2e8c9912fa5bc46b9fe8f34765c2e4a291f4749c4 🔍 |
| VirtualSize | 0x1b38 |
| VirtualAddress | 0x522000 |
| SizeOfRawData | 0x1c00 |
| PointerToRawData | 0x515200 |
| PointerToRelocations | 0 |
| PointerToLineNumbers | 0 |
| NumberOfLineNumbers | 0 |
| NumberOfRelocations | 0 |
| Characteristics |
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
|
| Entropy | 5.39214 |
| WINHTTP.dll |
WinHttpOpen
WinHttpReadData WinHttpOpenRequest WinHttpCloseHandle WinHttpSendRequest WinHttpConnect WinHttpReceiveResponse |
|---|---|
| COMDLG32.dll |
GetOpenFileNameA
|
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
| ntdll.dll |
RtlPcToFileHeader
RtlLookupFunctionEntry RtlCaptureContext VerSetConditionMask RtlUnwindEx RtlUnwind RtlVirtualUnwind |
| KERNEL32.dll |
GetModuleHandleA
GetLocaleInfoA MultiByteToWideChar LoadLibraryA QueryPerformanceFrequency GetProcAddress FreeLibrary QueryPerformanceCounter GlobalAlloc GlobalFree GlobalLock WideCharToMultiByte GlobalUnlock Sleep ReadFile WriteFile PeekNamedPipe GetTickCount64 GetLastError CreateFileA CloseHandle GetCurrentProcessId SwitchToThread GetConsoleWindow Module32Next GetProcessId Module32First OpenProcess CreateToolhelp32Snapshot Process32NextW Process32FirstW lstrcmpiW SetThreadPriority GetCurrentThread ReadProcessMemory SetPriorityClass SetConsoleTitleA GetCurrentProcess CreateThread QueryFullProcessImageNameW GetExitCodeProcess GetFileSizeEx HeapAlloc HeapReAlloc HeapFree GetProcessHeap MapViewOfFile UnmapViewOfFile CreateFileMappingA VirtualProtect ReadConsoleW GetConsoleMode SetFilePointerEx GetFileType UnhandledExceptionFilter SetStdHandle GetCommandLineW GetCommandLineA GetStdHandle GetModuleFileNameW IsProcessorFeaturePresent TerminateProcess ExitProcess FreeLibraryAndExitThread ExitThread FlsFree FlsSetValue FlsGetValue FlsAlloc SetLastError InitializeSListHead GetSystemTimeAsFileTime GetStartupInfoW SetUnhandledExceptionFilter GetStringTypeW GetCPInfo DecodePointer EncodePointer DeleteCriticalSection InitializeCriticalSectionEx LeaveCriticalSection EnterCriticalSection LCMapStringEx GetFileInformationByHandleEx GetModuleHandleW AreFileApisANSI CreateFile2 SetFileInformationByHandle GetFileAttributesExW CreateFileW HeapSize WriteConsoleW SetEndOfFile FindNextFileW FindFirstFileExW FindFirstFileW LoadLibraryExW SetEnvironmentVariableW FreeEnvironmentStringsW GetEnvironmentStringsW FindClose CompareStringW LCMapStringW GetLocaleInfoW IsDebuggerPresent GetOEMCP GetACP IsValidCodePage CreateProcessW WaitForSingleObject GetConsoleOutputCP FlushFileBuffers EnumSystemLocalesW GetUserDefaultLCID GetSystemTimePreciseAsFileTime ReleaseSRWLockExclusive AcquireSRWLockExclusive GetCurrentThreadId ReleaseSRWLockShared AcquireSRWLockShared SleepConditionVariableSRW RaiseException FreeLibraryWhenCallbackReturns CreateThreadpoolWork SubmitThreadpoolWork CloseThreadpoolWork GetModuleHandleExW InitOnceComplete InitOnceBeginInitialize FormatMessageA WakeAllConditionVariable LocalFree GetLocaleInfoEx CreateDirectoryW IsValidLocale |
| USER32.dll |
MonitorFromPoint
GetWindowRect DestroyWindow SetWindowPos GetSystemMetrics SetWindowLongA SetWindowDisplayAffinity MessageBoxA DefWindowProcA CreateWindowExA SetLayeredWindowAttributes PeekMessageA UnregisterClassA PostQuitMessage RegisterClassExA UpdateWindow GetMessageA DispatchMessageA CallNextHookEx SetWindowsHookExA UnhookWindowsHookEx TranslateMessage GetWindowThreadProcessId IsWindow EnumWindows ShowWindow SetForegroundWindow FindWindowA SendInput OpenClipboard CloseClipboard EmptyClipboard GetClipboardData SetClipboardData GetKeyState GetMessageExtraInfo LoadCursorA GetDC ScreenToClient GetCapture ClientToScreen TrackMouseEvent GetKeyboardLayout GetForegroundWindow SetCapture SetCursor GetClientRect IsWindowUnicode ReleaseCapture SetCursorPos ReleaseDC GetCursorPos GetAsyncKeyState |
| GDI32.dll |
GetDeviceCaps
|
| SHELL32.dll |
SHGetFolderPathA
ShellExecuteW ShellExecuteA |
| D3DCOMPILER_47.dll |
D3DCompile
|
| dwmapi.dll |
DwmExtendFrameIntoClientArea
|
| IMM32.dll |
ImmReleaseContext
ImmGetContext ImmSetCompositionWindow ImmSetCandidateWindow |
| WINMM.dll |
PlaySoundA
timeBeginPeriod |
| Type |
RT_MANIFEST
|
|---|---|
| Language | English - United States |
| Codepage | UNKNOWN |
| Size | 0x188 |
| TimeDateStamp | 1980-Jan-01 00:00:00 |
| Entropy | 4.89623 |
| MD5 | b8e76ddb52d0eb41e972599ff3ca431b 🔍 |
| SHA1 | fc12d7ad112ddabfcd8f82f290d84e637a4d62f8 🔍 |
| SHA256 | 165c5c883fd4fd36758bcba6baf2faffb77d2f4872ffd5ee918a16f91de5a8a8 🔍 |
| SHA3 | 37f83338b28cb102b1b14f27280ba1aa3fffb17f7bf165cb7b675b7e8eb7cddd 🔍 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-26 21:34:48 |
| Version | 0.0 |
| SizeofData | 89 |
| AddressOfRawData | 0x32b02c |
| PointerToRawData | 0x32962c |
| Referenced File | C:\Users\adamd\OneDrive\Documents\femware\src\build\CLAUDEAI.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-26 21:34:48 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x32b088 |
| PointerToRawData | 0x329688 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-26 21:34:48 |
| Version | 0.0 |
| SizeofData | 1052 |
| AddressOfRawData | 0x32b09c |
| PointerToRawData | 0x32969c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-26 21:34:48 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x14032b500 |
|---|---|
| EndAddressOfRawData | 0x14032b558 |
| AddressOfIndex | 0x140504a38 |
| AddressOfCallbacks | 0x1401de9d0 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x14034e380 |
| XOR Key | 0x5fa0ae2a |
|---|---|
| Unmarked objects | 0 |
| C++ objects (33145) | 191 |
| C objects (33145) | 43 |
| ASM objects (33145) | 25 |
| 253 (35721) | 1 |
| C objects (35721) | 19 |
| ASM objects (35721) | 14 |
| C++ objects (35721) | 105 |
| C objects (VS2022 Update 7 (17.7.0-3) compiler 32822) | 27 |
| Imports (33145) | 25 |
| Total imports | 257 |
| C++ objects (LTCG) (36256) | 75 |
| ASM objects (36256) | 1 |
| Resource objects (36256) | 1 |
| Linker (36256) | 1 |
No comments yet.