Skip to content

Releases: theflakes/fmd

v1.1.5

Choose a tag to compare

@theflakes theflakes released this 02 Sep 12:03

Add Windows prefetch file analysis. This will also analyze the DLLs listed as loaded by the PE binary based upon the offsets loaded to try and determine what DLL exported functions may have been used by the binary.

Fixups, optimizations, and more DLL descriptions

Choose a tag to compare

@theflakes theflakes released this 31 May 17:00

Fixed sorted hash regression, a little more optimization, and more DLL and virtual DLL descriptions

v1.1.3

Choose a tag to compare

@theflakes theflakes released this 31 May 12:18

Using local LLM to learn how to create more optimized code

Fix arch identification on Windows ARM

Choose a tag to compare

@theflakes theflakes released this 30 May 20:34
v1.1.2

Hard setting sha1 and sha256 crates due to digest dependency mismatch

1.1.1

Choose a tag to compare

@theflakes theflakes released this 29 Sep 14:02

Code cleanup, update for abandoned package nom, update for updated package lnk

Cleaned up error handling some.

1.0.1 release

Choose a tag to compare

@theflakes theflakes released this 02 Jun 02:01

Fix for not identifying .Net DLLs.

  "hashes": {
    "md5": "425f0dad77889eff133b9fb8d2dcfad0",
    "sha1": "c5972e6629b3b9089a24d637262fd2938b862dec",
    "sha256": "6b5205f5063d538d95ec24f57c2d7b4bbefb3247b507b7a2ffe5cf517fa1942a",
    "ssdeep": "12288:IfO21hr9/kIqSHuROQl2ZNWypzWZCal8/+HdGZJzwHS8SZI:IfO+/kIqSOoDkmWIEHShI"
  },

FMD v1.0.0

Choose a tag to compare

@theflakes theflakes released this 09 Jul 16:34

Updated interesting mimetypes that should be examined.

  "hashes": {
    "md5": "5053e0c1bd144d41a222f10fd0ecc3bf",
    "sha1": "4eef7ffdd30bf91a051c9dafc1750c86fe9d8724",
    "sha256": "9a975a2a14ab54bf008349de9b8bec42ae60abf10120e70dad0a9dcae3aea2da",
    "ssdeep": "12288:jBe33uvQk+ZZkpAcmEi0fw57rMrZEE9rvW6JHDu0NQQEggbM:jBe33uvHAcmEleEc260NYgg"
  }

0.9.9

Choose a tag to compare

@theflakes theflakes released this 08 May 14:10

Beginning to add information on imports and tagging them if they are "more interesting". A lot of work still to be done on gathering information on more interesting imports.

{
  "name": "GetModuleHandleExW",
  "more_interesting": true,
  "info": "Retrieves a module handle for the specified module and increments the module's reference count."
}

FMD hashes:

"hashes": {
  "md5": "f771e9ca94e03156d156e59cf1108acf",
  "sha1": "b2e11e6a56d6195959a48dbc59503e82ae656f5c",
  "sha256": "e2862b30b4629f48068edd292fd100e8ff2d9c0f5b621cdd5dd994f48de38205",
  "ssdeep": "12288:iTUxmsNjTtfnRRIAk/HsnDvj5eqpb8qhLx7VcptoZ:iTUTtfDIX/Hs35xpbrX7Gpti"
},

Add more LNK metadata and fix original filename

Choose a tag to compare

@theflakes theflakes released this 21 Apr 14:45

Add more LNK metadata and fix original filename

{
  "md5":"17fb8a62cbe5fcbe731845d28207e9b4",
  "sha1":"a8229e7e2f28834e40ab44e10c1041cf7d946927",
  "sha256":"73f1582ff383e7db34ee10f92a57a6c16213b3635c38e19ffb0ea40a8e00668c",
  "ssdeep":"12288:sshY35h+be2o8KP6s71mvHKAe3luV/du52ISqsfmWsn4:sshYOK2o8NsRmPKA4wVVzISlf"
}

0.9.4 FMD

Choose a tag to compare

@theflakes theflakes released this 27 Jan 02:22

Fix for crash on parsing certain bin file types. Improved error handling when the problem is encountered.

"md5":"729e4a560c865f7cc28725337abcb4a0",
"sha1":"8df4ca63445baac454f17aa773ad8f21d8e72abf",
"sha256":"3da337a3655a4188166df7f3def588336c95d1f9647bb75453a743e0679e357c