fm.exe threat report

MD5 7553aa008793fe2b94b8ab8897886ce7
Latest seen 2024-06-12 23:02:22 (2 years ago)
First seen 2024-06-12 23:02:22 (2 years ago)
Size 553 MB
Publisher Sports Interactive

This report summarizes the file identity, detection status, publisher metadata, observed locations, and technical indicators for fm.exe. ThreatInfo currently classifies this sample as Trojan.Heur!.

GridinSoft Anti-Malware detection

GridinSoft already detects this file

The latest ThreatInfo record shows fm.exe detected as Trojan.Heur!. You can download GridinSoft Anti-Malware to scan the system and remove this detection if the file is present on your device.

Detection name
Trojan.Heur!
Last analysis
2024-06-12 23:02:22 (2 years ago)
File hash
7553aa008793fe2b94b8ab8897886ce7
Download Anti-Malware

fm.exe is a Windows file recorded in the ThreatInfo database. It is associated with Football Manager 2021 Touch. The reported company name is Sports Interactive. The current detection status is Trojan.Heur!, based on the latest analysis from 2024-06-12 23:02:22 (2 years ago).

If fm.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Trojan.Heur!.

Product Name: Football Manager 2021 Touch
Company Name: Sports Interactive
MD5: 7553aa008793fe2b94b8ab8897886ce7
Size: 553 MB
First Published: 2024-06-12 23:02:22 (2 years ago)
Latest Published: 2024-06-12 23:02:22 (2 years ago)
Status: Trojan.Heur! (on last analysis)
Analysis Date: 2024-06-12 23:02:22 (2 years ago)
fm.exe detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%sysdrive%\steamlibrary\steamapps\common

ThreatInfo has observed fm.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Brazil with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for fm.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

fm.exe is identified as pe for 64 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x22a0e020

PE Sections:

Name Size of data MD5
.data 98498048 b9d85109359b9c3d39dd2d816b7ea7d6
.xpdata 2072576 32c305e75c920a1173a99b2b443f6d75
.udata 15567360 3c41a5348720bd1821e012e222093250
.sbss 935424 af6e58ceef06c60027253685fa8035a1
.xcode 512 bf619eac0cdf3f68d496ea9344137e8b
.rdata 39936 e7240ad3e7158980a75ad35696fe2be5
.sdata 191488 8d65c087c2170e95f687f3d45e1cf5f8
.srdata 459481600 adc9d4c6c3225969d4066de366ce0992
.data1 85504 9b4aa2cf8896b0b901dc64db01a3e469
.trace 512 8f6435c9d29d3b93e92f0a4dc312bc88
.debug 512 d6834f056c5b1e1f0ea5866b0e5eb079
.didata 16896 e22701ccc7cbc1aa79514ae6c45e2d63
.debug$P 512 2496428dd66764e4a44177a92468d6e6
.xtls 512 02e06cec04a11cc5f178ac610a350176
.bss 512 bea80d1f5b162e123fc547272bb96d34
.arch 29696 7ef31f8bc6fe14477841b23f902560bb
.text1 50688 2b19b8f9c829d08c3b3adada0ae51a2e
.code 2859520 d27e591ee14ac5bc3a06a21956766ebb
.impdata 151040 8aed701ffd1cd4887c487512b0855680

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: