3c970b0d220cae8827c3db68d69d6944cad6b56c1c45ffcf269b2ffc1bc96323

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Sep-05 15:48:34
Detected languages English - United States
TLS Callbacks 1 callback(s) detected.
Debug artifacts fut2d_setup.pdb
FileDescription fut2d-launcher
FileVersion 0.1.0
ProductName fut2d-launcher
ProductVersion 0.1.0

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains another PE executable:
  • This program cannot be run in DOS mode.
Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • GoDaddy.com
  • api.fut2d.com
  • cacerts.digicert.com
  • crl3.digicert.com
  • digicert.com
  • fut2d.com
  • http://cacerts.digicert.com
  • http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
  • http://cacerts.digicert.com/DigiCertTrustedG4TimeStampingRSA4096SHA2562025CA1.crt0_
  • http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
  • http://ccsca2021.crl.certum.pl
  • http://ccsca2021.crl.certum.pl/ccsca2021.crl0s
  • http://ccsca2021.ocsp-certum.com05
  • http://crl.certum.pl
  • http://crl.certum.pl/ctnca2.crl0l
  • http://crl3.digicert.com
  • http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
  • http://crl3.digicert.com/DigiCertTrustedG4TimeStampingRSA4096SHA2562025CA1.crl0
  • http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
  • http://ocsp.digicert.com0
  • http://ocsp.digicert.com0A
  • http://ocsp.digicert.com0C
  • http://repository.certum.pl
  • http://repository.certum.pl/ccsca2021.cer0
  • http://repository.certum.pl/ctnca2.cer09
  • http://subca.ocsp-certum.com02
  • http://www.certum.pl
  • http://www.certum.pl/CPS0
  • https://api.fut2d.com
  • https://api.fut2d.com/v1/diagnostics
  • https://api.fut2d.comURL
  • https://docs.rs
  • https://www.certum.pl
  • https://www.certum.pl/CPS0
  • openssl.org
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Uses constants related to SHA256
Uses constants related to SHA512
Suspicious The PE contains functions most legitimate programs don't use. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • LoadLibraryA
  • GetProcAddress
Functions which can be used for anti-debugging purposes:
  • SwitchToThread
Can access the registry:
  • RegSetValueExW
  • RegCloseKey
  • RegCreateKeyW
Possibly launches other programs:
  • CreateProcessW
Uses Windows's Native API:
  • NtReadFile
  • NtCreateNamedPipeFile
  • NtOpenFile
  • NtWriteFile
Info The PE is digitally signed. Signer: Daniel Vieira
Issuer: Certum Code Signing 2021 CA
Safe VirusTotal score: 0/71 (Scanned on 2026-09-05 17:45:01) All the AVs think this file is safe.

Hashes

MD5 a25be351a1a9bc6614e4dcd4ea15f472 🔍
SHA1 cdf64f1679a179fb9ac76a3f99ce4a39c2d90954 🔍
SHA256 3c970b0d220cae8827c3db68d69d6944cad6b56c1c45ffcf269b2ffc1bc96323 🔍
SHA3 dc6fdbc71288d146d6d6c38e62ed4a9469a3a9958e6bfedc3f335c2c0316d441 🔍
SSDeep 49152:FFyzQ4XaGyUXuNfIlVddQnlA+ukslM1rtxtDiRAqDQOErnchtQbXQDayuLL2Xw/E:FFy1NR6RFX2yrc4JLHIQLVSqH+7 🔍
Imports Hash a4ac9954f4e6e8e3f3d3aadd4ad7edde 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x100

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 7
TimeDateStamp 2026-Sep-05 15:48:34
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0x5a800
SizeOfInitializedData 0x551800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x000000000004A2E8 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x5af000
SizeOfHeaders 0x400
Checksum 0x5b8da1
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 5af3aff9f08043c855674366dbede0bb 🔍
SHA1 8be6e5b665e2ae4ae0f2349beb43cf0f3f5888c3 🔍
SHA256 01d1273c1c44929caf764a2c0c84bc27373bb4ba54d362efd4ce3018336216e1 🔍
SHA3 1d3c75c275f33245cee82ea4525c2304642cc3d3d47752fe369ffe27030e0b6a 🔍
VirtualSize 0x5a660
VirtualAddress 0x1000
SizeOfRawData 0x5a800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.4123

.rdata

MD5 a4f8ea04e803208c31359b1dac7c2dbb 🔍
SHA1 927efae4ac6b5f9fd39d8928b6d3e12dd93d2bd0 🔍
SHA256 ff55b898aea0418bcadd8f183869b5eed2d538129fd5730030dba8ecd953b199 🔍
SHA3 09d5f956bc2289c662e0d1c56903921270a0227dd315b7248a125a4f25386cd3 🔍
VirtualSize 0x546fc8
VirtualAddress 0x5c000
SizeOfRawData 0x547000
PointerToRawData 0x5ac00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.51074

.data

MD5 3a2f7c52c9d16d964de32de2c1d91548 🔍
SHA1 f429dc4e757df9659725773fec721e6fa2ebdeb8 🔍
SHA256 f47932b8f6d5021d38ccff76dcf6465f0445533bd8b7cad6af6eeb138960b3de 🔍
SHA3 753fbc1fffc2c16fcd57aa74612808b89a3cdd7eb7788f900cbf9e89cf8982b1 🔍
VirtualSize 0x1d78
VirtualAddress 0x5a3000
SizeOfRawData 0xc00
PointerToRawData 0x5a1c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.07412

.pdata

MD5 db990bfd28e65e027bfa11abfe1a0a22 🔍
SHA1 59c101bae97c27cf14c040330f549229b36a9794 🔍
SHA256 50034389f25caf33c032bc6e7d5154f830349a8330993ecb54962f83f16b2f86 🔍
SHA3 9684771d404a32c3ff1690ea678a3e70f6cafdc7d9467eb11ab5078810d2e29e 🔍
VirtualSize 0x3ef4
VirtualAddress 0x5a5000
SizeOfRawData 0x4000
PointerToRawData 0x5a2800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.77792

.fptable

MD5 bf619eac0cdf3f68d496ea9344137e8b 🔍
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 🔍
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560 🔍
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59 🔍
VirtualSize 0x100
VirtualAddress 0x5a9000
SizeOfRawData 0x200
PointerToRawData 0x5a6800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 b2bbeafa2f7d7b38f45f61f254626cb2 🔍
SHA1 538a0e3cb2b77505b85221e7e55654c228b7b0bd 🔍
SHA256 8a19b2335b297137a56ce38c5687edf8c98ae1c9d55fd19dfbea1a71aadcc7d7 🔍
SHA3 187f4d5c02fc491d0fb0e0305689b3a63077b9acee67f5980e9fb9441064398d 🔍
VirtualSize 0x3a08
VirtualAddress 0x5aa000
SizeOfRawData 0x3c00
PointerToRawData 0x5a6a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 7.5256

.reloc

MD5 580fd48678cfef19c9e7596f8367dcef 🔍
SHA1 5071b1b67765cb2cde959c12efec598401eef71c 🔍
SHA256 e204f61dad0dd1a15aa2ca86afb35d54e633a74b98b64142ddab867ba2d8a095 🔍
SHA3 f1092d7e2c6437538f6348e63e6f2ff443833da7fb87d2bdde25b22a558a3c50 🔍
VirtualSize 0xb50
VirtualAddress 0x5ae000
SizeOfRawData 0xc00
PointerToRawData 0x5aa600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.31582

Imports

shell32.dll SHGetKnownFolderPath
combase.dll CoTaskMemFree
kernel32.dll DuplicateHandle
GetCurrentProcess
CreateProcessW
GetFileInformationByHandleEx
GetFileInformationByHandle
SetFileInformationByHandle
SetFileTime
CreateFileW
CreateWaitableTimerExW
GetCurrentProcessId
CreateMutexA
GetCurrentThreadId
SetFilePointerEx
GetFullPathNameW
ReleaseMutex
FlushFileBuffers
SetThreadStackGuarantee
WriteFileEx
GetCurrentThread
WaitForSingleObjectEx
CopyFileExW
MoveFileExW
WideCharToMultiByte
SleepEx
ReadFileEx
CompareStringOrdinal
SetWaitableTimer
Sleep
LCMapStringW
CompareStringW
SwitchToThread
DeleteFileW
WaitForSingleObject
GetFileAttributesW
GetUserDefaultLocaleName
FindFirstFileExW
CreateThread
CloseHandle
GetLastError
LockFileEx
FindClose
lstrlenW
CreateDirectoryW
SetLastError
MultiByteToWideChar
FlsFree
GetStartupInfoW
IsProcessorFeaturePresent
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
WriteFile
ExitProcess
TerminateProcess
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
api-ms-win-core-synch-l1-2-0.dll WaitOnAddress
WakeByAddressSingle
WakeByAddressAll
ole32.dll CoInitializeEx
CoCreateInstance
CoUninitialize
ntdll.dll NtReadFile
RtlNtStatusToDosError
NtCreateNamedPipeFile
NtOpenFile
NtWriteFile
KERNEL32.dll GetSystemTimeAsFileTime
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
RtlUnwindEx
RtlPcToFileHeader
RaiseException
EncodePointer
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
LoadLibraryExW
GetModuleHandleExW
GetCommandLineA
SetEnvironmentVariableW
SetStdHandle
InitializeCriticalSectionEx
VirtualProtect
HeapSize
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
GetModuleHandleA
FormatMessageW
GetConsoleOutputCP
GetConsoleMode
WriteConsoleW
GetModuleFileNameW
HeapAlloc
LoadLibraryA
GetProcAddress
GetCommandLineW
GetEnvironmentVariableW
GetCurrentDirectoryW
AddVectoredExceptionHandler
GetWindowsDirectoryW
GetSystemDirectoryW
FreeEnvironmentStringsW
GetEnvironmentStringsW
QueryPerformanceCounter
QueryPerformanceFrequency
GetModuleHandleW
GetStdHandle
HeapReAlloc
HeapFree
GetProcessHeap
InitializeSListHead
user32.dll DispatchMessageW
TranslateMessage
GetMessageW
SetTimer
ShowWindow
CreateWindowExW
GetSystemMetrics
RegisterClassW
LoadCursorW
LoadIconW
InvalidateRect
GetClientRect
DrawTextW
FillRect
BeginPaint
PostQuitMessage
DefWindowProcW
DestroyWindow
KillTimer
GetWindowLongPtrW
SetWindowLongPtrW
MessageBoxW
EndPaint
gdi32.dll SetBkMode
SetTextColor
SelectObject
CreateFontW
DeleteObject
CreateSolidBrush
advapi32.dll CredEnumerateW
CredDeleteW
RegSetValueExW
RegCloseKey
RegCreateKeyW
RegDeleteTreeW
CredFree
comctl32.dll TaskDialogIndirect

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x13a0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.74553
Detected Filetype PNG graphic file
MD5 031046cf2faea6d6bd3109e5fc2ae617 🔍
SHA1 af82f1d8a43e497bc717cf063ec57d15340c966a 🔍
SHA256 3c9f8589fa26b5653a80bcb252c3d6f079f6e95c4ab55dc2540aa5a640117a47 🔍
SHA3 0f1f9f8331b5a1d08def75882f6356cd86b13f504d86715233101d9972d91667 🔍

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xde5
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.87142
Detected Filetype PNG graphic file
MD5 11c4cd6f2e2cde4337c60479d6137234 🔍
SHA1 aa8860da36c8c7d26a34a64ddd549ad088997771 🔍
SHA256 baf2517749eacd2fbe7f91b34ec39c16a8f2dd41adfdebe6de1f272be88159d3 🔍
SHA3 a84f552012c89736258937d64b67925dd171a250f36a014b8fe69cfad7c94221 🔍

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x6f1
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.82636
Detected Filetype PNG graphic file
MD5 ca66fd463430078f5789d7699f9b132e 🔍
SHA1 861f08c3d93521a066f9f3a41d14ec92bb647acd 🔍
SHA256 4ab0c8c543e87a8cb7aebf2a052837e633d43e6be17ee0c4e482c482da15a968 🔍
SHA3 0e0c489d2abdd7a5eab7bba9d7bc5d620af856b040d95bd56dbda52e23650231 🔍

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x52f
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.79782
Detected Filetype PNG graphic file
MD5 ccabf9f3916769f1c7870f3ed567e4d2 🔍
SHA1 63b40ddbc6c1f39b325550cdfe9f667db80a9ede 🔍
SHA256 8c01bbfab44ef19cda25d64b94c5287995076d2ecfc523cfc0eebde0982d1009 🔍
SHA3 1a97d2e98dcc8774698d027519d1853da3cb74f6954d39f0848c197fcbf65c60 🔍

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x3b3
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.70086
Detected Filetype PNG graphic file
MD5 c1d21c92e15b14ff359d2e2ef4469a8c 🔍
SHA1 9d4efb37d0b2dec53346ae7c250180b33c25f770 🔍
SHA256 578fa877564b5e7aee3237b8c6862b827b7a33871b7a2e73a5e2c0845ed5b7e7 🔍
SHA3 3d6d0a3db0e41e0bf4f1ac84eae3281dc8c7f326f33c71efc4c6e51950ce38f2 🔍

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x243
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 7.42751
Detected Filetype PNG graphic file
MD5 70dbefcfe5a8f49c92f44926f30c1a67 🔍
SHA1 f6656c4a06e0411f3688e3d2e9cb372daf77ba74 🔍
SHA256 64f0b23ce9e69d7af31f5cc11cbcdce5c4fc4a4a5e8a06cea9b95ecd46da99ad 🔍
SHA3 38fdb736a3f73fb819d24a1eeb33ddd8d71045f1d8054056915f9276ec88d7b0 🔍

1 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x5a
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.77149
Detected Filetype Icon file
MD5 9ba7000855ab70d6a318ad49500983aa 🔍
SHA1 afedaef0c74a8df401ee5499be2fddd445127b7a 🔍
SHA256 108ff7f79ce3fd79a2d61f6ef19852486f8b46824c9e9a57851fd763e772d618 🔍
SHA3 5b814a64601b825f64de88d3f28d7165e9c540c94bad1ed52e7c85b33c2dae40 🔍

1 (#3)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x1c0
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.11663
MD5 9b74bba4ac9dab2b5b6d555317b375fc 🔍
SHA1 44d0b8a3a21a8ed49cff3e40607d10fd95cc215e 🔍
SHA256 30f86d419654d9e53bb755f4e379835ee27edc8c4ad6200c54325b88ba3241af 🔍
SHA3 37880fba086cf1cf4aa4d63c9e60944b97aebc08b024ab768f2af8f75a9c44e5 🔍

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x213
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.98032
MD5 c12e482fe7dabbd6f30a7c09d54a8de8 🔍
SHA1 7bde3cece56b35f9aba5f029613d493c85566bbf 🔍
SHA256 6d5ba4254f411d164de3b7462cc3b21d60e748d61554104c885626746cb42560 🔍
SHA3 13a23eb4250369e1bee236d9c54bf8fc9563bbb5495bad2249b986d1115c5296 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 0.1.0.0
ProductVersion 0.1.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language UNKNOWN
FileDescription fut2d-launcher
FileVersion (#2) 0.1.0
ProductName fut2d-launcher
ProductVersion (#2) 0.1.0
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Sep-05 15:48:34
Version 0.0
SizeofData 40
AddressOfRawData 0x596b10
PointerToRawData 0x595710
Referenced File fut2d_setup.pdb

IMAGE_DEBUG_TYPE_VC_FEATURE

Characteristics 0
TimeDateStamp 2026-Sep-05 15:48:34
Version 0.0
SizeofData 20
AddressOfRawData 0x596b38
PointerToRawData 0x595738

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 2026-Sep-05 15:48:34
Version 0.0
SizeofData 1012
AddressOfRawData 0x596b4c
PointerToRawData 0x59574c

TLS Callbacks

StartAddressOfRawData 0x140596f88
EndAddressOfRawData 0x140596ff0
AddressOfIndex 0x1405a3cd0
AddressOfCallbacks 0x14005c610
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x0000000140043030

Load Configuration

Size 0x140
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1405a3140

RICH Header

XOR Key 0x2bd4aca2
Unmarked objects 0
C++ objects (33145) 141
C objects (33145) 12
ASM objects (33145) 8
ASM objects (35207) 9
C objects (35207) 16
C++ objects (35207) 41
Imports (33145) 3
Total imports 180
Unmarked objects (#2) 156
Resource objects (35228) 1
Linker (35228) 1

Errors

Leave a comment

No comments yet.