File name:

Elden Ring Nightreign v1.01 Plus 26 Trainer.exe

Full analysis: https://app.any.run/tasks/53e3e5f3-188b-4eba-a9da-37dd1c01d5e5
Verdict: Malicious activity
Analysis date: June 01, 2025, 17:53:07
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
flingtrainer
cheat
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

2D01872CD080BF1F6FCB51AA38FC6BDB

SHA1:

3DA9021D306CC631489FFA02BE0B7260E466120C

SHA256:

14358D5B23A59929550F6B01D389F87235222B1A4C2E0F998E8DB1B6539125BD

SSDEEP:

49152:2bsysBypV3pfK+u4NghZy7yXJK+oI2SJWCgYiaGvarRCpOVYMplfd5M1cYzfhf:2bsysBypV3pfK+u2ghZbJWCgYBTVlfdg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • FLINGTRAINER mutex has been found

      • Elden Ring Nightreign v1.01 Plus 26 Trainer.exe (PID: 7360)
  • INFO

    • Disables trace logs

      • Elden Ring Nightreign v1.01 Plus 26 Trainer.exe (PID: 7360)
    • Checks supported languages

      • Elden Ring Nightreign v1.01 Plus 26 Trainer.exe (PID: 7360)
    • Creates files or folders in the user directory

      • Elden Ring Nightreign v1.01 Plus 26 Trainer.exe (PID: 7360)
    • Reads Environment values

      • Elden Ring Nightreign v1.01 Plus 26 Trainer.exe (PID: 7360)
    • Reads the machine GUID from the registry

      • Elden Ring Nightreign v1.01 Plus 26 Trainer.exe (PID: 7360)
    • Reads the computer name

      • Elden Ring Nightreign v1.01 Plus 26 Trainer.exe (PID: 7360)
    • Checks proxy server information

      • Elden Ring Nightreign v1.01 Plus 26 Trainer.exe (PID: 7360)
    • Reads the software policy settings

      • Elden Ring Nightreign v1.01 Plus 26 Trainer.exe (PID: 7360)
      • slui.exe (PID: 5968)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:05:30 03:31:37+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.43
CodeSize: 619520
InitializedDataSize: 836096
UninitializedDataSize: -
EntryPoint: 0x6d518
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: 3DMGAME
FileDescription: Elden Ring Nightreign v1.01 Plus 26 Trainer
FileVersion: 1.0.0.0
InternalName: Elden Ring Nightreign v1.01 Plus 26 Trainer
LegalCopyright: FLiNG Copyright (C) 2025
OriginalFileName: Elden Ring Nightreign v1.01 Plus 26 Trainer.exe
ProductName: Elden Ring Nightreign v1.01 Plus 26 Trainer
ProductVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
131
Monitored processes
4
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start #FLINGTRAINER elden ring nightreign v1.01 plus 26 trainer.exe sppextcomobj.exe no specs slui.exe elden ring nightreign v1.01 plus 26 trainer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2332C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
4200"C:\Users\admin\AppData\Local\Temp\Elden Ring Nightreign v1.01 Plus 26 Trainer.exe" C:\Users\admin\AppData\Local\Temp\Elden Ring Nightreign v1.01 Plus 26 Trainer.exeexplorer.exe
User:
admin
Company:
3DMGAME
Integrity Level:
MEDIUM
Description:
Elden Ring Nightreign v1.01 Plus 26 Trainer
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\elden ring nightreign v1.01 plus 26 trainer.exe
c:\windows\system32\ntdll.dll
5968"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7360"C:\Users\admin\AppData\Local\Temp\Elden Ring Nightreign v1.01 Plus 26 Trainer.exe" C:\Users\admin\AppData\Local\Temp\Elden Ring Nightreign v1.01 Plus 26 Trainer.exe
explorer.exe
User:
admin
Company:
3DMGAME
Integrity Level:
HIGH
Description:
Elden Ring Nightreign v1.01 Plus 26 Trainer
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\elden ring nightreign v1.01 plus 26 trainer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
2 018
Read events
2 004
Write events
14
Delete events
0

Modification events

(PID) Process:(7360) Elden Ring Nightreign v1.01 Plus 26 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Elden Ring Nightreign v1_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7360) Elden Ring Nightreign v1.01 Plus 26 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Elden Ring Nightreign v1_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7360) Elden Ring Nightreign v1.01 Plus 26 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Elden Ring Nightreign v1_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(7360) Elden Ring Nightreign v1.01 Plus 26 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Elden Ring Nightreign v1_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(7360) Elden Ring Nightreign v1.01 Plus 26 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Elden Ring Nightreign v1_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(7360) Elden Ring Nightreign v1.01 Plus 26 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Elden Ring Nightreign v1_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(7360) Elden Ring Nightreign v1.01 Plus 26 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Elden Ring Nightreign v1_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(7360) Elden Ring Nightreign v1.01 Plus 26 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Elden Ring Nightreign v1_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7360) Elden Ring Nightreign v1.01 Plus 26 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Elden Ring Nightreign v1_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7360) Elden Ring Nightreign v1.01 Plus 26 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Elden Ring Nightreign v1_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
0
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
7360Elden Ring Nightreign v1.01 Plus 26 Trainer.exeC:\Users\admin\AppData\Local\FLiNGTrainer\TrainerSettings.initext
MD5:100AD43A6E39D44013FAD7F3AA343E3B
SHA256:A7B15EE77DD0DB946E7FDBF574889BD30C23FA3D7BFF6D509DF118595EE14EC5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
28
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2244
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2244
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
864
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
6544
svchost.exe
20.190.160.20:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:138
whitelisted
7360
Elden Ring Nightreign v1.01 Plus 26 Trainer.exe
172.67.73.26:443
flingtrainer.com
CLOUDFLARENET
US
suspicious
6544
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
whitelisted
login.live.com
  • 20.190.160.20
  • 40.126.32.136
  • 20.190.160.2
  • 40.126.32.68
  • 40.126.32.138
  • 40.126.32.140
  • 20.190.160.22
  • 40.126.32.134
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.174
  • 23.48.23.158
  • 23.48.23.162
  • 23.48.23.161
  • 23.48.23.147
  • 23.48.23.164
  • 23.48.23.146
  • 23.48.23.159
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 95.101.149.131
whitelisted
google.com
  • 142.250.185.78
whitelisted
flingtrainer.com
  • 172.67.73.26
  • 104.26.14.72
  • 104.26.15.72
unknown
ocsp.digicert.com
  • 2.23.77.188
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted

Threats

No threats detected
No debug info