File name:

Stellar Blade v1.1.0 Plus 43 Trainer.exe

Full analysis: https://app.any.run/tasks/e0816e1e-c4e3-4c86-a451-f31d16f07fea
Verdict: Malicious activity
Analysis date: June 22, 2025, 12:51:26
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
flingtrainer
cheat
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

EAB825E03F0E791FB3105F4781C63E66

SHA1:

B1BE8BFBE9F21ED1E26A66B6286F5650F5181CA3

SHA256:

A9EDC40C08EDEDC94C9027A39FD9BC6AFC7A328A18B110940B0DE82F037F4BFC

SSDEEP:

49152:/EswOeviGRFrzz+HnexMFlVA5KtgLc0yzW0WYqN6VFpOVYMp33DIyXTwhf:/vwOyiGRRz+HexMF2UqNaCV3zIyjwF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • FLINGTRAINER mutex has been found

      • Stellar Blade v1.1.0 Plus 43 Trainer.exe (PID: 1496)
  • INFO

    • Creates files or folders in the user directory

      • Stellar Blade v1.1.0 Plus 43 Trainer.exe (PID: 1496)
    • Checks supported languages

      • Stellar Blade v1.1.0 Plus 43 Trainer.exe (PID: 1496)
    • Reads the computer name

      • Stellar Blade v1.1.0 Plus 43 Trainer.exe (PID: 1496)
    • Reads Environment values

      • Stellar Blade v1.1.0 Plus 43 Trainer.exe (PID: 1496)
    • Reads the machine GUID from the registry

      • Stellar Blade v1.1.0 Plus 43 Trainer.exe (PID: 1496)
    • Disables trace logs

      • Stellar Blade v1.1.0 Plus 43 Trainer.exe (PID: 1496)
    • Checks proxy server information

      • Stellar Blade v1.1.0 Plus 43 Trainer.exe (PID: 1496)
    • Reads the software policy settings

      • Stellar Blade v1.1.0 Plus 43 Trainer.exe (PID: 1496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:06:16 15:08:35+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.43
CodeSize: 835072
InitializedDataSize: 886784
UninitializedDataSize: -
EntryPoint: 0x9d0f8
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: 3DMGAME
FileDescription: Stellar Blade v1.1.0 Plus 43 Trainer
FileVersion: 1.0.0.0
InternalName: Stellar Blade v1.1.0 Plus 43 Trainer
LegalCopyright: FLiNG Copyright (C) 2025
OriginalFileName: Stellar Blade v1.1.0 Plus 43 Trainer.exe
ProductName: Stellar Blade v1.1.0 Plus 43 Trainer
ProductVersion: 1.0.0.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
3
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start #FLINGTRAINER stellar blade v1.1.0 plus 43 trainer.exe slui.exe no specs stellar blade v1.1.0 plus 43 trainer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1496"C:\Users\admin\Desktop\Stellar Blade v1.1.0 Plus 43 Trainer.exe" C:\Users\admin\Desktop\Stellar Blade v1.1.0 Plus 43 Trainer.exe
explorer.exe
User:
admin
Company:
3DMGAME
Integrity Level:
HIGH
Description:
Stellar Blade v1.1.0 Plus 43 Trainer
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\stellar blade v1.1.0 plus 43 trainer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2404"C:\Users\admin\Desktop\Stellar Blade v1.1.0 Plus 43 Trainer.exe" C:\Users\admin\Desktop\Stellar Blade v1.1.0 Plus 43 Trainer.exeexplorer.exe
User:
admin
Company:
3DMGAME
Integrity Level:
MEDIUM
Description:
Stellar Blade v1.1.0 Plus 43 Trainer
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\stellar blade v1.1.0 plus 43 trainer.exe
c:\windows\system32\ntdll.dll
4864C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
1 781
Read events
1 767
Write events
14
Delete events
0

Modification events

(PID) Process:(1496) Stellar Blade v1.1.0 Plus 43 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Stellar Blade v1_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1496) Stellar Blade v1.1.0 Plus 43 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Stellar Blade v1_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(1496) Stellar Blade v1.1.0 Plus 43 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Stellar Blade v1_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1496) Stellar Blade v1.1.0 Plus 43 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Stellar Blade v1_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(1496) Stellar Blade v1.1.0 Plus 43 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Stellar Blade v1_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(1496) Stellar Blade v1.1.0 Plus 43 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Stellar Blade v1_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(1496) Stellar Blade v1.1.0 Plus 43 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Stellar Blade v1_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(1496) Stellar Blade v1.1.0 Plus 43 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Stellar Blade v1_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1496) Stellar Blade v1.1.0 Plus 43 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Stellar Blade v1_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(1496) Stellar Blade v1.1.0 Plus 43 Trainer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Stellar Blade v1_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
0
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
1496Stellar Blade v1.1.0 Plus 43 Trainer.exeC:\Users\admin\AppData\Local\FLiNGTrainer\TrainerSettings.initext
MD5:100AD43A6E39D44013FAD7F3AA343E3B
SHA256:A7B15EE77DD0DB946E7FDBF574889BD30C23FA3D7BFF6D509DF118595EE14EC5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
26
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.216.77.20:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
892
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6812
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6812
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5328
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6172
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1496
Stellar Blade v1.1.0 Plus 43 Trainer.exe
104.26.14.72:443
flingtrainer.com
CLOUDFLARENET
US
shared
2336
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
892
svchost.exe
20.190.160.132:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
892
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
whitelisted
google.com
  • 142.250.74.206
whitelisted
flingtrainer.com
  • 104.26.14.72
  • 104.26.15.72
  • 172.67.73.26
unknown
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.132
  • 40.126.32.138
  • 20.190.160.2
  • 20.190.160.20
  • 20.190.160.22
  • 20.190.160.131
  • 20.190.160.65
  • 40.126.32.133
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 2.23.77.188
whitelisted
crl.microsoft.com
  • 23.216.77.20
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
nexusrules.officeapps.live.com
  • 52.111.227.13
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted

Threats

No threats detected
No debug info