Is Jade Empire Special Edition Trainer +5 MrAntiFun.zip safe?
Twenty-four of 75 engines flagged this game trainer, with six tier-1 detections and strong, corroborated identification of Cheat Engine hacktool components.
The archive contains a game trainer built around Cheat Engine components, corroborated by 24 of 75 engines and six tier-1 detections. Although one sandbox run produced no malicious verdict, confirmed hacktool labeling and three-engine tier-1 family agreement make execution unsafe on a normal system.
e7aa2e5a8fb16254ae…6a076b61e913ddRecommended next actions
Before opening or extracting
Do not open or extract it. Delete this archive from the device, then empty the Recycle Bin or Trash.
If you already opened or extracted it
Close it. If it opened links, requested credentials, or triggered unexpected behavior, disconnect from the internet and run a full device scan.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The archive contains a game trainer built around Cheat Engine components, corroborated by 24 of 75 engines and six tier-1 detections. Although one sandbox run produced no malicious verdict, confirmed hacktool labeling and three-engine tier-1 family agreement make execution unsafe on a normal system.
The strongest evidence is the 24/75 detection ratio, including six independent tier-1 detections. Three tier-1 engines agree on the Cheat Engine family, and multiple products explicitly describe the contents as a hacktool or riskware. The completed sandbox run observed the trainer extracting and executing a CETRAINER payload, but it did not produce an independently malicious sandbox verdict or offensive MITRE techniques. Seven extracted children were inspected without a confirmed malicious finding, although their individual verdicts remain unknown. No complete contacted-host reputation result is available, so network reputation cannot reduce the risk. The confirmed offensive-tool classification outweighs the limited counter-signals.
What We Detected
24 of 75 antivirus engines flagged the ZIP archive. Six tier-1 engines detected it, and three tier-1 engines independently agreed on the Cheat Engine family. ESET-NOD32, GData, Ikarus, and Yandex specifically used Cheat Engine or hacktool labels, satisfying the corroboration requirement for offensive tooling.
Threat Behavior
The completed sandbox run showed the archive extracting and launching a trainer executable with a CET_TRAINER.CETRAINER payload and supporting Lua and debugging modules. No offensive MITRE techniques, persistence, or malicious sandbox verdict were recorded in that run. Seven dropped files were inspected without a confirmed malicious child, but all seven remain unclassified, and no complete contacted-host reputation check is available.
What To Do Now
Do not run the trainer on a production, gaming, or personal system. Keep endpoint protection enabled, quarantine or delete the archive, and scan the system if it has already been executed.
Where this verdict could be wrong4 caveats
- behaviour.hasMaliciousSandboxVerdict=false and behaviour.offensiveCount=0 in the single completed sandbox run.
- droppedChildren.hasMaliciousChild=false, but all 7 inspected children have unknown verdicts rather than confirmed benign results.
- externalIntel.yaraify.ruleCount=0, externalIntel.circl.hit=false, and externalIntel.malwareBazaar.hit=false; these absences may reflect intelligence coverage gaps.
- 12 of 18 reporting tier-1 engines did not flag the archive, including BitDefender, Avast, AVG, and Avira.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- behaviour.hasMaliciousSandboxVerdict=false in one completed sandbox run.
- behaviour.offensiveCount=0 and no persistence indicators were recorded.
- droppedChildren.hasMaliciousChild=false.
- No CIRCL, MalwareBazaar, or YARAify hit was present.
- The archive has been known since 2016 rather than being newly observed.
- 24/75 antivirus engines detected the archive.
- Six tier-1 engines flagged the sample.
- Three tier-1 engines reached strong consensus on Cheat Engine.
- engines.hacktoolConfirmed=true based on corroborated hacktool labels.
- The archive extracted and executed a CETRAINER payload.
- file.reputation=-23.
Quarantine or delete the archive and do not execute its trainer components. If it was already run, keep security protection enabled and perform a full system scan.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete24 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 0MITRE ATT&CK techniques
- 2spawned processes
- 0network contacts
- 8filesystem & mutex artifacts
Threat context
How hacktools are abused
This is a hacking or cracking tool — the kind used to bypass software licences, generate fake keys, or attack other systems. Even when the tool 'works', these downloads very often carry hidden malware.
Bottom line:Running one means trusting an anonymous author with full access to your PC — rarely worth the risk.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
Jade Empire Special Edition Trainer +5 MrAntiFun.zip
e7aa2e5a8fb16254ae07ccdb7f9cb2c26951b508c0363442026a076b61e913dd
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
C:\Users\<USER>\AppData\Local\Temp\cetrainers\CETA0B6.tmp\Jade Empire Special Edition Trainer +5 MrAntiFun.EXE -ORIGIN:C:\Users\<USER>\Downloads\
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Users\<USER>\AppData\Local\Temp\cetrainers\CETA0B6.tmp\extracted\Jade Empire Special Edition Trainer +5 MrAntiFun.EXE C:\Users\<USER>\AppData\Local\Temp\cetrainers\CETA0B6.tmp\extracted\CET_TRAINER.CETRAINER -ORIGIN:C:\Users\<USER>\Downloads\
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
CET_Archive.dat
C:\Users\<USER>\AppData\Local\Temp\cetrainers\CETA0B6.tmp\CET_Archive.dat
04Isolated runtime analysis - Written fileObserved
Jade Empire Special Edition Trainer +5 MrAntiFun.EXE
C:\Users\<USER>\AppData\Local\Temp\cetrainers\CETA0B6.tmp\Jade Empire Special Edition Trainer +5 MrAntiFun.EXE
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
5 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
- C:\Users\<USER>\AppData\Local\Temp\cetrainers\CETA0B6.tmp\CET_Archive.dat
- C:\Users\<USER>\AppData\Local\Temp\cetrainers\CETA0B6.tmp\Jade Empire Special Edition Trainer +5 MrAntiFun.EXE
- C:\Users\<USER>\AppData\Local\Temp\cetrainers\CETA0B6.tmp\extracted\CET_TRAINER.CETRAINER
- C:\Users\<USER>\AppData\Local\Temp\cetrainers\CETA0B6.tmp\extracted\defines.lua
- C:\Users\<USER>\AppData\Local\Temp\cetrainers\CETA0B6.tmp\extracted\Jade Empire Special Edition Trainer +5 MrAntiFun.EXE
- C:\Users\<USER>\AppData\Local\Temp\cetrainers\CETA0B6.tmp
Files this sample writes at runtime
This file drops 7 children at runtime. None are currently flagged malicious in our cache.
- c61e557958752e8bc21c…64063fNever scannednever seen before
- 65cbed2e8db313b89666…518c39Never scannednever seen before
- ea90c7fe0d0fa3a52bae…4a6c29Never scannednever seen before
- d4347332b232622283e7…2898f2Never scannednever seen before
- 03b71aca53dd55626836…df90b6Never scannednever seen before
- faf0850051ba175347e4…b06e6bNever scannednever seen before
- 150782fca5e188762a41…50948fNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 24 / 75engines flagged
- 7sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
24 of 75 antivirus engines flagged the file, including Antiy-AVL and CAT-QuickHeal.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 7 times from 7 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: Jade Empire Special Edition Trainer +5 MrAntiFun.zip — e7aa2e5a8fb16254ae07ccdb7f9cb2c26951b508c0363442026a076b61e913dd
ProvenanceObservedSourceUploaded fileObserved at - 04
Observed process — C:\Users\<USER>\AppData\Local\Temp\cetrainers\CETA0B6.tmp\Jade Empire Special Edition Trainer +5 MrAntiFun.EXE -ORIGIN:C:\Users\<USER>\Downloads\
ProvenanceObservedSourceIsolated runtime analysisObserved at - 05
Observed process — C:\Users\<USER>\AppData\Local\Temp\cetrainers\CETA0B6.tmp\extracted\Jade Empire Special Edition Trainer +5 MrAntiFun.EXE C:\Users\<USER>\AppData\Local\Temp\cetrainers\CETA0B6.tmp\extracted\CET_TRAINER.CETRAINER -ORIGIN:C:\Users\<USER>\Downloads\
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
File written: CET_Archive.dat — C:\Users\<USER>\AppData\Local\Temp\cetrainers\CETA0B6.tmp\CET_Archive.dat
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Jade Empire Special Edition Trainer +5 MrAntiFun.EXE — C:\Users\<USER>\AppData\Local\Temp\cetrainers\CETA0B6.tmp\Jade Empire Special Edition Trainer +5 MrAntiFun.EXE
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: hacktool
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
24 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- Jade Empire Special Edition Trainer +5 MrAntiFun.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 4.2 MB
- Last analyzed
- Sep 12, 2026, 7:51 PM UTC
e7aa2e5a8fb16254ae07ccdb7f9cb2c26951b508c0363442026a076b61e913ddSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't open or extract this archive. Delete this archive from the device, then empty the Recycle Bin or Trash.
- Recovery step 02
If you already opened or extracted it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
If you typed any passwords while it was open, change them from a device you trust.
- Recovery step 04
Get a fresh copy from the original trusted source and verify its exact hash when possible.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Jade Empire Special Edition Trainer +5 MrAntiFun.zip a virus?
What is Jade Empire Special Edition Trainer +5 MrAntiFun.zip?
How many antivirus engines detected Jade Empire Special Edition Trainer +5 MrAntiFun.zip?
What should I do if I already opened or extracted Jade Empire Special Edition Trainer +5 MrAntiFun.zip?
How do I remove Jade Empire Special Edition Trainer +5 MrAntiFun.zip?
What kind of malware is Jade Empire Special Edition Trainer +5 MrAntiFun.zip?
What is the SHA-256 hash of Jade Empire Special Edition Trainer +5 MrAntiFun.zip?
How up to date is this analysis of Jade Empire Special Edition Trainer +5 MrAntiFun.zip?
Community
Member reviews and reports for this exact file hash.