Safe
This file is a legitimate, unsigned open-source utility for game integration that triggers generic heuristic warnings due to its lack of a digital signature and process interaction methods.
2b416d1b6e085e6130…2efc2fb97eThe reasoning behind this verdict
The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.
The file is an open-source project that interacts with game processes to provide custom status updates. Because it is not code-signed, it frequently triggers generic heuristic alerts in security software. Our analysis confirms that the observed behaviours, such as process interaction, are consistent with the tool's documented functionality. There is no evidence of malicious intent, such as communication with known malicious hosts or the presence of a malicious payload.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
3/74 engines flagged the file, all of which are low-trust or generic heuristic detections (e.g., 'win/malicious_confidence_60%'), with no tier-1 consensus.
The file is unsigned (signing.verified=null), which is consistent with the developer's stated reason for not paying for code-signing certificates.
The file name 'leagueRPC.exe' matches a known open-source project hosted on GitHub, which explicitly warns users about potential false-positive detections due to the lack of a signature.
Behavioural analysis shows no malicious contacted hosts or dropped malicious children, despite the triggered heuristics (T1055) related to process interaction.
Similar hashes RAG shows only one prior malicious verdict, which is an imphash-only match (matchKind=imphash) and likely a framework collision rather than a true similarity.
- no tier-1 engine detections
- consistent with known open-source project
- no malicious network activity
- unsigned binary
- triggers process injection heuristics
The file is safe to use. If blocked, add an exclusion in your security software.
What to do now
This file looks safe based on everything we checked.
This file is safe to use.
Good habit: only download files from the official website or an app store.
Keep your antivirus and Windows updates switched on so you stay protected.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 140.82.112.6
- 162.159.36.2
- C:\Users\<USER>\AppData\Local\Temp\_MEI40362\VCRUNTIME140.dll
- C:\Users\<USER>\AppData\Local\Temp\_MEI40362\VCRUNTIME140_1.dll
- C:\Users\<USER>\AppData\Local\Temp\_MEI40362\_asyncio.pyd
- C:\Users\<USER>\AppData\Local\Temp\_MEI40362\_bz2.pyd
- C:\Users\<USER>\AppData\Local\Temp\_MEI40362\_ctypes.pyd
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 2693c7ee4fba55dc548f…c28b20Never scannednever seen before
- b9cf502dadcb124f693b…a67e1eNever scannednever seen before
- 6d989d7123e0a05e01bc…ef4677Never scannednever seen before
- d3e81017b4a82ae1b85e…b2ff23Never scannednever seen before
- eff52743773eb550fcc6…7b280aNever scannednever seen before
- ceebae7b8927a3227e53…2f1508Never scannednever seen before
- dbeae7cb6f256998f9d8…88000aNever scannednever seen before
- 63ae2fefbfbbbc6ea39c…1f603eNever scannednever seen before
- 223cf615d1bc10996d93…933f7bNever scannednever seen before
- 437ceb75e7bc7c72c909…d300caNever scannednever seen before
YARA & heuristic rule matches
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
EvidenceC:\Windows\System32\svchost.exe -k NetworkService -pSandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeSample contacted 2 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence140.82.112.6 · 162.159.36.2
3 detections across 74 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- leagueRPC.exe
- Size
- 12.80 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 2b416d1b6e085e6130ca72b3747942d767619b2673e180e4c0ce7d2efc2fb97e
- MD5
- 09dd7c6f3cf03831e38b2e65a82734fc
- SHA-1
- 06988655808a09ff35c1095d5534e7ab8c259db8
- PE imphash
- 33742414196e45b8b306a928e178f844
- First seen (VT)
- 6/1/2026, 3:19:57 AM
- Last analysis (VT)
- 7/11/2026, 1:54:50 AM
- First scan (MalwareTips)
- 7/19/2026, 11:31:04 AM
- Last scan (MalwareTips)
- 7/19/2026, 11:31:04 AM
Safety FAQ
Common questions about leagueRPC.exe, answered from the scan data above.
- leagueRPC.exe appears safe. 71 of 74 antivirus engines report it clean, with only 3 low-confidence detections that read as false positives. As a habit, only run files you downloaded from the official source, since attackers sometimes distribute trojanised copies of legitimate software under the same name.
- leagueRPC.exe is a Windows executable program, about 12.8 MB. Our analysis found no threat indicators for it. A file's name can be reused by different files, so we identify it by its cryptographic hash (below).
- 3 of 74 antivirus engines flagged leagueRPC.exe, 3 of them as outright malicious. A small number of detections can include false positives, so we weigh which engines flagged it and what else the file does, not just the raw count.
- The SHA-256 hash of leagueRPC.exe is 2b416d1b6e085e6130ca72b3747942d767619b2673e180e4c0ce7d2efc2fb97e, and its MD5 is 09dd7c6f3cf03831e38b2e65a82734fc. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
- Based on this scan, yes — leagueRPC.exe shows no threat indicators. The important caveat is source: make sure you downloaded it from the official website or a trusted store, because attackers sometimes distribute malware-laced copies under a legitimate file's name. If your own antivirus flags it while we report it clean, that is most often a false positive, but verify the source before overriding your antivirus.
- This report reflects the scan run on July 19, 2026. Because a file's hash never changes, the identity of leagueRPC.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.