File verdict·Decided by the MT AI Engine
Our call

Malicious

Unsigned 1-day-old EXE with process injection, LSASS access, scheduled-task persistence, and direct-IP C2 flagged by two tier-1 engines.

alien
Trust score12Critical
Fleasion-v2.3.0-Windows.exe
56.9 MB
e16001a8d80af46d302ad9ae778a
Antivirus engines
4 of 74 flagged
Code signing
Unsigned
Age
First seen 2 days ago
MT AI Engine · Verdict analysis

The reasoning behind this verdict

The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.

78%Confidence
High
Reasoning

The combination of two tier-1 detections on the same 'alien' family, four offensive MITRE techniques, and multiple high-severity heuristics (process injection, credential dumping, direct-IP C2, scheduled-task persistence) outweighs the lack of strong tier-1 consensus and the common_new prevalence label. Unsigned status and zero-day age further reduce the likelihood of a legitimate commodity tool. No RAG matches or external-intel hits exist to contradict the behavioural evidence.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. engines.topDetections: Kaspersky 'Trojan-Banker.Win64.Alien.bn' (tier1), Microsoft 'Trojan:Win32/Wacatac.B!ml' (tier1)

  2. behaviour.offensiveTechniques: T1055, T1485, T1486, T1548

  3. triggeredHeuristics[1].rule: MalwareTips.Synth.ProcessInjection (high severity)

  4. behaviour.contactedIps: 140.82.113.5, 185.199.109.133, 23.33.85.245, 128.116.95.3 (direct-IP, zero domains)

  5. signing.signed: false

Points in its favour
  • No malicious dropped children
  • No external-intel hits on known C2 infrastructure
Points against
  • Unsigned binary
  • Process injection (T1055)
  • LSASS credential access
  • Direct-IP C2 without DNS
  • Scheduled-task persistence
  • Data destruction/encryption techniques
Recommended action

Treat as malicious; isolate the file and investigate the host for credential theft or persistence mechanisms.

What this file does

What it attempted when executed in an isolated sandbox

  • High concern: Hides inside another running program to evade antivirus.

  • High concern: Talks to a remote server to take commands or send out your data.

  • High concern: Downloads more malware onto your PC.

  • High concern: Encrypts your files and demands payment — ransomware behaviour.

  • High concern: Hijacks how Windows loads programs so it runs automatically.

  • Moderate concern: Obfuscates or packs its code to avoid detection.

  • Moderate concern: Lists running programs — often to find security tools.

Translated from the file's technical behaviour during analysis. It never ran on your device.

Threat context

How trojans work

A trojan disguises itself as something useful or harmless to trick you into running it. Once open, it does its real job in the background — anything from stealing data to opening a back door or downloading more malware.

Bottom line:The disguise is the whole trick, so a trustworthy-looking name or icon means nothing.

What to do now

This file is dangerous. Treat it as harmful and remove it.

  1. Don't open or run this file. Delete it from your Downloads (or wherever you saved it), then empty the Recycle Bin.

  2. If you already opened it, disconnect from the internet and run a full scan with your antivirus — Windows Security, built into Windows, is sufficient.

  3. If any of your files were locked or renamed, do NOT pay the ransom — payment rarely restores files. Recover them from a backup instead.

  4. In future, only download software from the official website or an official app store.

Threat family attribution

alien corroborated by 2 sources

  • VT (74 engines)
    alien
  • MT AI Engine
    alien
Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
32

Adversary techniques mapped to the MITRE ATT&CK framework.

T1012T1027· Obfuscated codeT1027.002· Obfuscated codeT1027.009· Obfuscated codeT1033· Reads user infoT1036T1045T1055· Process injectionT1057· Lists programsT1059· Runs commandsT1063T1070· Covers its tracksT1070.006· Covers its tracksT1071· Remote server (C2)T1082· System reconT1083· Scans your filesT1105· Downloads malwareT1112T1129· Loads modulesT1140· DeobfuscationT1202T1485T1486· File encryptionT1497· Sandbox evasion+8 more
Spawned processes
15
$(unnamed)
C:\Windows\System32\schtasks.exe /create /TN Fleasion-HostsWatchdog /XML C:\Users\<USER>\AppData\Local\Temp\fleasion_watchdog_task.xml /RU SYSTEM /F
$(unnamed)
"C:\Users\<USER>\Desktop\Fleasion-v2.3.0-Windows.exe"
$(unnamed)
C:\Windows\system32\cmd.exe /c "ver"
$(unnamed)
C:\Windows\system32\services.exe
$(unnamed)
"C:\Users\<USER>\Desktop\Fleasion-v2.3.0-Windows.exe" --fleasion-user-localappdata=C:\Users\<USER>\AppData\Local --kill-others
$(unnamed)
tasklist /FI "IMAGENAME eq Fleasion-v2.3.0-Windows.exe" /FO CSV /NH
$(unnamed)
C:\Windows\System32\certutil.exe -store Root
$(unnamed)
C:\Windows\System32\certutil.exe -store Root 0FEF36D2DBC116C39C39CA9E21E663CAC80AEF69
+7 more processes captured.
Network activity
4
IP addresses4
  • 140.82.113.5
  • 185.199.109.133
  • 23.33.85.245
  • 128.116.95.3
Filesystem & mutexes
31
Files written15
  • C:\Users\<USER>\AppData\Local\Temp\_MEI58522\DracoPy.cp314-win_amd64.pyd
  • C:\Users\<USER>\AppData\Local\Temp\_MEI58522\OpenGL\DLLS\GLE_WIN32_README.txt
  • C:\Users\<USER>\AppData\Local\Temp\_MEI58522\OpenGL\DLLS\freeglut32.vc10.dll
  • C:\Users\<USER>\AppData\Local\Temp\_MEI58522\OpenGL\DLLS\freeglut32.vc14.dll
  • C:\Users\<USER>\AppData\Local\Temp\_MEI58522\OpenGL\DLLS\freeglut32.vc9.dll
+10 more
Files deleted15
  • C:\Users\<USER>\AppData\Local\Temp\_MEI58522\ada92cb5d92a588d1b93__mypyc.cp314-win_amd64.pyd
  • C:\Users\<USER>\AppData\Local\Temp\_MEI58522\api-ms-win-core-console-l1-1-0.dll
  • C:\Users\<USER>\AppData\Local\Temp\_MEI58522\api-ms-win-core-datetime-l1-1-0.dll
  • C:\Users\<USER>\AppData\Local\Temp\_MEI58522\api-ms-win-core-debug-l1-1-0.dll
  • C:\Users\<USER>\AppData\Local\Temp\_MEI58522\api-ms-win-core-errorhandling-l1-1-0.dll
+10 more
Mutexes created1
  • Local\SessionImmersiveColorMutex
Dropped payload

Files this sample writes at runtime

This file drops 10 children at runtime. None are currently flagged malicious in our cache.

10 unseen
  • 17c3504e92fa17b916f26cf82dNever scanned
    never seen before
  • c20ad45b3c2891d9f7a5b3e43dNever scanned
    never seen before
  • a4a6f28f2be50a9698c42326d8Never scanned
    never seen before
  • 8cbc5f4dc299a119dc3970bdd4Never scanned
    never seen before
  • db8e259a9b413cd152b0a57c1aNever scanned
    never seen before
  • 1bd81dfd19204b446625c16818Never scanned
    never seen before
  • 0485663735266f5eb240e2cee5Never scanned
    never seen before
  • f578b85ed4bc61d12173d52352Never scanned
    never seen before
  • 9471324dd50bf1f8cfc9f00c75Never scanned
    never seen before
  • c4f03a873f96edd8ab9c8319c7Never scanned
    never seen before
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA & heuristic rule matches

A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.

4 synthesis
MITRE ATT&CK profile
Persistence× 1Defense evasion× 1Cred access× 1C2× 1
MalwareTips synthesis rules
Our own detection rules, applied to the scan data and sandbox behaviour
  • PersistenceScheduledTaskmedium

    Sample spawned schtasks / PowerShell scheduled-task cmdlets / sc create. Persistence mechanism.

    Evidence
    C:\Windows\System32\schtasks.exe /create /TN Fleasion-HostsWatchdog /XML C:\Users\<USER>\AppData\Local\Temp\fleasion_watchdog_task.xml /RU SYSTEM /F
  • ProcessInjectionhigh

    MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.

    Evidence
    C:\Windows\System32\svchost.exe -k NetworkService -p
  • CredentialDumpermedium

    Sandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.

    Evidence
    C:\Windows\system32\lsass.exe
  • DirectIpC2medium

    Sample contacted 4 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    140.82.113.5 · 185.199.109.133 · 23.33.85.245
Antivirus engine breakdown

4 detections across 74 engines

4 malicious0 suspicious70 clean
Tier-117 engines
2flag
Top commercial AVs (low FP rate)
Tier-240 engines
0flag
Mainstream engines with mixed FP rates
Low-trust17 engines
2flag
Heuristic / generic-AI engines (high FP rate)
Bkav
malicious
W32.Malware.62CF7605
Kaspersky
malicious
Trojan-Banker.Win64.Alien.bn
Microsoft
malicious
Trojan:Win32/Wacatac.B!ml
Rising
malicious
Trojan.Alien!8.5E97 (CLOUD)
Hash e16001a8d80a… cross-referenced against 74 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

ent 8.00Unpacked
Section entropy7 sections
.text
6.47
.rdata
5.75
.data
1.82
.pdata
5.47
.fptable
0.00
.rsrc
4.11
.reloc
5.25
0.0Packed threshold 7.28.0
Prevalence

How widely this file has been seen

Lots of people are uploading this but it's recent — typical of newly-released legitimate software. Low prior for malware.

Common & new
Unique uploaders
138
Hundreds of people have uploaded this — common.
Total submissions
153
Includes repeat uploads by the same source.
First seen
1d ago
Jul 18, 2026
Prevalence quadrant
Rare · New
Targeted malware lives here
here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
7/18/2026, 4:21:10 PM
First seen (MalwareBazaar)
Last analysis (VT)
7/19/2026, 2:34:54 PM
Scanned here
7/19/2026, 4:05:24 PM
File name
Fleasion-v2.3.0-Windows.exe
Size
56.94 MB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
e16001a8d80af46d306d1112bb0b577bc8e7900f393316aa384a082ad9ae778a
MD5
9a041b7a2d2ab62a19d5eba886bcd8bd
SHA-1
cd4274a45529d0e79a28bde58aeab2cd62f7f5aa
PE imphash
cf72283be50852e418ce6bbb6b645835
First seen (VT)
7/18/2026, 4:21:10 PM
Last analysis (VT)
7/19/2026, 2:34:54 PM
First scan (MalwareTips)
7/19/2026, 4:05:24 PM
Last scan (MalwareTips)
7/19/2026, 4:05:24 PM
Behavior tags
64bitspeexeoverlay
Frequently asked

Safety FAQ

Common questions about Fleasion-v2.3.0-Windows.exe, answered from the scan data above.

  • Yes — Fleasion-v2.3.0-Windows.exe is malicious, so do not run it, and delete it. 4 of 74 antivirus engines flag it (family: alien). It behaves as a trojan — malware disguised as something harmless to trick you into running it. If you've already run it, see the removal and recovery steps below.
  • Fleasion-v2.3.0-Windows.exe is a Windows executable program, about 56.9 MB. Our analysis identifies it as malicious (family: alien) — a trojan — malware disguised as something harmless to trick you into running it. Because a file's name and icon can be faked, the safest way to identify it is by its cryptographic hash (below), not its filename.
  • 4 of 74 antivirus engines flagged Fleasion-v2.3.0-Windows.exe, 4 of them as outright malicious. A detection rate at this level is a reliable signal that the file is dangerous.
  • Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
  • To remove Fleasion-v2.3.0-Windows.exe: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original Fleasion-v2.3.0-Windows.exe file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
  • Fleasion-v2.3.0-Windows.exe is classified as a trojan — malware disguised as something harmless to trick you into running it. Engines attribute it to the alien family. Knowing the family matters because it tells you the likely impact — data theft, remote control, file encryption, or unwanted ads — and guides the cleanup.
  • The SHA-256 hash of Fleasion-v2.3.0-Windows.exe is e16001a8d80af46d306d1112bb0b577bc8e7900f393316aa384a082ad9ae778a, and its MD5 is 9a041b7a2d2ab62a19d5eba886bcd8bd. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
  • This report reflects the scan run on July 19, 2026. Because a file's hash never changes, the identity of Fleasion-v2.3.0-Windows.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.