Malicious
Unsigned 1-day-old EXE with process injection, LSASS access, scheduled-task persistence, and direct-IP C2 flagged by two tier-1 engines.
e16001a8d80af46d30…2ad9ae778aThe reasoning behind this verdict
The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.
The combination of two tier-1 detections on the same 'alien' family, four offensive MITRE techniques, and multiple high-severity heuristics (process injection, credential dumping, direct-IP C2, scheduled-task persistence) outweighs the lack of strong tier-1 consensus and the common_new prevalence label. Unsigned status and zero-day age further reduce the likelihood of a legitimate commodity tool. No RAG matches or external-intel hits exist to contradict the behavioural evidence.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines.topDetections: Kaspersky 'Trojan-Banker.Win64.Alien.bn' (tier1), Microsoft 'Trojan:Win32/Wacatac.B!ml' (tier1)
behaviour.offensiveTechniques: T1055, T1485, T1486, T1548
triggeredHeuristics[1].rule: MalwareTips.Synth.ProcessInjection (high severity)
behaviour.contactedIps: 140.82.113.5, 185.199.109.133, 23.33.85.245, 128.116.95.3 (direct-IP, zero domains)
signing.signed: false
- No malicious dropped children
- No external-intel hits on known C2 infrastructure
- Unsigned binary
- Process injection (T1055)
- LSASS credential access
- Direct-IP C2 without DNS
- Scheduled-task persistence
- Data destruction/encryption techniques
Treat as malicious; isolate the file and investigate the host for credential theft or persistence mechanisms.
What this file does
What it attempted when executed in an isolated sandbox
High concern: Hides inside another running program to evade antivirus.
High concern: Talks to a remote server to take commands or send out your data.
High concern: Downloads more malware onto your PC.
High concern: Encrypts your files and demands payment — ransomware behaviour.
High concern: Hijacks how Windows loads programs so it runs automatically.
Moderate concern: Obfuscates or packs its code to avoid detection.
Moderate concern: Lists running programs — often to find security tools.
Translated from the file's technical behaviour during analysis. It never ran on your device.
Threat context
How trojans work
A trojan disguises itself as something useful or harmless to trick you into running it. Once open, it does its real job in the background — anything from stealing data to opening a back door or downloading more malware.
Bottom line:The disguise is the whole trick, so a trustworthy-looking name or icon means nothing.
What to do now
This file is dangerous. Treat it as harmful and remove it.
Don't open or run this file. Delete it from your Downloads (or wherever you saved it), then empty the Recycle Bin.
If you already opened it, disconnect from the internet and run a full scan with your antivirus — Windows Security, built into Windows, is sufficient.
If any of your files were locked or renamed, do NOT pay the ransom — payment rarely restores files. Recover them from a backup instead.
In future, only download software from the official website or an official app store.
alien corroborated by 2 sources
- VT (74 engines)alien
- MT AI Enginealien
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 140.82.113.5
- 185.199.109.133
- 23.33.85.245
- 128.116.95.3
- C:\Users\<USER>\AppData\Local\Temp\_MEI58522\DracoPy.cp314-win_amd64.pyd
- C:\Users\<USER>\AppData\Local\Temp\_MEI58522\OpenGL\DLLS\GLE_WIN32_README.txt
- C:\Users\<USER>\AppData\Local\Temp\_MEI58522\OpenGL\DLLS\freeglut32.vc10.dll
- C:\Users\<USER>\AppData\Local\Temp\_MEI58522\OpenGL\DLLS\freeglut32.vc14.dll
- C:\Users\<USER>\AppData\Local\Temp\_MEI58522\OpenGL\DLLS\freeglut32.vc9.dll
- C:\Users\<USER>\AppData\Local\Temp\_MEI58522\ada92cb5d92a588d1b93__mypyc.cp314-win_amd64.pyd
- C:\Users\<USER>\AppData\Local\Temp\_MEI58522\api-ms-win-core-console-l1-1-0.dll
- C:\Users\<USER>\AppData\Local\Temp\_MEI58522\api-ms-win-core-datetime-l1-1-0.dll
- C:\Users\<USER>\AppData\Local\Temp\_MEI58522\api-ms-win-core-debug-l1-1-0.dll
- C:\Users\<USER>\AppData\Local\Temp\_MEI58522\api-ms-win-core-errorhandling-l1-1-0.dll
- Local\SessionImmersiveColorMutex
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 17c3504e92fa17b916f2…6cf82dNever scannednever seen before
- c20ad45b3c2891d9f7a5…b3e43dNever scannednever seen before
- a4a6f28f2be50a9698c4…2326d8Never scannednever seen before
- 8cbc5f4dc299a119dc39…70bdd4Never scannednever seen before
- db8e259a9b413cd152b0…a57c1aNever scannednever seen before
- 1bd81dfd19204b446625…c16818Never scannednever seen before
- 0485663735266f5eb240…e2cee5Never scannednever seen before
- f578b85ed4bc61d12173…d52352Never scannednever seen before
- 9471324dd50bf1f8cfc9…f00c75Never scannednever seen before
- c4f03a873f96edd8ab9c…8319c7Never scannednever seen before
YARA & heuristic rule matches
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
Sample spawned schtasks / PowerShell scheduled-task cmdlets / sc create. Persistence mechanism.
EvidenceC:\Windows\System32\schtasks.exe /create /TN Fleasion-HostsWatchdog /XML C:\Users\<USER>\AppData\Local\Temp\fleasion_watchdog_task.xml /RU SYSTEM /FMITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
EvidenceC:\Windows\System32\svchost.exe -k NetworkService -pSandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeSample contacted 4 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence140.82.113.5 · 185.199.109.133 · 23.33.85.245
4 detections across 74 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How widely this file has been seen
Lots of people are uploading this but it's recent — typical of newly-released legitimate software. Low prior for malware.
Forensic fingerprint
- File name
- Fleasion-v2.3.0-Windows.exe
- Size
- 56.94 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- e16001a8d80af46d306d1112bb0b577bc8e7900f393316aa384a082ad9ae778a
- MD5
- 9a041b7a2d2ab62a19d5eba886bcd8bd
- SHA-1
- cd4274a45529d0e79a28bde58aeab2cd62f7f5aa
- PE imphash
- cf72283be50852e418ce6bbb6b645835
- First seen (VT)
- 7/18/2026, 4:21:10 PM
- Last analysis (VT)
- 7/19/2026, 2:34:54 PM
- First scan (MalwareTips)
- 7/19/2026, 4:05:24 PM
- Last scan (MalwareTips)
- 7/19/2026, 4:05:24 PM
Safety FAQ
Common questions about Fleasion-v2.3.0-Windows.exe, answered from the scan data above.
- Yes — Fleasion-v2.3.0-Windows.exe is malicious, so do not run it, and delete it. 4 of 74 antivirus engines flag it (family: alien). It behaves as a trojan — malware disguised as something harmless to trick you into running it. If you've already run it, see the removal and recovery steps below.
- Fleasion-v2.3.0-Windows.exe is a Windows executable program, about 56.9 MB. Our analysis identifies it as malicious (family: alien) — a trojan — malware disguised as something harmless to trick you into running it. Because a file's name and icon can be faked, the safest way to identify it is by its cryptographic hash (below), not its filename.
- 4 of 74 antivirus engines flagged Fleasion-v2.3.0-Windows.exe, 4 of them as outright malicious. A detection rate at this level is a reliable signal that the file is dangerous.
- Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
- To remove Fleasion-v2.3.0-Windows.exe: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original Fleasion-v2.3.0-Windows.exe file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
- Fleasion-v2.3.0-Windows.exe is classified as a trojan — malware disguised as something harmless to trick you into running it. Engines attribute it to the alien family. Knowing the family matters because it tells you the likely impact — data theft, remote control, file encryption, or unwanted ads — and guides the cleanup.
- The SHA-256 hash of Fleasion-v2.3.0-Windows.exe is e16001a8d80af46d306d1112bb0b577bc8e7900f393316aa384a082ad9ae778a, and its MD5 is 9a041b7a2d2ab62a19d5eba886bcd8bd. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
- This report reflects the scan run on July 19, 2026. Because a file's hash never changes, the identity of Fleasion-v2.3.0-Windows.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.