MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 4d096a4d27f59f46ba928179f912d8df4467b32a7a7ecf70fac63f0d97fc5edf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 4
| SHA256 hash: | 4d096a4d27f59f46ba928179f912d8df4467b32a7a7ecf70fac63f0d97fc5edf |
|---|---|
| SHA3-384 hash: | cdaf5c16526736e60c2ef7f7a0c5ec9ce1c09ec80cf87b1ebf8c6c5a742b5339827111fcc6786d937f9f1b83998f6105 |
| SHA1 hash: | 16ff64512593993b3e4264378bf60692740562f5 |
| MD5 hash: | a31d9599908319a3719526026798f572 |
| humanhash: | item-eighteen-alabama-two |
| File name: | EscapetothePast.exe |
| Download: | download sample |
| File size: | 96'751'104 bytes |
| First seen: | 2026-07-23 00:50:12 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| ssdeep | 786432:zibPia/z0AogG3niVKBuinJuPYFknHrUnJxWb3SmITEgPtA2D1:mb6aQAo4iJuPsknHroJxWb3SmITEgPt |
| TLSH | T12A287B06B1A298ADD996C030CE5BF232B7347C4547B26AE73198B7743F726D05F39A84 |
| TrID | 25.1% (.EXE) DOS Borland compiled Executable (generic) (10000/1/2) 16.4% (.EXE) Win64 Executable (generic) (6522/11/2) 13.9% (.FON) Windows Font (5545/9/1) 12.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 11.3% (.EXE) Win32 Executable (generic) (4504/4/1) |
| Magika | pebin |
| dhash icon | 39e8ccd4f0f8d4cc (1 x RedLineStealer, 1 x ACRStealer) |
| Reporter | |
| Tags: | exe |
lfr
https://sant-debug.itch.io/escape-to-the-pasthttps://www.virustotal.com/gui/file/316d870d48d325717cf81d00b2d2bfecb6596b01fcd722fb9ebce7a074033cb7/detection
https://www.virustotal.com/gui/file/4d096a4d27f59f46ba928179f912d8df4467b32a7a7ecf70fac63f0d97fc5edf/detection
Intelligence
File Origin
# of uploads :
1
# of downloads :
318
Origin country :
FRVendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:
Behaviour
Creating a window
Verdict:
Suspicious
Labled as:
Win64/Agent_AGeneric.ONN trojan
Verdict:
Clean
File Type:
exe x64
Score:
0%
Verdict:
Benign
File Type:
PE
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-23 00:52:48 UTC
File Type:
PE+ (.Net Exe)
Extracted files:
400
AV detection:
6 of 24 (25.00%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
exe 4d096a4d27f59f46ba928179f912d8df4467b32a7a7ecf70fac63f0d97fc5edf
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.