MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d096a4d27f59f46ba928179f912d8df4467b32a7a7ecf70fac63f0d97fc5edf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4d096a4d27f59f46ba928179f912d8df4467b32a7a7ecf70fac63f0d97fc5edf
SHA3-384 hash: cdaf5c16526736e60c2ef7f7a0c5ec9ce1c09ec80cf87b1ebf8c6c5a742b5339827111fcc6786d937f9f1b83998f6105
SHA1 hash: 16ff64512593993b3e4264378bf60692740562f5
MD5 hash: a31d9599908319a3719526026798f572
humanhash: item-eighteen-alabama-two
File name:EscapetothePast.exe
Download: download sample
File size:96'751'104 bytes
First seen:2026-07-23 00:50:12 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 786432:zibPia/z0AogG3niVKBuinJuPYFknHrUnJxWb3SmITEgPtA2D1:mb6aQAo4iJuPsknHroJxWb3SmITEgPt
TLSH T12A287B06B1A298ADD996C030CE5BF232B7347C4547B26AE73198B7743F726D05F39A84
TrID 25.1% (.EXE) DOS Borland compiled Executable (generic) (10000/1/2)
16.4% (.EXE) Win64 Executable (generic) (6522/11/2)
13.9% (.FON) Windows Font (5545/9/1)
12.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.3% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 39e8ccd4f0f8d4cc (1 x RedLineStealer, 1 x ACRStealer)
Reporter lfr
Tags:exe


Avatar
lfr
https://sant-debug.itch.io/escape-to-the-past

https://www.virustotal.com/gui/file/316d870d48d325717cf81d00b2d2bfecb6596b01fcd722fb9ebce7a074033cb7/detection
https://www.virustotal.com/gui/file/4d096a4d27f59f46ba928179f912d8df4467b32a7a7ecf70fac63f0d97fc5edf/detection

Intelligence


File Origin
# of uploads :
1
# of downloads :
318
Origin country :
FR FR
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Verdict:
Suspicious
Labled as:
Win64/Agent_AGeneric.ONN trojan
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-23 00:52:48 UTC
File Type:
PE+ (.Net Exe)
Extracted files:
400
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Executable exe 4d096a4d27f59f46ba928179f912d8df4467b32a7a7ecf70fac63f0d97fc5edf

(this sample)

  
Delivery method
Distributed via web download

Comments