VT-500cd979076c01f3873bd08de8f09163f74eb25a462ea66037b92a0665524012
medium
📛 Threat Title
File hash (SHA256): 500cd979076c01f3873bd08de8f09163f74eb25a462ea66037b92a0665524012
Description
Hash IOC ingested from threat-intel feed 'Abuse.ch'. See VirusTotal for vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, dropped files, etc.). Feed description: SHA256 hashes: Recent additions
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
abuse.ch
VT 0 / 91
UrlVoid 1 / 35
IOC database
- Type
- domain
- Value
abuse.ch- First seen
- Last seen
- Attached to this threat
- Appears in
- 4019 threats
- Description
- Extracted from Threat VT-0bc58e58275d6ecca05335aac681a0352173e19d8718230c1902c2bf99d8782f
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| TLD | ch |
History
| Last analysis | 2026-05-24 09:28 UTC |
| Last modified on VirusTotal | 2026-05-24 16:38 UTC |
| WHOIS record date | 2026-03-29 11:09 UTC |
hash_sha256
500cd979076c01f3873bd08de8f09163f74eb25a462ea66037b92a0665524012
VT 25 / 75
1 feed
IOC database
- Type
- hash_sha256
- Value
500cd979076c01f3873bd08de8f09163f74eb25a462ea66037b92a0665524012- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- AgentTesla
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 25 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Trojan[downloader]:Win/Heur2.ZKdf |
| Arcabit | malicious | GT:VB.Heur2.ZBot.3.C8B18C87 |
| Avira | malicious | TR/SNH |
| BitDefender | malicious | GT:VB.Heur2.ZBot.3.C8B18C87 |
| CTX | malicious | txt.trojan.generic |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | VBS.Starter.539 |
| Emsisoft | malicious | GT:VB.Heur2.ZBot.3.C8B18C87 (B) |
| ESET-NOD32 | malicious | PowerShell/TrojanDownloader.Agent.QCG trojan |
| F-Secure | malicious | Trojan.TR/SNH |
| Fortinet | malicious | VBS/Agent.QCG!tr |
| GData | malicious | GT:VB.Heur2.ZBot.3.C8B18C87 |
| malicious | Detected |
|
| Ikarus | malicious | Trojan-Downloader.PowerShell.Agent |
| Kaspersky | malicious | HEUR:Trojan.Script.Generic |
| Lionic | malicious | Trojan.CSV.ZBot.4!c |
| McAfeeD | malicious | Trojan:Script/Remcos.AW!1 |
| MicroWorld-eScan | malicious | GT:VB.Heur2.ZBot.3.C8B18C87 |
| Sangfor | malicious | Malware.Generic-HTML.Save.61eb41a5 |
| Symantec | malicious | Trojan.Gen.MBT |
| Tencent | malicious | Win32.Trojan-Downloader.Downloader.Qwhl |
| TrendMicro | malicious | Backdoor.VBS.XWORM.YXGEOZ |
| TrendMicro-HouseCall | malicious | Backdoor.VBS.XWORM.YXGEOZ |
| Varist | malicious | VBS/Agent.CRE |
| VIPRE | malicious | GT:VB.Heur2.ZBot.3.C8B18C87 |
Details From VirusTotal
Basic Properties
| MD5 | b881069da4c4526a6e5002d580619845 |
| SHA-1 | c5591c5cc73d4beac2508ced5b9d89dd499982f1 |
| SHA-256 | 500cd979076c01f3873bd08de8f09163f74eb25a462ea66037b92a0665524012 |
| SSDEEP | 96:qJXHaAQpVjz9UOSe01Uf6sxrGzTz3wnlrl2DiOxfXEUV9umgY+8iP0jOg0BNhpVB:qJXHor6loQO |
| TLSH | T161B50A01066D5668B088578C7CCB3F5A26E766BE04CD1F98B67A7F333815072FCAA4B5 |
| File type | CSV |
| File type tag | csv |
| File extension | csv |
| Magic | CSV text |
| File size | 2.3 MB |
History
| First seen on VirusTotal | 2026-05-15 14:21 UTC |
| Last submission | 2026-05-18 06:33 UTC |
| Last analysis | 2026-05-18 06:33 UTC |
| Last modified on VirusTotal | 2026-05-18 11:48 UTC |
Known Names
500cd979076c01f3873bd08de8f09163f74eb25a462ea66037b92a0665524012.vbs_500cd979076c01f3873bd08de8f09163f74eb25a462ea66037b92a0665524012.txtORDEN 5377 PROYRCTOS.vbsconfirmaci�n de pago.vbsORDEN_5377_PROYRCTOS.vbs
References (1)
-
VirusTotal report
Vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, execution parents, dropped files).
Remediations (10)
-
web:brownie.tools
Verify file integrity with SHA-1, SHA-256 , SHA-384, SHA-512. Upload a file , paste the expected hash , and instantly confirm it matches. 100% private.
-
web:check.town
Free file hash checker. Upload a file and compute MD5, SHA-1, SHA-256 , and SHA-512 checksums client-side.
-
web:cybercheck360.com
Calculate the MD5, SHA-1, SHA-256 , and SHA-512 hash of any file directly in your browser. No upload needed, hashes are computed locally.
-
web:emn178.github.io
This SHA256 online tool helps you calculate the hash of a file from local or URL using SHA256 without uploading the file . It also supports HMAC.
-
web:scanly.co
Free file hash calculator. Generate SHA-256 , SHA-512, SHA-1, and MD5 checksums for any file . Verify integrity and detect tampering in your browser.
-
web:webfiletools.com
Calculate & Verify File Hash Compute and verify MD5, SHA-1, SHA-256 , SHA-512 & CRC32 hashes. No file sent — computed in your browser.
-
web:windowsloop.com
Want to check SHA1, SHA256 , SHA384, SHA512, or MD5 hash for a file ? You can do it without using any third-party tools in Windows. Here's how.
-
web:www.freecodeformat.com
Verify file integrity online. Calculate MD5, SHA1, SHA256 , SHA512, SHA3, RIPEMD-160, and CRC32 hashes for any file . Fast, secure, and supports multiple files .
-
web:www.getzenquery.com
Verify file integrity instantly with our free online File Hash Checker. Upload any file to compute MD5, SHA-1, SHA-256 , and SHA-512 hashes—then compare with original or expected checksums. Perfect for ensuring downloaded files are intact, validating software authenticity, or detecting corruption. All processing happens locally in your browser for privacy.
-
web:www.scanwith.com
Free online file hash checker. Calculate MD5, SHA1, SHA256 , SHA512 checksums to verify file integrity. Drag and drop files - processed locally, never uploaded.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.