s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

VT-500cd979076c01f3873bd08de8f09163f74eb25a462ea66037b92a0665524012 medium

📛 Threat Title

File hash (SHA256): 500cd979076c01f3873bd08de8f09163f74eb25a462ea66037b92a0665524012

Category: malware-hash Published: Source updated: First seen: Last updated:

Description

Hash IOC ingested from threat-intel feed 'Abuse.ch'. See VirusTotal for vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, dropped files, etc.). Feed description: SHA256 hashes: Recent additions

Indicators of Compromise (2)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain abuse.ch VT 0 / 91 UrlVoid 1 / 35

IOC database

Type
domain
Value
abuse.ch
First seen
Last seen
Attached to this threat
Appears in
4019 threats
Description
Extracted from Threat VT-0bc58e58275d6ecca05335aac681a0352173e19d8718230c1902c2bf99d8782f

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
TLDch
History
Last analysis2026-05-24 09:28 UTC
Last modified on VirusTotal2026-05-24 16:38 UTC
WHOIS record date2026-03-29 11:09 UTC
hash_sha256 500cd979076c01f3873bd08de8f09163f74eb25a462ea66037b92a0665524012 VT 25 / 75 1 feed

IOC database

Type
hash_sha256
Value
500cd979076c01f3873bd08de8f09163f74eb25a462ea66037b92a0665524012
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
AgentTesla

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 25 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Trojan[downloader]:Win/Heur2.ZKdf
Arcabit malicious GT:VB.Heur2.ZBot.3.C8B18C87
Avira malicious TR/SNH
BitDefender malicious GT:VB.Heur2.ZBot.3.C8B18C87
CTX malicious txt.trojan.generic
Cynet malicious Malicious (score: 99)
DrWeb malicious VBS.Starter.539
Emsisoft malicious GT:VB.Heur2.ZBot.3.C8B18C87 (B)
ESET-NOD32 malicious PowerShell/TrojanDownloader.Agent.QCG trojan
F-Secure malicious Trojan.TR/SNH
Fortinet malicious VBS/Agent.QCG!tr
GData malicious GT:VB.Heur2.ZBot.3.C8B18C87
Google malicious Detected
Ikarus malicious Trojan-Downloader.PowerShell.Agent
Kaspersky malicious HEUR:Trojan.Script.Generic
Lionic malicious Trojan.CSV.ZBot.4!c
McAfeeD malicious Trojan:Script/Remcos.AW!1
MicroWorld-eScan malicious GT:VB.Heur2.ZBot.3.C8B18C87
Sangfor malicious Malware.Generic-HTML.Save.61eb41a5
Symantec malicious Trojan.Gen.MBT
Tencent malicious Win32.Trojan-Downloader.Downloader.Qwhl
TrendMicro malicious Backdoor.VBS.XWORM.YXGEOZ
TrendMicro-HouseCall malicious Backdoor.VBS.XWORM.YXGEOZ
Varist malicious VBS/Agent.CRE
VIPRE malicious GT:VB.Heur2.ZBot.3.C8B18C87

Details From VirusTotal

Basic Properties
MD5b881069da4c4526a6e5002d580619845
SHA-1c5591c5cc73d4beac2508ced5b9d89dd499982f1
SHA-256500cd979076c01f3873bd08de8f09163f74eb25a462ea66037b92a0665524012
SSDEEP96:qJXHaAQpVjz9UOSe01Uf6sxrGzTz3wnlrl2DiOxfXEUV9umgY+8iP0jOg0BNhpVB:qJXHor6loQO
TLSHT161B50A01066D5668B088578C7CCB3F5A26E766BE04CD1F98B67A7F333815072FCAA4B5
File typeCSV
File type tagcsv
File extensioncsv
MagicCSV text
File size2.3 MB
History
First seen on VirusTotal2026-05-15 14:21 UTC
Last submission2026-05-18 06:33 UTC
Last analysis2026-05-18 06:33 UTC
Last modified on VirusTotal2026-05-18 11:48 UTC
Known Names
  • 500cd979076c01f3873bd08de8f09163f74eb25a462ea66037b92a0665524012.vbs
  • _500cd979076c01f3873bd08de8f09163f74eb25a462ea66037b92a0665524012.txt
  • ORDEN 5377 PROYRCTOS.vbs
  • confirmaci�n de pago.vbs
  • ORDEN_5377_PROYRCTOS.vbs

References (1)

  • VirusTotal report

    Vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, execution parents, dropped files).

Remediations (10)

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.