s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-257f942650afbf14f40b45a7ccfee3959d7b59dcf7030ca9a246ad8fa3ca925a high

📛 Threat Title

Unknown: gmail.ps1

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: ps1. Size: 2730 bytes. Tags: ps1. Reporter: BastianHein_. First seen: 2026-05-21 00:15:26.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 257f942650afbf14f40b45a7ccfee3959d7b59dcf7030ca9a246ad8fa3ca925a VT 7 / 75

IOC database

Type
hash_sha256
Value
257f942650afbf14f40b45a7ccfee3959d7b59dcf7030ca9a246ad8fa3ca925a
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 7 of 75 VirusTotal vendors

VendorVerdictDetection
Arcabit malicious CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53
BitDefender malicious CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53
CTX malicious powershell.unknown.pantera
Emsisoft malicious CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 (B)
GData malicious CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53
MicroWorld-eScan malicious CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53
VIPRE malicious CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53

Details From VirusTotal

Basic Properties
MD569c5050366ff5915f17c2c8fbdde8332
SHA-14891c0b401d23599c70d8fc386aeacf2ddaa21fa
SHA-256257f942650afbf14f40b45a7ccfee3959d7b59dcf7030ca9a246ad8fa3ca925a
SSDEEP48:A3q6XuS3H2Oe3jqYzf5xzMYA1r893qNKVywwS2/Lj/iu8xl6/tXqfw19:A/L3H2OeHTzbA1r8qNC2/Cu82/taf29
TLSHT1EF517599EC5F3E40D72423E201CF48E4489D17DD7AD399DD231AD0485F8632798E8ED8
File typePowershell
File type tagpowershell
File extensionps1
MagicASCII text, with very long lines (2667u), with CRLF line terminators
File size2.7 KB
History
First seen on VirusTotal2026-05-20 23:50 UTC
Last submission2026-05-20 23:50 UTC
Last analysis2026-05-21 00:13 UTC
Last modified on VirusTotal2026-05-21 00:18 UTC
Known Names
  • gmail.ps1
hash_sha1 4891c0b401d23599c70d8fc386aeacf2ddaa21fa VT 7 / 75

IOC database

Type
hash_sha1
Value
4891c0b401d23599c70d8fc386aeacf2ddaa21fa
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 7 of 75 VirusTotal vendors

VendorVerdictDetection
Arcabit malicious CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53
BitDefender malicious CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53
CTX malicious powershell.unknown.pantera
Emsisoft malicious CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 (B)
GData malicious CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53
MicroWorld-eScan malicious CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53
VIPRE malicious CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53

Details From VirusTotal

Basic Properties
MD569c5050366ff5915f17c2c8fbdde8332
SHA-14891c0b401d23599c70d8fc386aeacf2ddaa21fa
SHA-256257f942650afbf14f40b45a7ccfee3959d7b59dcf7030ca9a246ad8fa3ca925a
SSDEEP48:A3q6XuS3H2Oe3jqYzf5xzMYA1r893qNKVywwS2/Lj/iu8xl6/tXqfw19:A/L3H2OeHTzbA1r8qNC2/Cu82/taf29
TLSHT1EF517599EC5F3E40D72423E201CF48E4489D17DD7AD399DD231AD0485F8632798E8ED8
File typePowershell
File type tagpowershell
File extensionps1
MagicASCII text, with very long lines (2667u), with CRLF line terminators
File size2.7 KB
History
First seen on VirusTotal2026-05-20 23:50 UTC
Last submission2026-05-21 00:23 UTC
Last analysis2026-05-21 00:23 UTC
Last modified on VirusTotal2026-05-21 00:29 UTC
Known Names
  • _257f942650afbf14f40b45a7ccfee3959d7b59dcf7030ca9a246ad8fa3ca925a.txt
  • gmail.ps1
hash_md5 69c5050366ff5915f17c2c8fbdde8332 VT 7 / 75

IOC database

Type
hash_md5
Value
69c5050366ff5915f17c2c8fbdde8332
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 7 of 75 VirusTotal vendors

VendorVerdictDetection
Arcabit malicious CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53
BitDefender malicious CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53
CTX malicious powershell.unknown.pantera
Emsisoft malicious CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 (B)
GData malicious CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53
MicroWorld-eScan malicious CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53
VIPRE malicious CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53

Details From VirusTotal

Basic Properties
MD569c5050366ff5915f17c2c8fbdde8332
SHA-14891c0b401d23599c70d8fc386aeacf2ddaa21fa
SHA-256257f942650afbf14f40b45a7ccfee3959d7b59dcf7030ca9a246ad8fa3ca925a
SSDEEP48:A3q6XuS3H2Oe3jqYzf5xzMYA1r893qNKVywwS2/Lj/iu8xl6/tXqfw19:A/L3H2OeHTzbA1r8qNC2/Cu82/taf29
TLSHT1EF517599EC5F3E40D72423E201CF48E4489D17DD7AD399DD231AD0485F8632798E8ED8
File typePowershell
File type tagpowershell
File extensionps1
MagicASCII text, with very long lines (2667u), with CRLF line terminators
File size2.7 KB
History
First seen on VirusTotal2026-05-20 23:50 UTC
Last submission2026-05-21 00:23 UTC
Last analysis2026-05-21 00:23 UTC
Last modified on VirusTotal2026-05-21 00:51 UTC
Known Names
  • _257f942650afbf14f40b45a7ccfee3959d7b59dcf7030ca9a246ad8fa3ca925a.txt
  • gmail.ps1

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: ps1. Size: 2730 bytes. Tags: ps1. Reporter: BastianHein_. First seen: 2026-05-21 00:15:26.

Remediations (8)

  • web:github.com

    The script provides two main functionalities: detection and remediation of built-in apps. By default, the script runs in detection mode, but it can also be configured to perform remediation .

  • web:learn.microsoft.com

    This table shows the script names, descriptions, detections, remediations , and configurable items. Script files whose names start with Detect are detection scripts. Remediation scripts start with Remediate. These scripts can be copied from the next section in this article.

  • web:microsoft.github.io

    The Exchange On-premises Mitigation Tool (EOMT) applies IIS URL Rewrite mitigations for known Exchange Server CVEs. It replaces the legacy EOMT.ps1 and EOMTv2.ps1 scripts with a single, extensible tool that supports multiple CVEs from a unified interface. Features Multi-CVE support — Apply mitigations for any supported CVE from a single script Interactive CVE selection — When -CVE is not ...

  • web:powershellisfun.com

    Microsoft Defender has security recommendations for the "Fix unquoted service path for Windows services." (CVE-2013-1609, CVE-2014-0759, CVE-2014-5455) These might be reported for things like Dell services, and you can fix them manually by editing the Registry on the affected device. But… There is an easier way This blog post will show you how to create a Proactive Remediation in Intune ...

  • web:scloud.work

    When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what […]

  • web:stackoverflow.com

    I create a detection and remediation script and upload it in Intune however when I run the remediation script the status shows in the detection (With issues) and remediation (failed). I've been trying to move the exit 1 code but having the same result. I don't know if the problem is on my script, but here's my script: DetectAdminChange.ps1

  • web:www.joeyverlinden.com

    The complete detection script can be found here. The remediation script can be found here. Detect_CloudDeliveredProtection.ps1 / Remediate_CloudDeliveredProtection.ps1 This proactive remediation is built by Simon Eriksen. Credits go to him directly! This proactive remediation configures the device to send advanced information to Microsoft about malicious software, spyware, and potentially ...

  • web:www.reddit.com

    69 votes, 55 comments. Forget Powershell, Remediation seem to be one of the only "Instant" actions on Intune. On a a Hybrid or On-Prem PC, you can…

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.