MB-257f942650afbf14f40b45a7ccfee3959d7b59dcf7030ca9a246ad8fa3ca925a
high
📛 Threat Title
Unknown: gmail.ps1
Description
File type: ps1. Size: 2730 bytes. Tags: ps1. Reporter: BastianHein_. First seen: 2026-05-21 00:15:26.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
257f942650afbf14f40b45a7ccfee3959d7b59dcf7030ca9a246ad8fa3ca925a
VT 7 / 75
IOC database
- Type
- hash_sha256
- Value
257f942650afbf14f40b45a7ccfee3959d7b59dcf7030ca9a246ad8fa3ca925a- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 7 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Arcabit | malicious | CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 |
| BitDefender | malicious | CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 |
| CTX | malicious | powershell.unknown.pantera |
| Emsisoft | malicious | CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 (B) |
| GData | malicious | CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 |
| MicroWorld-eScan | malicious | CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 |
| VIPRE | malicious | CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 |
Details From VirusTotal
Basic Properties
| MD5 | 69c5050366ff5915f17c2c8fbdde8332 |
| SHA-1 | 4891c0b401d23599c70d8fc386aeacf2ddaa21fa |
| SHA-256 | 257f942650afbf14f40b45a7ccfee3959d7b59dcf7030ca9a246ad8fa3ca925a |
| SSDEEP | 48:A3q6XuS3H2Oe3jqYzf5xzMYA1r893qNKVywwS2/Lj/iu8xl6/tXqfw19:A/L3H2OeHTzbA1r8qNC2/Cu82/taf29 |
| TLSH | T1EF517599EC5F3E40D72423E201CF48E4489D17DD7AD399DD231AD0485F8632798E8ED8 |
| File type | Powershell |
| File type tag | powershell |
| File extension | ps1 |
| Magic | ASCII text, with very long lines (2667u), with CRLF line terminators |
| File size | 2.7 KB |
History
| First seen on VirusTotal | 2026-05-20 23:50 UTC |
| Last submission | 2026-05-20 23:50 UTC |
| Last analysis | 2026-05-21 00:13 UTC |
| Last modified on VirusTotal | 2026-05-21 00:18 UTC |
Known Names
gmail.ps1
hash_sha1
4891c0b401d23599c70d8fc386aeacf2ddaa21fa
VT 7 / 75
IOC database
- Type
- hash_sha1
- Value
4891c0b401d23599c70d8fc386aeacf2ddaa21fa- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 7 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Arcabit | malicious | CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 |
| BitDefender | malicious | CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 |
| CTX | malicious | powershell.unknown.pantera |
| Emsisoft | malicious | CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 (B) |
| GData | malicious | CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 |
| MicroWorld-eScan | malicious | CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 |
| VIPRE | malicious | CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 |
Details From VirusTotal
Basic Properties
| MD5 | 69c5050366ff5915f17c2c8fbdde8332 |
| SHA-1 | 4891c0b401d23599c70d8fc386aeacf2ddaa21fa |
| SHA-256 | 257f942650afbf14f40b45a7ccfee3959d7b59dcf7030ca9a246ad8fa3ca925a |
| SSDEEP | 48:A3q6XuS3H2Oe3jqYzf5xzMYA1r893qNKVywwS2/Lj/iu8xl6/tXqfw19:A/L3H2OeHTzbA1r8qNC2/Cu82/taf29 |
| TLSH | T1EF517599EC5F3E40D72423E201CF48E4489D17DD7AD399DD231AD0485F8632798E8ED8 |
| File type | Powershell |
| File type tag | powershell |
| File extension | ps1 |
| Magic | ASCII text, with very long lines (2667u), with CRLF line terminators |
| File size | 2.7 KB |
History
| First seen on VirusTotal | 2026-05-20 23:50 UTC |
| Last submission | 2026-05-21 00:23 UTC |
| Last analysis | 2026-05-21 00:23 UTC |
| Last modified on VirusTotal | 2026-05-21 00:29 UTC |
Known Names
_257f942650afbf14f40b45a7ccfee3959d7b59dcf7030ca9a246ad8fa3ca925a.txtgmail.ps1
hash_md5
69c5050366ff5915f17c2c8fbdde8332
VT 7 / 75
IOC database
- Type
- hash_md5
- Value
69c5050366ff5915f17c2c8fbdde8332- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 7 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Arcabit | malicious | CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 |
| BitDefender | malicious | CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 |
| CTX | malicious | powershell.unknown.pantera |
| Emsisoft | malicious | CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 (B) |
| GData | malicious | CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 |
| MicroWorld-eScan | malicious | CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 |
| VIPRE | malicious | CMD:Heur.BZC.PZQ.Pantera.130.DB00AE53 |
Details From VirusTotal
Basic Properties
| MD5 | 69c5050366ff5915f17c2c8fbdde8332 |
| SHA-1 | 4891c0b401d23599c70d8fc386aeacf2ddaa21fa |
| SHA-256 | 257f942650afbf14f40b45a7ccfee3959d7b59dcf7030ca9a246ad8fa3ca925a |
| SSDEEP | 48:A3q6XuS3H2Oe3jqYzf5xzMYA1r893qNKVywwS2/Lj/iu8xl6/tXqfw19:A/L3H2OeHTzbA1r8qNC2/Cu82/taf29 |
| TLSH | T1EF517599EC5F3E40D72423E201CF48E4489D17DD7AD399DD231AD0485F8632798E8ED8 |
| File type | Powershell |
| File type tag | powershell |
| File extension | ps1 |
| Magic | ASCII text, with very long lines (2667u), with CRLF line terminators |
| File size | 2.7 KB |
History
| First seen on VirusTotal | 2026-05-20 23:50 UTC |
| Last submission | 2026-05-21 00:23 UTC |
| Last analysis | 2026-05-21 00:23 UTC |
| Last modified on VirusTotal | 2026-05-21 00:51 UTC |
Known Names
_257f942650afbf14f40b45a7ccfee3959d7b59dcf7030ca9a246ad8fa3ca925a.txtgmail.ps1
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: ps1. Size: 2730 bytes. Tags: ps1. Reporter: BastianHein_. First seen: 2026-05-21 00:15:26.
Remediations (8)
-
web:github.com
The script provides two main functionalities: detection and remediation of built-in apps. By default, the script runs in detection mode, but it can also be configured to perform remediation .
-
web:learn.microsoft.com
This table shows the script names, descriptions, detections, remediations , and configurable items. Script files whose names start with Detect are detection scripts. Remediation scripts start with Remediate. These scripts can be copied from the next section in this article.
-
web:microsoft.github.io
The Exchange On-premises Mitigation Tool (EOMT) applies IIS URL Rewrite mitigations for known Exchange Server CVEs. It replaces the legacy EOMT.ps1 and EOMTv2.ps1 scripts with a single, extensible tool that supports multiple CVEs from a unified interface. Features Multi-CVE support — Apply mitigations for any supported CVE from a single script Interactive CVE selection — When -CVE is not ...
-
web:powershellisfun.com
Microsoft Defender has security recommendations for the "Fix unquoted service path for Windows services." (CVE-2013-1609, CVE-2014-0759, CVE-2014-5455) These might be reported for things like Dell services, and you can fix them manually by editing the Registry on the affected device. But… There is an easier way This blog post will show you how to create a Proactive Remediation in Intune ...
-
web:scloud.work
When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what […]
-
web:stackoverflow.com
I create a detection and remediation script and upload it in Intune however when I run the remediation script the status shows in the detection (With issues) and remediation (failed). I've been trying to move the exit 1 code but having the same result. I don't know if the problem is on my script, but here's my script: DetectAdminChange.ps1
-
web:www.joeyverlinden.com
The complete detection script can be found here. The remediation script can be found here. Detect_CloudDeliveredProtection.ps1 / Remediate_CloudDeliveredProtection.ps1 This proactive remediation is built by Simon Eriksen. Credits go to him directly! This proactive remediation configures the device to send advanced information to Microsoft about malicious software, spyware, and potentially ...
-
web:www.reddit.com
69 votes, 55 comments. Forget Powershell, Remediation seem to be one of the only "Instant" actions on Intune. On a a Hybrid or On-Prem PC, you can…
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.