s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-b361da35631cd2de33fc9a08e2b702b548d04598189b8a81b36484393cac2cd0 high

📛 Threat Title

Unknown: Travel_Omega_Record_654.ps1

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: ps1. Size: 222710 bytes. Tags: CountLoader, memory-shield-vg, ps1. Reporter: iamaachum. First seen: 2026-09-25 22:45:36.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 b361da35631cd2de33fc9a08e2b702b548d04598189b8a81b36484393cac2cd0

IOC database

Type
hash_sha256
Value
b361da35631cd2de33fc9a08e2b702b548d04598189b8a81b36484393cac2cd0
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 5fbb436b599aa46d083d4a4c9d75d175abd9b138

IOC database

Type
hash_sha1
Value
5fbb436b599aa46d083d4a4c9d75d175abd9b138
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 bc0ff67254c4c609491cacdae67572a6

IOC database

Type
hash_md5
Value
bc0ff67254c4c609491cacdae67572a6
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: ps1. Size: 222710 bytes. Tags: CountLoader, memory-shield-vg, ps1. Reporter: iamaachum. First seen: 2026-09-25 22:45:36.

Remediations (10)

  • web:github.com

    Intune related scripts and tings. Contribute to jamesvincent/Intune development by creating an account on GitHub.

  • web:github.com

    The following library contains a collection of remediation scripts designed to remove common unwanted software, adware, and malware found in the wild. If you come across a particular program you'd like to remediate, feel free to download the corresponding script and use it in your environment.

  • web:learn.microsoft.com

    When you create a set of exploit protection mitigations (known as a configuration), you might find that the configuration export and import process does not remove all unwanted mitigations . You can manually remove unwanted mitigations in Windows Security, or you can use the following process to remove all mitigations and then import a baseline configuration file instead. Remove all process ...

  • web:msrc.microsoft.com

    Access Microsoft Security Response Center's guide to address vulnerabilities, manage security risks, and keep your systems protected with the latest updates.

  • web:omegatravel.com

    Omega continues to move forward, providing industry-leading software and services to help your employees navigate the globe safely As one of America's largest business travel management companies, we serve corporations, nonprofits, government agencies and contractors, and educational institutions.

  • web:omegatravel.com

    Government Travel Omega pioneered government travel management in 1982 and, more than four decades later, continues to be the leading innovator in government travel. Our highly trained and experienced government travel staff provides targeted, specialized services, meeting the unique and ever-changing needs of our federal, state, and local government travel customers. As the first travel […]

  • web:tommadness.github.io

    Scans the Glamour Dresser for items that can now be stored in the Armoire (per patch 7.5), finds partial and complete sets, and spots duplicates across the dresser, armoire, bags, armoury, saddlebag and retainers. Everything it finds gets highlighted right in the game's inventory windows, one color per intent, so you can see what to grab without hunting.

  • web:www.infosecurity-magazine.com

    The attackers use a social engineering technique called ClickFix to specifically target individuals in hospitality organizations in North America, Oceania, South and Southeast Asia, and Europe, which are likely to work with Booking.com, an online travel agency.

  • web:www.malwarebytes.com

    We uncovered ClickFix attacks using fake Google and Cloudflare pages to deliver everything from infostealers to a newly discovered malware loader.

  • web:www.reddit.com

    ADMIN MOD Why the hell are remediation the only way to do "Instant" Powershell? Remediations and Scripts Forget Powershell, Remediation seem to be one of the only "Instant" actions on Intune. On a a Hybrid or On-Prem PC, you can just do Invoke-Command PCName {command} to send commands or even Enter-pssession to do an interactive session.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.