s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-b904d112863daa15107be8a9419738ed3ac4987c6191bea17248c3bba7f0424a high

📛 Threat Title

Unknown: RUN.bat

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: bat. Size: 2922984 bytes. Tags: bat. Reporter: burger403. First seen: 2026-05-14 17:57:08.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain run.bat

IOC database

Type
domain
Value
run.bat
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Extracted from Threat MB-b904d112863daa15107be8a9419738ed3ac4987c6191bea17248c3bba7f0424a

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 b904d112863daa15107be8a9419738ed3ac4987c6191bea17248c3bba7f0424a 1 feed

IOC database

Type
hash_sha256
Value
b904d112863daa15107be8a9419738ed3ac4987c6191bea17248c3bba7f0424a
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 f0b0ae8b014fa703a496ce85af1e520496e13607 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/f0b0ae8b014fa703a496ce85af1e520496e13607
1 feed

IOC database

Type
hash_sha1
Value
f0b0ae8b014fa703a496ce85af1e520496e13607
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/f0b0ae8b014fa703a496ce85af1e520496e13607

hash_md5 137942d0682a209adc293ebe0f724378 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/137942d0682a209adc293ebe0f724378
1 feed

IOC database

Type
hash_md5
Value
137942d0682a209adc293ebe0f724378
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/137942d0682a209adc293ebe0f724378

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: bat. Size: 2922984 bytes. Tags: bat. Reporter: burger403. First seen: 2026-05-14 17:57:08.

Remediations (10)

  • web:bonguides.com

    Intune remediation is all about using Microsoft Intune to automatically find and fix common issues on managed devices. It works through remediation scripts, which include a detection script to spot problems and a remediation script to solve them.

  • web:community.spiceworks.com

    This is for the remediation status column. I can't find anything on the interwebs about this. I know the scripts should work b/c I used other scripts that worked and only changed the registry key and value within each script, and the scripts are UTF-8. Detection status of course shows 'With issues' b/c the registry key value is wrong, the remediation script sets to correct value. DETECT ...

  • web:learn.microsoft.com

    The run remediation action in Microsoft Intune allows IT administrators to proactively detect and resolve support issues on managed devices. This action triggers a remediation script that checks for specific conditions and applies a fix if needed—without requiring user interaction. Use this action to address common problems such as configuration drift, missing settings, or compliance gaps ...

  • web:learn.microsoft.com

    Learn more about Remediations in Microsoft Intune, including what Remediations are and view any prerequisites and licensing requirements. Also, learn how to deploy built-in and custom remediation scripts, and learn how to monitor your scripts.

  • web:scloud.work

    When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what […]

  • web:stackoverflow.com

    Failed remediation script in Intune while "run script 64-bit PowerShell" option is turned on Ask Question Asked 1 year, 10 months ago Modified 1 year, 10 months ago

  • web:www.reddit.com

    The remediation script below runs DISM, checks/corrects various registry values, checks for update blocks, and finally checks for Windows Updates. I mostly put together different pieces that I've found online, wrote of my own and definitely did not write any of the modules in here.

  • web:www.reddit.com

    I am fairly new to using Compliance settings in SCCM but I can't seem to figure out why my remediation powershell script is not running. I have setup the CI to remediate, tested the script manually to make sure it's working. The deployment is also set to remediate and I confirmed that the powershell execution policy is set to bypass in the client settings. I can also confirm that the ...

  • web:www.spyglassmtg.com

    Intune's remediation scripts and on-demand remediation scripting capabilities provide IT admins with a powerful way to enforce policies, troubleshoot issues, and maintain compliance.

  • web:www.systemcenterdudes.com

    In this post, we will describe how to use Intune Remediation script with an example to uninstall an application based on detection script.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.