Open-source atomic malware analysis

Analyze another

MSFT_IntuneRoleAssignment.psm1

POWERSHELL
Verdict: BENIGN
Mal-ecule
O(C)H(Cm)
Size 21.2 KB download
First seen 73 days ago
Analyzed 70 days ago

Objectives

notable severity, 90% confident.
command-and-control/channel/deaddrop Microsoft Graph mailbox client
component severity, 94% confident.
command-and-control/backdoor/tasking Regex component marker
component severity, 90% confident.
command-and-control/dropper/execution Regex component marker
component severity, 86% confident.
command-and-control/dropper/staging Multiple embedded base64 literals
component severity, 95% confident.
evasion/indicator-removal Regex component marker
component severity, 100% confident.
exfiltration/cloud Regex component marker

Micro-behaviors

notable severity, 75% confident.
communications/http/lib HTTP/HTTPS URL literal
baseline severity, 90% confident.
communications/http HTTPS protocol prefix
component severity, 100% confident.
data/text/keywords "Environment" keyword

Metadata

baseline severity, 100% confident.
lang Valid PowerShell code
component severity, 90% confident.
file/text File has 30 or more lines

Identity

SHA-256 20a020c3bb3fdf295b4438cba630a7ffd380c32027f3b2496caeef91749ff71b
Filename MSFT_IntuneRoleAssignment.psm1

Origin

Source harvest

Timeline

First seen 4 Jun 2026 23:20 UTC
First analyzed 8 Jun 2026 01:09 UTC
Last analyzed 8 Jun 2026 01:09 UTC
Last updated 8 Jun 2026 01:09 UTC

Labeling

Label bad
Label source harvest
Traits version 8e9ac