Open-source atomic malware analysis

Analyze another

MSFT_IntuneAppProtectionPolicyiOS.psm1

POWERSHELL
Verdict: BENIGN
Mal-ecule
O(C)H(Cm)
Size 39.0 KB download unavailable
First seen 73 days ago
Analyzed 69 days ago

Objectives

notable severity, 90% confident.
command-and-control/channel/deaddrop Microsoft Graph mailbox client
component severity, 70% confident.
anti-static/obfuscation/code-metrics Many random-looking source identifier names
component severity, 94% confident.
command-and-control/backdoor/tasking Regex component marker
component severity, 90% confident.
command-and-control/dropper/execution Regex component marker
component severity, 86% confident.
command-and-control/dropper/staging Multiple embedded base64 literals
component severity, 95% confident.
evasion/indicator-removal Regex component marker

Micro-behaviors

notable severity, 75% confident.
communications/http/lib HTTP/HTTPS URL literal
baseline severity, 90% confident.
communications/http HTTPS protocol prefix
component severity, 100% confident.
data/text/keywords "Environment" keyword
component severity, 84% confident.
data/text/llm clipboard keyword (doc-context)
component severity, 84% confident.
fs/path Hidden directory path literal

Metadata

baseline severity, 100% confident.
lang Valid PowerShell code
component severity, 90% confident.
file/text File has 30 or more lines

Identity

SHA-256 7bcf7d9849c34804619b8467cbfa4f979f53d6d4e051846ac596409ab2be22ea
Filename MSFT_IntuneAppProtectionPolicyiOS.psm1

Origin

Source harvest

Timeline

First seen 4 Jun 2026 23:20 UTC
First analyzed 9 Jun 2026 10:18 UTC
Last analyzed 9 Jun 2026 10:18 UTC
Last updated 9 Jun 2026 10:18 UTC

Labeling

Label bad
Label source harvest
Traits version 58380