MALICIOUS — mimikaz.exe
MALICIOUS — mimikaz.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Mimikatz family. 11 of 56 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
61c0810a23580cf492a6ba4f7654566108331e7a4134c968c2d6a05261b2d8a1 - SHA-1:
e3b6ea8c46fa831cec6f235a5cf48b38a4ae8d69 - MD5:
29efd64dd3c7fe1e2b022b7ad73a1ba5 - imphash:
54ccad29800146a9484fc134da861841 - ssdeep:
24576:0CgjBAeu8iuUHGzkuBhzy2F+yVICFPC27rIlve3NuacODvsG:0CI7XBE2IuF64rIlmdii - TLSH:
T19556189C8B5F1211D2BACD74BC6195ED8476F0A85079FBAC0E03CA7A8490133DDF25A6 - Submitted as: mimikaz.exe
- File type: pe · Size: 1355264 bytes
- Verdict: malicious (100/100) · Family: Mimikatz
Detections (11 of 56 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- capa (capabilities): capability:credential-access
- ClamAV (daily): Win.Dropper.Mimikatz-9778171-1
- YARA: Airbnb BinaryAlert: hacktool_windows_mimikatz_copywrite
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: MalwareAnalyser community pack: TL_Shellcode_VirtualAlloc_Exec
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: HackTool:Win32/Mimikatz!pz
- Emsisoft (Emergency Kit): Trojan.HackTool.Mimikatz.1
- Trellix Stinger (McAfee): HTool-MimiKatz!29EFD64DD3C7
- Kaspersky (KVRT): Trojan-PSW.Win32.WinCred.ato
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
- Generic_Credential_Theft_Strings
Why this verdict
The malicious score of 100/100 is the fusion of 16 weighted signals:
- ClamAV (daily) flagged Win.Dropper.Mimikatz-9778171-1 (rule
Win.Dropper.Mimikatz-9778171-1) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - References to browser/OS credential stores (rule
Generic_Credential_Theft_Strings) - yara signal, weight 0.60, confidence 0.90 - YARA: Airbnb BinaryAlert flagged hacktool_windows_mimikatz_copywrite (rule
hacktool_windows_mimikatz_copywrite) - engine signal, weight 0.70, confidence 0.70 - Microsoft Defender flagged HackTool:Win32/Mimikatz!pz (rule
HackTool:Win32/Mimikatz!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.HackTool.Mimikatz.1 (rule
Trojan.HackTool.Mimikatz.1) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged HTool-MimiKatz!29EFD64DD3C7 (rule
HTool-MimiKatz!29EFD64DD3C7) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-PSW.Win32.WinCred.ato (rule
Trojan-PSW.Win32.WinCred.ato) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - access stored credentials (rule
access stored credentials) - capa signal, weight 0.50, confidence 0.80 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser built-in flagged Windows_Injection_Api_Combo (rule
Windows_Injection_Api_Combo) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:credential-access (rule
capability:credential-access) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Shellcode_VirtualAlloc_Exec (rule
TL_Shellcode_VirtualAlloc_Exec) - engine signal, weight 0.30, confidence 0.70 - encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60 - inject code into another process (rule
inject code into another process) - capa signal, weight 0.12, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://blog.gentilkiwi.com/mimikatz
- https://pingcastle.com
- https://mysmartlogon.com
- https://login.microsoftonline.com
Embedded domains
- gentilkiwi.com
- blog.gentilkiwi.com
- gmail.com
- pingcastle.com
- mysmartlogon.com
- login.microsoftonline.com
File paths
- c:\windows\system32\spool\drivers\%s
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Ngc
More Mimikatz samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report