MALICIOUS — mimikatz.exe
MALICIOUS — mimikatz.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Mimikatz family. 5 of 38 detection engines flagged it, exhibiting 5 ATT&CK techniques.
Identification
- SHA-256:
f8b15bef0053858be6342669099f5d4478dc4a6482f68fb32234b2fffcb2c0a0 - SHA-1:
4927d85d0fbe3c870175c79ed96e37d8dc856338 - MD5:
01e866f56d2ac8e16884b1bab4dbd3ca - imphash:
54ccad29800146a9484fc134da861841 - ssdeep:
24576:0CgjBAeu8iuUHGzkuBhzy2F+yVICFPC27rIlve3NuacODvsGR:0CI7XBE2IuF64rIlmdiit - TLSH:
T1AE56189C8B5F1211D2BACD74BC6195ED8476F0A85079FBAC0E03CA7A8490133DDF25A6 - Submitted as: mimikatz.exe
- File type: pe · Size: 1355277 bytes
- Verdict: malicious (100/100) · Family: Mimikatz
Detections (5 of 38 engines)
- YARA: MalwareAnalyser built-in: Windows_Injection_Api_Combo
- capa (capabilities): inject code into another process
- ClamAV (daily): Win.Dropper.Mimikatz-9778171-1
- Microsoft Defender: HackTool:Win32/Mimikatz!pz
- Emsisoft (Emergency Kit): Trojan.HackTool.Mimikatz.1
MITRE ATT&CK
YARA
- Windows_Injection_Api_Combo
- Generic_Credential_Theft_Strings
Why this verdict
The malicious score of 100/100 is the fusion of 10 weighted signals:
- ClamAV (daily) flagged Win.Dropper.Mimikatz-9778171-1 (rule
Win.Dropper.Mimikatz-9778171-1) - engine signal, weight 0.90, confidence 0.95 - Process injection API combination (rule
Windows_Injection_Api_Combo) - yara signal, weight 0.65, confidence 0.90 - References to browser/OS credential stores (rule
Generic_Credential_Theft_Strings) - yara signal, weight 0.60, confidence 0.90 - Microsoft Defender flagged HackTool:Win32/Mimikatz!pz (rule
HackTool:Win32/Mimikatz!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.HackTool.Mimikatz.1 (rule
Trojan.HackTool.Mimikatz.1) - engine signal, weight 0.55, confidence 0.85 - inject code into another process (rule
inject code into another process) - capa signal, weight 0.50, confidence 0.80 - access stored credentials (rule
access stored credentials) - capa signal, weight 0.50, confidence 0.80 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: https://blog.gentilkiwi.com/mimikatz, https://pingcastle.com, https://mysmartlogon.com - static signal, weight 0.35, confidence 0.60
- encrypt data (rule
encrypt data) - capa signal, weight 0.30, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://blog.gentilkiwi.com/mimikatz
- https://pingcastle.com
- https://mysmartlogon.com
- https://login.microsoftonline.com
Embedded domains
- gentilkiwi.com
- blog.gentilkiwi.com
- gmail.com
- pingcastle.com
- mysmartlogon.com
- login.microsoftonline.com
Embedded IP addresses
- 1.3.6.1
- 2.5.29.17
- 2.5.29.15
- 2.5.29.37
- 2.5.29.14
- 2.5.29.35
- 2.5.29.31
- 2.5.29.19
- 2.5.4.3
- 2.5.4.11
- 2.5.4.10
- 2.5.4.6
- 1.3.14.3
- 5.5.7.3
- 2.5.4.0
- 2.2.0.0
File paths
- c:\windows\system32\spool\drivers\%s
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Ngc
More Mimikatz samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report