How to remove mimikatz.exe
- File Details
- Overview
- Analysis
mimikatz.exe
The module mimikatz.exe has been detected as Hack.Mimikatz
File Details
Product Name: |
|
Company Name: |
|
MD5: |
53a0a94fcd38c422caf334b44638c03d |
Size: |
888 KB |
First Published: |
2018-06-29 20:04:38 (6 years ago) |
Latest Published: |
2020-11-25 23:22:43 (4 years ago) |
Status: |
Hack.Mimikatz (on last analysis) |
|
Analysis Date: |
2020-11-25 23:22:43 (4 years ago) |
Overview
%localappdata%\packages\kalilinux.54290c8133fee_ey8k8hqnwqnmg\localstate\rootfs\usr\share\mimikatz |
%sysdrive%\utilities\mimikatz_trunk |
%desktop%\zrtfg |
%desktop%\aaaaaa\m |
%sysdrive%\$recycle.bin\s-1-5-21-4002530241-252803949-4081733239-1001\$r0x0u0a |
%sysdrive%\$recycle.bin\s-1-5-21-4002530241-252803949-4081733239-1001\$ruk6czp |
%sysdrive%\bcert 19-02\encryption exercise\mimikatz_trunk.zip |
Windows 8.1 |
42.9% |
|
Windows 10 |
28.6% |
|
Windows Server 2008 R2 |
14.3% |
|
Windows Server 2012 R2 |
14.3% |
|
Analysis
Subsystem: |
Windows CUI |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000140000000 |
Entry Address: |
0x0007e2a8 |
Name |
Size of data |
MD5 |
.text |
540672 |
03f7364e372fae7f3273aa3aecf1bca4 |
.rdata |
294400 |
41608f17c8fac060369f150566be43fa |
.data |
20992 |
92f37eb207b78bad2ba6a2ff50a7e660 |
.pdata |
17920 |
5fdfd0b652228a57ec56b213ad628d68 |
.rsrc |
16384 |
3705eb79ddeb0c097a5b73534640fc70 |
.reloc |
6656 |
fe12c24325df5f7bc8ed06031e5e8f51 |