61c0810a23580cf492a6ba4f7654566108331e7a4134c968c2d6a05261b2d8a1

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date 2022-Sep-19 15:44:39
Detected languages English - United States
ProductName mimikatz
ProductVersion 2.2.0.0
CompanyName gentilkiwi (Benjamin DELPY)
FileDescription mimikatz for Windows
FileVersion 2.2.0.0
InternalName mimikatz
LegalCopyright Copyright (c) 2007 - 2021 gentilkiwi (Benjamin DELPY)
OriginalFilename mimikatz.exe
PrivateBuild Build with love for POC only
SpecialBuild :)

Plugin Output

Info Matching compiler(s): MASM/TASM - sig1(h)
Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • regedit.exe
  • taskmgr.exe
Miscellaneous malware strings:
  • cmd.exe
  • exploit
Contains code from Mimikatz.
Contains strings from Mimikatz:
  • BCryptCloseAlgorithmProvider
  • BCryptDecrypt
  • BCryptDestroyKey
  • BCryptEncrypt
  • BCryptGenerateSymmetricKey
  • BCryptGetProperty
  • BCryptOpenAlgorithmProvider
  • BCryptSetProperty
  • CredentialKeys
  • Primary
Contains domain names:
  • blog.gentilkiwi.com
  • gentilkiwi.com
  • gmail.com
  • https://blog.gentilkiwi.com
  • https://blog.gentilkiwi.com/mimikatz
  • https://login.microsoftonline.com
  • https://mysmartlogon.com
  • https://pingcastle.com
  • login.microsoftonline.com
  • microsoftonline.com
  • mysmartlogon.com
  • pingcastle.com
Info Libraries used to perform cryptographic operations: Microsoft's Cryptography API
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryW
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • NtQuerySystemInformation
  • NtQueryInformationProcess
Code injection capabilities:
  • CreateRemoteThread
  • WriteProcessMemory
  • VirtualAllocEx
  • VirtualAlloc
  • OpenProcess
Code injection capabilities (mapping injection):
  • CreateRemoteThread
  • CreateFileMappingW
  • MapViewOfFile
  • CreateFileMappingA
Can access the registry:
  • RegQueryValueExW
  • RegQueryInfoKeyW
  • RegEnumValueW
  • RegOpenKeyExW
  • RegEnumKeyExW
  • RegCloseKey
  • RegSetValueExW
Possibly launches other programs:
  • CreateProcessWithLogonW
  • CreateProcessAsUserW
  • CreateProcessW
Uses Windows's Native API:
  • NtQueryObject
  • NtQuerySystemInformation
  • NtQueryInformationProcess
  • NtCompareTokens
  • NtQueryDirectoryObject
  • NtResumeProcess
  • NtOpenDirectoryObject
  • NtSuspendProcess
  • NtTerminateProcess
  • NtQuerySystemEnvironmentValueEx
  • NtSetSystemEnvironmentValueEx
  • NtEnumerateSystemEnvironmentValuesEx
Uses Microsoft's cryptographic API:
  • CryptSetHashParam
  • CryptGetHashParam
  • CryptExportKey
  • CryptAcquireContextW
  • CryptSetKeyParam
  • CryptGetKeyParam
  • CryptReleaseContext
  • CryptDuplicateKey
  • CryptAcquireContextA
  • CryptGetProvParam
  • CryptImportKey
  • CryptEncrypt
  • CryptCreateHash
  • CryptGenKey
  • CryptDestroyKey
  • CryptDecrypt
  • CryptDestroyHash
  • CryptHashData
  • CryptSetProvParam
  • CryptEnumProvidersW
  • CryptEnumProviderTypesW
  • CryptGetUserKey
  • CryptDeriveKey
  • CryptSignHashW
  • CryptSignAndEncodeCertificate
  • CryptDecodeObjectEx
  • CryptStringToBinaryA
  • CryptStringToBinaryW
  • CryptUnprotectData
  • CryptBinaryToStringW
  • CryptBinaryToStringA
  • CryptExportPublicKeyInfo
  • CryptFindOIDInfo
  • CryptAcquireCertificatePrivateKey
  • CryptEncodeObject
  • CryptProtectData
  • CryptQueryObject
Can create temporary files:
  • GetTempPathA
  • CreateFileA
  • CreateFileW
  • GetTempPathW
Memory manipulation functions often used by packers:
  • VirtualAllocEx
  • VirtualProtectEx
  • VirtualAlloc
  • VirtualProtect
Functions related to the privilege level:
  • OpenProcessToken
  • DuplicateTokenEx
  • CheckTokenMembership
  • SamQueryInformationUser
Interacts with services:
  • CreateServiceW
  • DeleteService
  • OpenSCManagerW
  • OpenServiceW
  • QueryServiceObjectSecurity
  • QueryServiceStatusEx
  • ControlService
Manipulates other processes:
  • WriteProcessMemory
  • ReadProcessMemory
  • OpenProcess
Deletes entries from the event log:
  • ClearEventLogW
Queries user information on remote machines:
  • NetWkstaUserEnum
Reads the contents of the clipboard:
  • GetClipboardData
Interacts with the certificate store:
  • CertAddCertificateContextToStore
  • CertAddEncodedCertificateToStore
  • CertOpenStore
Malicious VirusTotal score: 64/69 (Scanned on 2026-09-15 01:06:36) ALYac: Misc.HackTool.Mimikatz
APEX: Malicious
AVG: Win64:MalwareX-gen [Hack]
AhnLab-V3: Trojan/Win32.RL_Mimikatz.R366782
Alibaba: Trojan:Win32/Mimikatz.10401874
Antiy-AVL: HackTool/Win64.Mimikatz
Arcabit: Trojan.HackTool.Mimikatz.1
Avast: Win64:MalwareX-gen [Hack]
Avira: TR/W64.MalwareX
BitDefender: Trojan.HackTool.Mimikatz.1
Bkav: W64.MimikatwQH.Trojan
CAT-QuickHeal: HackTool.Mimikatz.S13719268
CTX: exe.trojan.mimikatz
ClamAV: Win.Dropper.Mimikatz-9778171-1
CrowdStrike: win/malicious_confidence_100% (W)
Cylance: Unsafe
Cynet: Malicious (score: 100)
DeepInstinct: MALICIOUS
DrWeb: Tool.Mimikatz.1232
ESET-NOD32: Win64/Riskware.Mimikatz.G application
Elastic: Windows.Hacktool.Mimikatz
Emsisoft: Trojan.HackTool.Mimikatz.1 (B)
F-Secure: Trojan.TR/W64.MalwareX
Fortinet: Riskware/NetWalker
GData: Win64.Trojan-Stealer.Mimikatz.J
Google: Detected
Gridinsoft: Risk.Win64.Gen.dd!i
Ikarus: Trojan.Mimikatz
Jiangmin: Trojan.PSW.Mimikatz.pv
K7AntiVirus: Riskware ( 005ce46a1 )
K7GW: Riskware ( 005ce46a1 )
Kaspersky: Trojan-PSW.Win32.WinCred.ato
Kingsoft: Win32.Troj.Undef.a
Malwarebytes: Mimikatz.Spyware.Stealer.DDS
MaxSecure: Trojan.Malware.691784879.susgen
McAfeeD: Trojan:Win/Mimikatz.EAH
MicroWorld-eScan: Trojan.HackTool.Mimikatz.1
Microsoft: HackTool:Win32/Mimikatz!pz
NANO-Antivirus: Trojan.Win64.Mimikatz.jsrqig
Paloalto: generic.ml
Panda: HackingTool/Mimikatz
Rising: HackTool.Mimikatz!1.B3A8 (CLASSIC)
SUPERAntiSpyware: Hack.Tool/Gen-Mimikatz
Sangfor: Trojan.Win32.Save.a
SentinelOne: Static AI - Malicious PE
Sophos: ATK/Mimikatz-BJ
Symantec: Hacktool.Mimikatz
TACHYON: Abuse-Worry/W64.Mimikatz.1355264
Tencent: Trojan.Win64.Mimikatz.a
TrellixENS: HTool-MimiKatz!29EFD64DD3C7
TrendMicro: HackTool.Win64.Mimikatz.ZTKE
TrendMicro-HouseCall: HackTool.Win64.Mimikatz.ZTKE
VBA32: Trojan.Win64.Mimikatz
VIPRE: Trojan.HackTool.Mimikatz.1
Varist: W64/S-b61adc75!Eldorado
ViRobot: HackTool.S.Mimikatz.1355264
VirIT: HackTool.Win64.Genus.BBC
Webroot: Win.Trojan.Gen
Xcitium: Malware@#2e2m06ht3u8w
Yandex: Trojan.Agent!RmbVaruywWw
Zillya: Tool.Mimikatz.Win64.2782
ZoneAlarm: ATK/Mimikatz-BJ
alibabacloud: HackTool:Win/Mimikatz.FZ
huorong: HackTool/Mikatz.k

Hashes

MD5 29efd64dd3c7fe1e2b022b7ad73a1ba5 🔍
SHA1 e3b6ea8c46fa831cec6f235a5cf48b38a4ae8d69 🔍
SHA256 61c0810a23580cf492a6ba4f7654566108331e7a4134c968c2d6a05261b2d8a1 🔍
SHA3 ee5ab9c779fb86f845d8ef03025cc0bc8b21e226827f866436eebd71d3ad871f 🔍
SSDeep 24576:0CgjBAeu8iuUHGzkuBhzy2F+yVICFPC27rIlve3NuacODvsG:0CI7XBE2IuF64rIlmdii 🔍
Imports Hash 69f3125e6ab4a89e3fc502cc423d79db 🔍

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x120

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 6
TimeDateStamp 2022-Sep-19 15:44:39
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 9.0
SizeOfCode 0xcf800
SizeOfInitializedData 0x7c200
SizeOfUninitializedData 0
AddressOfEntryPoint 0x00000000000C98E8 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 5.2
ImageVersion 0.0
SubsystemVersion 5.2
Win32VersionValue 0
SizeOfImage 0x14f000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_CUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 c387ce05fea1862e051905b5f962fbba 🔍
SHA1 25498eb95eab2441a9d9cc41468e3e1cbe1d34ce 🔍
SHA256 0dc048763754fe66d89f71f1af307edc3cd1cb5d047b55e479e6d2ed51637455 🔍
SHA3 eddae65c933f1228c7df51ac08b488fc3d3a58f4a4167de22e57fd6b0d895688 🔍
VirtualSize 0xcf709
VirtualAddress 0x1000
SizeOfRawData 0xcf800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.45602

.rdata

MD5 141ab0062504cb120b4b3863487e6eba 🔍
SHA1 dfe825472a5a142d70fec1f3841199596d875d3e 🔍
SHA256 300b18c3d0aeeeb21a4feefada532dc3e33e73c836102796458a7838bcec0160 🔍
SHA3 bb8e4ec6fef5f6e8cb499909db218043860f9386288cb345700b2b2ae360ef74 🔍
VirtualSize 0x67768
VirtualAddress 0xd1000
SizeOfRawData 0x67800
PointerToRawData 0xcfc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.21883

.data

MD5 f77f571524ef2f8a1c79220d1fe86cdd 🔍
SHA1 0c8e78a987202cfb45de9839b6ba952690a9d934 🔍
SHA256 a3d0e2923e6c33be0adbfa2947f9454063fb46e62cbc5c37e2ffb29eec76ebbb 🔍
SHA3 46de4a2939f7235b1fb31e4b4f23417a686e38a49b5680e9ce830ac447b9ce99 🔍
VirtualSize 0x7850
VirtualAddress 0x139000
SizeOfRawData 0x6a00
PointerToRawData 0x137400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 2.86254

.pdata

MD5 66963c87a329693b9732109b0b7f0cbc 🔍
SHA1 c0fe06c56ddd7a9def62955ee0a17fecac2d8e0a 🔍
SHA256 0a2fcebf0f720444e5d06c6ee13a83e1b963e41cb9d3cf4e50dbb0edef5653aa 🔍
SHA3 bfbf8cfe6be7bf47f1ef9e474d6a8315c29138ad7339bdd812f2f3dfccf3e682 🔍
VirtualSize 0x6810
VirtualAddress 0x141000
SizeOfRawData 0x6a00
PointerToRawData 0x13de00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.80758

.rsrc

MD5 59c26993011f89d017b912f5119b3b30 🔍
SHA1 a89b9f96c8bc4fb9eed3ba7148e02c198b08b449 🔍
SHA256 a7f5a1a53fdf2b98e69bfec42336feeaa21ab2a65d42f830568662ad4d1b14d0 🔍
SHA3 a865d0d512fae0f9c9d6e604d13b126b6f2b16f49cf3f91005140ba37aded234 🔍
VirtualSize 0x3fe8
VirtualAddress 0x148000
SizeOfRawData 0x4000
PointerToRawData 0x144800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 6.54115

.reloc

MD5 439cd3f244a4feb5ff04a54a3c1f815c 🔍
SHA1 9c556fc94cd62410a374ad5a90e4923e3abd7981 🔍
SHA256 8b4e33d361cfc1a76ff9325772fb2121aefc95428b55985714839fd114fce5d6 🔍
SHA3 9de23b84e3af20ee497f26ce377921a7f4210312b0c39ecd8353667caa40e30e 🔍
VirtualSize 0x2540
VirtualAddress 0x14c000
SizeOfRawData 0x2600
PointerToRawData 0x148800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.3719

Imports

ADVAPI32.dll CryptSetHashParam
CryptGetHashParam
CryptExportKey
CryptAcquireContextW
CryptSetKeyParam
CryptGetKeyParam
CryptReleaseContext
CryptDuplicateKey
CryptAcquireContextA
CryptGetProvParam
CryptImportKey
SystemFunction007
CryptEncrypt
CryptCreateHash
CryptGenKey
CryptDestroyKey
CryptDecrypt
CryptDestroyHash
CryptHashData
CopySid
GetLengthSid
LsaQueryInformationPolicy
LsaOpenPolicy
LsaClose
CreateWellKnownSid
CreateProcessWithLogonW
CreateProcessAsUserW
RegQueryValueExW
RegQueryInfoKeyW
RegEnumValueW
RegOpenKeyExW
RegEnumKeyExW
RegCloseKey
RegSetValueExW
SystemFunction033
SystemFunction032
ConvertSidToStringSidW
CreateServiceW
CloseServiceHandle
DeleteService
OpenSCManagerW
SetServiceObjectSecurity
OpenServiceW
BuildSecurityDescriptorW
QueryServiceObjectSecurity
StartServiceW
AllocateAndInitializeSid
QueryServiceStatusEx
FreeSid
ControlService
IsTextUnicode
OpenProcessToken
GetTokenInformation
LookupAccountNameW
LookupAccountSidW
DuplicateTokenEx
CheckTokenMembership
CryptSetProvParam
CryptEnumProvidersW
ConvertStringSidToSidW
LsaFreeMemory
GetSidSubAuthority
GetSidSubAuthorityCount
IsValidSid
SetThreadToken
CryptEnumProviderTypesW
SystemFunction006
CryptGetUserKey
OpenEventLogW
GetNumberOfEventLogRecords
ClearEventLogW
SystemFunction001
CryptDeriveKey
SystemFunction005
LsaQueryTrustedDomainInfoByName
CryptSignHashW
LsaSetSecret
SystemFunction023
LsaOpenSecret
LsaQuerySecret
LsaRetrievePrivateData
LsaEnumerateTrustedDomainsEx
LookupPrivilegeValueW
StartServiceCtrlDispatcherW
SetServiceStatus
RegisterServiceCtrlHandlerW
LookupPrivilegeNameW
OpenThreadToken
EqualSid
CredFree
CredEnumerateW
SystemFunction026
ConvertStringSecurityDescriptorToSecurityDescriptorW
SystemFunction027
SystemFunction041
CredIsMarshaledCredentialW
CredUnmarshalCredentialW
Cabinet.dll #11
#14
#10
#13
CRYPT32.dll CryptSignAndEncodeCertificate
CertEnumSystemStore
CertEnumCertificatesInStore
CertAddCertificateContextToStore
CryptDecodeObjectEx
CryptStringToBinaryA
CertAddEncodedCertificateToStore
CertOpenStore
CertFreeCertificateContext
CertCloseStore
CryptStringToBinaryW
CertSetCertificateContextProperty
PFXExportCertStoreEx
CryptUnprotectData
CryptBinaryToStringW
CryptBinaryToStringA
CryptExportPublicKeyInfo
CryptFindOIDInfo
CryptAcquireCertificatePrivateKey
CertNameToStrW
CertFindCertificateInStore
CertGetCertificateContextProperty
CertGetNameStringW
CryptEncodeObject
CryptProtectData
CryptQueryObject
cryptdll.dll MD5Init
MD5Final
CDLocateCSystem
CDGenerateRandomBits
CDLocateCheckSum
MD5Update
DNSAPI.dll DnsFree
DnsQuery_A
FLTLIB.DLL FilterFindFirst
FilterFindNext
MPR.dll WNetCancelConnection2W
WNetAddConnection2W
NETAPI32.dll NetStatisticsGet
DsGetDcNameW
NetApiBufferFree
NetRemoteTOD
NetSessionEnum
NetServerGetInfo
DsEnumerateDomainTrustsW
NetShareEnum
NetWkstaUserEnum
ODBC32.dll #75
#9
#43
#24
#31
#111
#141
#13
ole32.dll CoInitializeEx
CoSetProxyBlanket
CoTaskMemFree
CoUninitialize
CoCreateInstance
OLEAUT32.dll SysAllocString
VariantInit
SysFreeString
VariantClear
RPCRT4.dll RpcBindingFree
RpcBindingFromStringBindingW
RpcStringBindingComposeW
MesEncodeIncrementalHandleCreate
RpcBindingSetAuthInfoExW
RpcBindingInqAuthClientW
RpcBindingSetOption
RpcImpersonateClient
RpcStringFreeW
RpcRevertToSelf
MesDecodeIncrementalHandleCreate
MesHandleFree
MesIncrementalHandleReset
NdrMesTypeDecode2
NdrMesTypeAlignSize2
NdrMesTypeFree2
NdrMesTypeEncode2
RpcServerUnregisterIfEx
I_RpcBindingInqSecurityContext
RpcServerInqBindings
RpcServerListen
RpcMgmtWaitServerListen
RpcEpRegisterW
RpcMgmtStopServerListening
RpcBindingToStringBindingW
RpcServerRegisterIf2
RpcServerRegisterAuthInfoW
RpcBindingVectorFree
UuidToStringW
RpcServerUseProtseqEpW
RpcEpUnregister
NdrServerCall2
NdrClientCall2
UuidCreate
RpcEpResolveBinding
RpcBindingSetObject
RpcBindingSetAuthInfoW
RpcMgmtEpEltInqDone
RpcMgmtEpEltInqNextW
RpcMgmtEpEltInqBegin
I_RpcGetCurrentCallHandle
SHLWAPI.dll UrlUnescapeW
PathIsDirectoryW
PathFindFileNameW
PathIsRelativeW
PathCombineW
PathCanonicalizeW
SAMLIB.dll SamEnumerateAliasesInDomain
SamQueryInformationUser
SamCloseHandle
SamEnumerateDomainsInSamServer
SamFreeMemory
SamEnumerateUsersInDomain
SamOpenUser
SamLookupDomainInSamServer
SamLookupNamesInDomain
SamLookupIdsInDomain
SamOpenDomain
SamConnect
SamSetInformationUser
SamiChangePasswordUser
SamEnumerateGroupsInDomain
SamGetGroupsForUser
SamGetMembersInGroup
SamGetMembersInAlias
SamRidToSid
SamGetAliasMembership
SamOpenGroup
SamOpenAlias
Secur32.dll FreeContextBuffer
LsaLookupAuthenticationPackage
LsaFreeReturnBuffer
LsaDeregisterLogonProcess
QueryContextAttributesW
InitializeSecurityContextW
AcquireCredentialsHandleW
EnumerateSecurityPackagesW
FreeCredentialsHandle
DeleteSecurityContext
LsaCallAuthenticationPackage
LsaConnectUntrusted
SHELL32.dll CommandLineToArgvW
USER32.dll SetClipboardViewer
DefWindowProcW
GetClipboardSequenceNumber
OpenClipboard
CreateWindowExW
GetClipboardData
RegisterClassExW
TranslateMessage
EnumClipboardFormats
PostMessageW
DispatchMessageW
GetKeyboardLayout
IsCharAlphaNumericW
SendMessageW
UnregisterClassW
DestroyWindow
CloseClipboard
GetMessageW
ChangeClipboardChain
USERENV.dll DestroyEnvironmentBlock
CreateEnvironmentBlock
VERSION.dll VerQueryValueW
GetFileVersionInfoSizeW
GetFileVersionInfoW
HID.DLL HidD_GetFeature
HidD_GetPreparsedData
HidD_GetHidGuid
HidD_GetAttributes
HidD_SetFeature
HidP_GetCaps
HidD_FreePreparsedData
SETUPAPI.dll SetupDiGetDeviceInterfaceDetailW
SetupDiEnumDeviceInterfaces
SetupDiGetClassDevsW
SetupDiDestroyDeviceInfoList
WinSCard.dll SCardReleaseContext
SCardListCardsW
SCardGetCardTypeProviderNameW
SCardListReadersW
SCardFreeMemory
SCardEstablishContext
SCardControl
SCardConnectW
SCardTransmit
SCardDisconnect
SCardGetAttrib
WINSTA.dll WinStationCloseServer
WinStationOpenServerW
WinStationFreeMemory
WinStationConnectW
WinStationQueryInformationW
WinStationEnumerateW
WLDAP32.dll #36
#79
#145
#73
#310
#208
#13
#77
#142
#54
#41
#309
#304
#301
#127
#26
#167
#147
#133
#157
#88
#14
#122
#140
#203
#69
#139
#97
#223
#12
#113
#224
#96
#27
advapi32.dll A_SHAFinal
A_SHAInit
A_SHAUpdate
msasn1.dll ASN1_CreateModule
ASN1_CloseEncoder
ASN1_CreateDecoder
ASN1_FreeEncoded
ASN1_CloseModule
ASN1_CreateEncoder
ASN1_CloseDecoder
ASN1BERDotVal2Eoid
ntdll.dll strtol
_strcmpi
strstr
towupper
_wcstoui64
wcsncmp
wcstol
strchr
strcspn
strncmp
memmove
_wcsnicmp
strtoul
wcsstr
wcschr
wcsrchr
_stricmp
_vscwprintf
_wcsicmp
strrchr
_vsnprintf
log
memcmp
RtlUnicodeStringToAnsiString
RtlFreeAnsiString
RtlDowncaseUnicodeString
RtlFreeUnicodeString
RtlInitUnicodeString
RtlEqualUnicodeString
NtQueryObject
RtlCompressBuffer
RtlGetCompressionWorkSpaceSize
NtQuerySystemInformation
RtlGetCurrentPeb
NtQueryInformationProcess
RtlCreateUserThread
RtlGUIDFromString
RtlStringFromGUID
NtCompareTokens
RtlGetNtVersionNumbers
RtlEqualString
RtlUpcaseUnicodeString
RtlAppendUnicodeStringToString
RtlAnsiStringToUnicodeString
RtlFreeOemString
RtlUpcaseUnicodeStringToOemString
NtQueryDirectoryObject
NtResumeProcess
NtOpenDirectoryObject
RtlAdjustPrivilege
NtSuspendProcess
NtTerminateProcess
NtQuerySystemEnvironmentValueEx
NtSetSystemEnvironmentValueEx
NtEnumerateSystemEnvironmentValuesEx
RtlIpv4AddressToStringW
RtlIpv6AddressToStringW
wcstoul
__chkstk
netapi32.dll I_NetServerAuthenticate2
I_NetServerTrustPasswordsGet
I_NetServerReqChallenge
KERNEL32.dll lstrlenA
GetDateFormatW
SystemTimeToFileTime
ClearCommError
CreateRemoteThread
WaitForSingleObject
CreateProcessW
SetConsoleOutputCP
GetConsoleOutputCP
CreateFileMappingW
UnmapViewOfFile
MapViewOfFile
WriteProcessMemory
VirtualAllocEx
VirtualProtectEx
RtlVirtualUnwind
SetFilePointerEx
GetProcessId
GetComputerNameW
IsWow64Process
VirtualAlloc
SetLastError
ReadProcessMemory
VirtualFreeEx
VirtualQueryEx
VirtualFree
VirtualQuery
GetComputerNameExW
DeviceIoControl
DuplicateHandle
OpenProcess
GetCurrentProcess
ExpandEnvironmentStringsW
FindNextFileW
FindClose
GetCurrentDirectoryW
GetFileSizeEx
FlushFileBuffers
GetFileAttributesW
FindFirstFileW
lstrlenW
GetProcAddress
LoadLibraryW
GetModuleHandleW
FreeLibrary
DeleteFileA
GetTempPathA
GetFileInformationByHandle
FileTimeToLocalFileTime
GetCurrentDirectoryA
GetTempFileNameA
SetFilePointer
CreateFileA
FileTimeToDosDateTime
CreateThread
LocalFree
CloseHandle
LocalAlloc
GetLastError
CreateFileW
ReadFile
TerminateThread
WriteFile
FileTimeToSystemTime
Sleep
VirtualProtect
WideCharToMultiByte
GetTimeFormatW
GetFullPathNameW
GetFullPathNameA
HeapReAlloc
GetFileSize
CreateMutexW
HeapCompact
SetEndOfFile
HeapAlloc
QueryPerformanceCounter
HeapFree
UnlockFile
FlushViewOfFile
LockFile
WaitForSingleObjectEx
OutputDebugStringW
GetTickCount
UnlockFileEx
GetProcessHeap
FormatMessageA
FormatMessageW
GetVersionExW
HeapDestroy
GetSystemTimeAsFileTime
GetFileAttributesA
HeapCreate
HeapValidate
MultiByteToWideChar
GetTempPathW
HeapSize
LockFileEx
GetDiskFreeSpaceW
LoadLibraryA
CreateFileMappingA
GetDiskFreeSpaceA
GetSystemInfo
GetFileAttributesExW
OutputDebugStringA
GetVersionExA
DeleteFileW
GetCurrentProcessId
GetSystemTime
AreFileApisANSI
ExitProcess
ExitThread
RaiseException
SetConsoleCtrlHandler
SetConsoleTitleW
SetFileAttributesW
GlobalSize
SetHandleInformation
CreatePipe
InitializeCriticalSection
LeaveCriticalSection
EnterCriticalSection
DeleteCriticalSection
SetEvent
CreateEventW
GetSystemDirectoryW
SetConsoleCursorPosition
GetTimeZoneInformation
GetStdHandle
FillConsoleOutputCharacterW
GetConsoleScreenBufferInfo
SetCurrentDirectoryW
GetCurrentThread
ProcessIdToSessionId
RtlLookupFunctionEntry
RtlCaptureContext
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentThreadId
PurgeComm
msvcrt.dll calloc
isdigit
_fmode
_commode
__setusermatherr
isspace
mbtowc
__mb_cur_max
isleadbyte
isxdigit
localeconv
_snprintf
__set_app_type
_itoa
wctomb
ferror
iswctype
wcstombs
?terminate@@YAXXZ
__badioinfo
__pioinfo
_read
_lseeki64
_write
_isatty
ungetc
_amsg_exit
_initterm
fclose
_setmode
vwprintf
exit
_cexit
_exit
_XcptFilter
__wgetmainargs
__C_specific_handler
memset
memcpy
_iob
getchar
_wpgmptr
fgetws
realloc
_msize
malloc
_vscprintf
_errno
free
_wcsdup
vfwprintf
fflush
_wfopen
wprintf
_fileno
bcrypt.dll (delay-loaded) BCryptOpenAlgorithmProvider
BCryptDestroyHash
BCryptKeyDerivation
BCryptHashData
BCryptFinishHash
BCryptGenerateSymmetricKey
BCryptCloseAlgorithmProvider
BCryptDestroyKey
BCryptDeriveKeyPBKDF2
BCryptCreateHash
BCryptGetProperty
BCryptEncrypt
BCryptDecrypt
BCryptSetProperty
BCryptImportKeyPair
BCryptExportKey
BCryptFreeBuffer
BCryptEnumRegisteredProviders

Delayed Imports

Attributes 0x1
Name bcrypt.dll
ModuleHandle 0x13f948
DelayImportAddressTable 0x13f830
DelayImportNameTable 0x1340b8
BoundDelayImportTable 0x134430
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x25a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.58742
MD5 af7f63ed38ac1eea9f4f45699b287a7b 🔍
SHA1 522c0952585ee2c23e67587066b08b0e2d3dd5be 🔍
SHA256 bb14aef3a976374d7a2d7032e95e8b7d339402547705c07768f5e523aa227dbc 🔍
SHA3 a68ddf26a5d32eedb129dab32b61508dcc34a8ed6deebb6cb5b44ba5127a683d 🔍

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.68627
MD5 4c8a1f13f0a76817ab4af037499713df 🔍
SHA1 2718541330281136297f4bc485008207083850d6 🔍
SHA256 4a5ff11cfc675db544c54be18d5f1c2a29ef4c9e02b931792b48263f773fe477 🔍
SHA3 33eee9e3eb0435d89035cdbec166c38fb5b85ef16070807dc41a6bae7044297e 🔍

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 6.69825
MD5 893e8ba8f9644997d70dcc5392c9fa68 🔍
SHA1 18b71655fa7f4e0dd880c6c05dca48984d792d37 🔍
SHA256 268a8b9081b620341e20e68861b379f8d9a72d2e44a5f9910ce6c67c5fcfcbc5 🔍
SHA3 50cf487748a5dc0a1e99f74c45a77af100a44c584b1eed23775946a22c09dd70 🔍

100

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x30
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.45849
Detected Filetype Icon file
MD5 1ec6a7b3300970378c29695a6cc13d36 🔍
SHA1 99ce74251d19d800608e30bed6e0d793931da56e 🔍
SHA256 77a1efb6136f52dd2372987b13bf486aa75baeacb93bad009aa3e284c57b8694 🔍
SHA3 7a94ba315b3ab461cec9dad3048599d32b0e597047f9655159bd6dfdc694e4a3 🔍

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x3ac
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.46245
MD5 ecab32b94787ec58ba3ce9e450099e8f 🔍
SHA1 30cfdc1a8d611ba805b5871a3ba61880e068f366 🔍
SHA256 1accdb2bb6bbf2e19900e4a566d6cc1749f6e8b08ee77535184836e452bc3c1f 🔍
SHA3 3812489ee30888ccac195fcfd7028ca14d9bfa7ec48e039da439ec712e776da6 🔍

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 2.2.0.0
ProductVersion 2.2.0.0
FileFlags VS_FF_PRERELEASE
VS_FF_PRIVATEBUILD
VS_FF_SPECIALBUILD
FileOs VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
FileType VFT_APP
Language English - United States
ProductName mimikatz
ProductVersion (#2) 2.2.0.0
CompanyName gentilkiwi (Benjamin DELPY)
FileDescription mimikatz for Windows
FileVersion (#2) 2.2.0.0
InternalName mimikatz
LegalCopyright Copyright (c) 2007 - 2021 gentilkiwi (Benjamin DELPY)
OriginalFilename mimikatz.exe
PrivateBuild Build with love for POC only
SpecialBuild :)
Resource LangID English - United States

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0x4eb91164
Unmarked objects 0
ASM objects (VS2008 SP1 build 30729) 1
C objects (VS2008 SP1 build 30729) 62
C++ objects (VS2008 SP1 build 30729) 16
Imports (VS2008 SP1 build 30729) 2
Imports (VS2012 UPD4 build 61030) 6
Imports (VS2012 UPD2 build 60315) 2
C objects (40310) 3
C++ objects (VS2008 build 21022) 2
Imports (40310) 51
Total imports 670
126 (VS2012 build 50727 / VS2005 build 50727) 1
137 (VS2008 SP1 build 30729) 114
Linker (VS2008 SP1 build 30729) 1
Resource objects (VS2008 SP1 build 30729) 1

Errors

Leave a comment

No comments yet.