| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2016-Aug-09 19:44:19 |
| Detected languages |
English - United States
|
| ProductName | mimikatz |
| ProductVersion | 2.1.0.0 |
| CompanyName | gentilkiwi (Benjamin DELPY) |
| FileDescription | mimikatz for Windows |
| FileVersion | 2.1.0.0 |
| InternalName | mimikatz |
| LegalCopyright | Copyright (c) 2007 - 2016 gentilkiwi (Benjamin DELPY) |
| OriginalFilename | mimikatz.exe |
| PrivateBuild | Build with love for POC only |
| SpecialBuild | kiwi flavor ! |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
Contains strings from Mimikatz:
|
| Info | Libraries used to perform cryptographic operations: | Microsoft's Cryptography API |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2016-Aug-09 19:44:19 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 10.0 |
| SizeOfCode | 0x79e00 |
| SizeOfInitializedData | 0x43400 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000685B4 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 5.2 |
| ImageVersion | 0.0 |
| SubsystemVersion | 5.2 |
| Win32VersionValue | 0 |
| SizeOfImage | 0xc4000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0xcc6d5 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| ADVAPI32.dll |
CryptSetHashParam
CryptGetHashParam CryptExportKey CryptAcquireContextW CryptSetKeyParam CryptGetKeyParam CryptReleaseContext CryptDuplicateKey CryptAcquireContextA CryptGetProvParam CryptImportKey SystemFunction007 CryptEncrypt CryptCreateHash CryptGenKey CryptDestroyKey CryptDecrypt CryptDestroyHash CryptHashData CopySid GetLengthSid LsaQueryInformationPolicy LsaOpenPolicy LsaClose CreateWellKnownSid CreateProcessWithLogonW CreateProcessAsUserW RegQueryValueExW RegQueryInfoKeyW RegEnumValueW RegOpenKeyExW RegEnumKeyExW RegCloseKey RegSetValueExW SystemFunction032 CloseServiceHandle DeleteService OpenSCManagerW OpenServiceW StartServiceW QueryServiceStatusEx ControlService IsTextUnicode CryptGenRandom ConvertSidToStringSidW OpenProcessToken GetTokenInformation LookupAccountNameW LookupAccountSidW ConvertStringSidToSidW LsaFreeMemory CryptEnumProvidersW CryptEnumProviderTypesW SystemFunction006 CryptGetUserKey OpenEventLogW GetNumberOfEventLogRecords ClearEventLogW CreateServiceW SetServiceObjectSecurity BuildSecurityDescriptorW QueryServiceObjectSecurity AllocateAndInitializeSid FreeSid GetSidSubAuthority SystemFunction001 GetSidSubAuthorityCount SystemFunction005 LsaQueryTrustedDomainInfoByName SystemFunction025 LsaOpenSecret LsaQuerySecret SystemFunction013 LsaRetrievePrivateData LsaEnumerateTrustedDomainsEx LookupPrivilegeValueW IsValidSid OpenThreadToken SetThreadToken DuplicateTokenEx CheckTokenMembership CredFree CredEnumerateW |
|---|---|
| CRYPT32.dll |
CryptUnprotectData
CryptBinaryToStringW CryptStringToBinaryW CryptProtectData CryptAcquireCertificatePrivateKey CertGetNameStringW CertAddEncodedCertificateToStore CertOpenStore CertFreeCertificateContext CertAddCertificateContextToStore CertCloseStore CertGetCertificateContextProperty CertEnumCertificatesInStore CertEnumSystemStore CertSetCertificateContextProperty PFXExportCertStoreEx |
| cryptdll.dll |
CDLocateCSystem
CDGenerateRandomBits MD5Final MD5Update CDLocateCheckSum MD5Init |
| NETAPI32.dll |
DsGetDcNameW
NetApiBufferFree |
| ole32.dll |
CoInitializeEx
CoUninitialize CoCreateInstance |
| OLEAUT32.dll |
#2
#8 #6 |
| RPCRT4.dll |
RpcBindingSetOption
RpcBindingFromStringBindingW RpcStringBindingComposeW MesEncodeIncrementalHandleCreate RpcBindingSetAuthInfoExW RpcBindingFree RpcStringFreeW MesDecodeIncrementalHandleCreate MesHandleFree MesIncrementalHandleReset NdrMesTypeDecode2 NdrMesTypeAlignSize2 NdrMesTypeFree2 NdrMesTypeEncode2 I_RpcBindingInqSecurityContext NdrClientCall2 |
| SHLWAPI.dll |
PathFindFileNameW
PathIsRelativeW PathCanonicalizeW PathCombineW PathIsDirectoryW |
| SAMLIB.dll |
SamFreeMemory
SamOpenAlias SamOpenGroup SamGetAliasMembership SamEnumerateAliasesInDomain SamGetMembersInAlias SamQueryInformationUser SamCloseHandle SamEnumerateUsersInDomain SamOpenUser SamLookupNamesInDomain SamLookupIdsInDomain SamOpenDomain SamConnect SamEnumerateGroupsInDomain SamEnumerateDomainsInSamServer SamGetGroupsForUser SamGetMembersInGroup SamRidToSid SamLookupDomainInSamServer |
| Secur32.dll |
LsaLookupAuthenticationPackage
LsaFreeReturnBuffer LsaConnectUntrusted LsaCallAuthenticationPackage LsaDeregisterLogonProcess QueryContextAttributesW FreeContextBuffer |
| SHELL32.dll |
CommandLineToArgvW
|
| USER32.dll |
IsCharAlphaNumericW
GetKeyboardLayout |
| HID.DLL |
HidD_GetHidGuid
HidD_GetAttributes HidD_FreePreparsedData HidP_GetCaps HidD_GetPreparsedData |
| SETUPAPI.dll |
SetupDiDestroyDeviceInfoList
SetupDiGetClassDevsW SetupDiEnumDeviceInterfaces SetupDiGetDeviceInterfaceDetailW |
| WLDAP32.dll |
#145
#310 #54 #309 #304 #301 #73 #127 #26 #157 #79 #36 #208 #167 #147 #13 #27 #77 #142 #133 #41 |
| ntdll.dll |
RtlGetCurrentPeb
NtQueryInformationProcess RtlCreateUserThread RtlGUIDFromString RtlStringFromGUID RtlGetNtVersionNumbers RtlUpcaseUnicodeString RtlAppendUnicodeStringToString NtQuerySystemInformation NtResumeProcess RtlAdjustPrivilege NtSuspendProcess NtTerminateProcess NtQuerySystemEnvironmentValueEx NtSetSystemEnvironmentValueEx NtEnumerateSystemEnvironmentValuesEx RtlEqualString RtlGetCompressionWorkSpaceSize RtlCompressBuffer NtQueryObject RtlEqualUnicodeString RtlInitUnicodeString RtlFreeUnicodeString RtlDowncaseUnicodeString RtlFreeAnsiString RtlAnsiStringToUnicodeString RtlUnicodeStringToAnsiString |
| netapi32.dll |
I_NetServerAuthenticate2
I_NetServerReqChallenge I_NetServerTrustPasswordsGet |
| KERNEL32.dll |
GetEnvironmentStringsW
FreeEnvironmentStringsW LCMapStringW GetStringTypeW GetTimeZoneInformation GetModuleFileNameW SetStdHandle GetConsoleMode GetConsoleCP GetStartupInfoW GetFileType InitializeCriticalSectionAndSpinCount SetHandleCount RtlUnwindEx FlsAlloc GetCurrentThreadId FlsFree FlsSetValue FlsGetValue IsValidCodePage GetOEMCP GetACP GetCPInfo GetVersion HeapSetInformation TerminateProcess RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind IsDebuggerPresent SetUnhandledExceptionFilter GetCommandLineW ExitProcess DecodePointer EncodePointer GetTimeFormatA GetDateFormatA GetCurrentThread SetCurrentDirectoryW GetConsoleScreenBufferInfo FillConsoleOutputCharacterW GetStdHandle SetConsoleCursorPosition GetModuleHandleW GetProcAddress LoadLibraryW FreeLibrary SetConsoleTitleW SetConsoleCtrlHandler DeleteFileA AreFileApisANSI GetSystemTime GetTempPathA GetCurrentProcessId DeleteFileW GetVersionExA OutputDebugStringA DeleteCriticalSection GetFileAttributesExW GetSystemInfo GetDiskFreeSpaceA CreateFileMappingA GetDiskFreeSpaceW EnterCriticalSection LockFileEx HeapSize WriteConsoleW CompareStringW UnhandledExceptionFilter SetEnvironmentVariableA GetTempPathW MultiByteToWideChar HeapValidate HeapCreate GetFileAttributesA LeaveCriticalSection HeapDestroy GetVersionExW FormatMessageW InitializeCriticalSection FormatMessageA GetSystemTimeAsFileTime GetProcessHeap UnlockFileEx GetTickCount OutputDebugStringW WaitForSingleObjectEx LockFile FlushViewOfFile UnlockFile HeapFree QueryPerformanceCounter SystemTimeToFileTime HeapAlloc SetEndOfFile TryEnterCriticalSection HeapCompact CreateMutexW GetFileSize CreateFileA HeapReAlloc GetFullPathNameA GetFullPathNameW FileTimeToLocalFileTime GetTimeFormatW WideCharToMultiByte GetDateFormatW CreateRemoteThread WaitForSingleObject SetLastError CreateProcessW SetConsoleOutputCP GetConsoleOutputCP CreateFileMappingW UnmapViewOfFile MapViewOfFile WriteProcessMemory VirtualProtect VirtualAllocEx VirtualProtectEx VirtualAlloc ReadProcessMemory VirtualFreeEx VirtualQueryEx VirtualFree VirtualQuery SetFilePointer DeviceIoControl DuplicateHandle FileTimeToSystemTime WriteFile TerminateThread Sleep ReadFile CreateFileW GetLastError LocalAlloc CloseHandle LocalFree CreateThread FindFirstFileW GetFileAttributesW FlushFileBuffers GetFileSizeEx GetCurrentDirectoryW FindClose FindNextFileW ExpandEnvironmentStringsW GetCurrentProcess OpenProcess |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.1.0.0 |
| ProductVersion | 2.1.0.0 |
| FileFlags |
VS_FF_PRERELEASE
VS_FF_PRIVATEBUILD
VS_FF_SPECIALBUILD
|
| FileOs |
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
|
| FileType |
VFT_APP
|
| Language | English - United States |
| ProductName | mimikatz |
| ProductVersion (#2) | 2.1.0.0 |
| CompanyName | gentilkiwi (Benjamin DELPY) |
| FileDescription | mimikatz for Windows |
| FileVersion (#2) | 2.1.0.0 |
| InternalName | mimikatz |
| LegalCopyright | Copyright (c) 2007 - 2016 gentilkiwi (Benjamin DELPY) |
| OriginalFilename | mimikatz.exe |
| PrivateBuild | Build with love for POC only |
| SpecialBuild | kiwi flavor ! |
| Resource LangID | English - United States |
|---|
| XOR Key | 0x743305f |
|---|---|
| Unmarked objects | 0 |
| C++ objects (VS2010 SP1 build 40219) | 44 |
| C objects (VS2010 SP1 build 40219) | 137 |
| ASM objects (VS2010 SP1 build 40219) | 9 |
| Imports (VS2012 UPD4 build 61030) | 4 |
| 135 (VS2008 SP1 build 30729) | 2 |
| Imports (40310) | 6 |
| Imports (VS2008 SP1 build 30729) | 27 |
| Total imports | 382 |
| 174 (VS2010 SP1 build 40219) | 74 |
| Resource objects (VS2010 SP1 build 40219) | 1 |
| Linker (VS2010 SP1 build 40219) | 1 |