Mimikatz veya Hacktool.Mimikatz, bir Windows işletim sisteminde belirli yetenekleri bozarak bir saldırgana bir makineye erişim sağlayabilmesine rağmen, yüksek riskli araç olarak sınıflandırılmaz. Bir bilgisayar Mimikatz tarafından saldırıya uğradığında, denetleyicileri rastgele işlemlere DLL'leri enjekte edebilir, güvenlik sertifikalarını dışa aktarabilir, Windows'tan düz metin parolaları kurtarabilir, belirli oturum açma ve güvenlik hizmetlerini devre dışı bırakabilir, bazı ayrıcalıkları silebilir ve birkaç Grup İlkesi ayarından kaçınabilir.
Mimikatz'ın bilgisayarınıza bulaşmış olabileceğinden şüpheleniyorsanız, bunu kontrol etmenin kolay bir yolu var: Özel bir tarayıcı kullanın çünkü Mimikatz'ı algılayabilir ve kaldırabilir. Ancak, bulaşmadıysanız ve virüs bulaşmasını önlemek için önlem almak istiyorsanız, bilinmeyen göndericiden gelen e-postaların kaynağını ve güvenilirliğini kontrol etmek, dosya paylaşırken dikkatli olun, paylaşmayın gibi uygulayabileceğiniz bazı stratejiler vardır. Anlık mesajlaşma programları hakkında, daha ciddi tehditler de dahil olmak üzere sayısız sorunu önleyebilecek çok fazla bilgi.
İçindekiler
Analiz raporu
Genel bilgi
Family Name:
Trojan.Mimikatz
Signature status:
No Signature
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.
This section lists file attributes found within family samples. These attributes are extracted
from the files’ Windows PE (Portable Executable) specification and various system flags. Portable
Executable Attributes give malware researchers insight into a file’s functionality, executable details,
platform and runtime environment.
File doesn't have "Rich" header
File doesn't have debug information
File doesn't have exports table
File doesn't have resources
File doesn't have security information
File has exports table
File has TLS information
File is .NET application
File is 32-bit executable
File is 64-bit executable
Show More
File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
File is either console or GUI application
File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
File is Native application (NOT .NET application)
File is not packed
IMAGE_FILE_DLL is not set inside PE header (Executable)
IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version
information data structure for samples within this family. To mislead users, malware actors often add
fake version information mimicking legitimate software.
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and
comparison with other samples. Blocks can be used to generate malware detection rules and to group file
samples into families based on shared source code, functionality and other distinguishing attributes and
characteristics. This section lists a summary of this block data, as well as its classification by
EnigmaSoft. A visual representation of the block data is also displayed, where available.
This section lists other families that share similarities with this family, based on
EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same
packing and encryption techniques but uniquely extend functionality. Similar families may also share
source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and
network characteristics. Researchers leverage these similarities to rapidly and effectively triage file
samples and extend malware detection rules.
MSIL.SharpKatz.B
MSIL.SharpKatz.E
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API
usage analysis is a valuable tool that can help identify malicious activity, such as keylogging,
security privilege escalation, data encryption, data exfiltration, interference with antivirus software,
and network request manipulation.
Category
API
Syscall Use
ntdll.dll!NtAdjustPrivilegesToken
ntdll.dll!NtAlertThreadByThreadId
ntdll.dll!NtAlpcConnectPortEx
ntdll.dll!NtAlpcQueryInformation
ntdll.dll!NtAlpcSendWaitReceivePort
ntdll.dll!NtApphelpCacheControl
ntdll.dll!NtAssociateWaitCompletionPacket
ntdll.dll!NtCancelTimer2
ntdll.dll!NtCancelWaitCompletionPacket
ntdll.dll!NtClearEvent
Show More
ntdll.dll!NtClose
ntdll.dll!NtCompareSigningLevels
ntdll.dll!NtCreateEvent
ntdll.dll!NtCreateFile
ntdll.dll!NtCreateIoCompletion
ntdll.dll!NtCreateMutant
ntdll.dll!NtCreatePrivateNamespace
ntdll.dll!NtCreateSection
ntdll.dll!NtCreateSemaphore
ntdll.dll!NtCreateThreadEx
ntdll.dll!NtCreateTimer2
ntdll.dll!NtCreateWaitCompletionPacket
ntdll.dll!NtCreateWorkerFactory
ntdll.dll!NtDeviceIoControlFile
ntdll.dll!NtDuplicateObject
ntdll.dll!NtEnumerateKey
ntdll.dll!NtEnumerateValueKey
ntdll.dll!NtFreeVirtualMemory
ntdll.dll!NtGetCachedSigningLevel
ntdll.dll!NtMapViewOfSection
ntdll.dll!NtNotifyChangeKey
ntdll.dll!NtOpenDirectoryObject
ntdll.dll!NtOpenEvent
ntdll.dll!NtOpenFile
ntdll.dll!NtOpenKey
ntdll.dll!NtOpenKeyEx
ntdll.dll!NtOpenProcess
ntdll.dll!NtOpenProcessToken
ntdll.dll!NtOpenSection
ntdll.dll!NtOpenThread
ntdll.dll!NtOpenThreadToken
ntdll.dll!NtProtectVirtualMemory
ntdll.dll!NtQueryAttributesFile
ntdll.dll!NtQueryDebugFilterState
ntdll.dll!NtQueryDefaultLocale
ntdll.dll!NtQueryDirectoryFileEx
ntdll.dll!NtQueryFullAttributesFile
ntdll.dll!NtQueryInformationFile
ntdll.dll!NtQueryInformationJobObject
ntdll.dll!NtQueryInformationProcess
ntdll.dll!NtQueryInformationThread
ntdll.dll!NtQueryInformationToken
ntdll.dll!NtQueryKey
ntdll.dll!NtQueryLicenseValue
ntdll.dll!NtQueryPerformanceCounter
ntdll.dll!NtQuerySecurityAttributesToken
ntdll.dll!NtQuerySecurityObject
ntdll.dll!NtQuerySystemInformation
ntdll.dll!NtQuerySystemInformationEx
ntdll.dll!NtQueryValueKey
ntdll.dll!NtQueryVirtualMemory
ntdll.dll!NtQueryVolumeInformationFile
ntdll.dll!NtQueryWnfStateData
ntdll.dll!NtReadFile
ntdll.dll!NtReadRequestData
ntdll.dll!NtReleaseMutant
ntdll.dll!NtReleaseWorkerFactoryWorker
ntdll.dll!NtRemoveIoCompletionEx
ntdll.dll!NtResumeThread
ntdll.dll!NtSetEvent
ntdll.dll!NtSetInformationFile
ntdll.dll!NtSetInformationKey
ntdll.dll!NtSetInformationProcess
ntdll.dll!NtSetInformationThread
ntdll.dll!NtSetInformationVirtualMemory
ntdll.dll!NtSetInformationWorkerFactory
ntdll.dll!NtSetIoCompletion
ntdll.dll!NtSetTimer2
ntdll.dll!NtSubscribeWnfStateChange
ntdll.dll!NtTestAlert
ntdll.dll!NtTraceControl
ntdll.dll!NtUnmapViewOfSection
ntdll.dll!NtUnmapViewOfSectionEx
ntdll.dll!NtUnsubscribeWnfStateChange
ntdll.dll!NtWaitForAlertByThreadId
ntdll.dll!NtWaitForSingleObject
ntdll.dll!NtWaitForWorkViaWorkerFactory
ntdll.dll!NtWorkerFactoryWorkerReady
ntdll.dll!NtWriteFile
ntdll.dll!NtWriteVirtualMemory
UNKNOWN
win32u.dll!NtUserGetKeyboardLayout
win32u.dll!NtUserGetThreadState
Process Shell Execute
CreateProcess
Anti Debug
NtQuerySystemInformation
User Data Access
GetComputerNameEx
GetUserDefaultLocaleName
GetUserObjectInformation
Other Suspicious
AdjustTokenPrivileges
Process Manipulation Evasion
ReadProcessMemory
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows
Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security
privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data,
and hide malicious activity.
Lütfen bu yorum sistemini destek veya faturalandırma soruları için KULLANMAYIN.
SpyHunter teknik destek talepleri için lütfen SpyHunter'ınız üzerinden bir müşteri destek bileti açarak doğrudan teknik destek ekibimize başvurun. Faturalandırma sorunları için lütfen " Faturalama Soruları veya Sorunları? " Sayfamızı ziyaret edin. Genel sorularınız için (şikayetler, yasal, basın, pazarlama, telif hakkı) " Sorular ve Geribildirim " sayfamızı ziyaret edin.
Enigmasoftware.com uses cookies to provide you with a better browsing experience and analyze how users navigate and utilize the Site. By using this Site or clicking on "OK", you consent to the use of cookies. Daha fazla bilgi edinin .