MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b71fc93811b74b31ee4d6d5ab13ed9857947845fdd3366a24007964f00c79212. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mimikatz


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b71fc93811b74b31ee4d6d5ab13ed9857947845fdd3366a24007964f00c79212
SHA3-384 hash: f95abdc66e3df545ff7975fe88a3aab28658ee710b04af8ac786bbe668041965ded72e9f8e035bbe7ba416ee2d94b793
SHA1 hash: e7420c93f88a351f7a608dae10fac0fd92d96ab4
MD5 hash: 168ae4e609eb9f0d59ced36b25ece4c8
humanhash: maryland-five-south-tango
File name:BetterSafetyKatz.zip
Download: download sample
Signature Mimikatz
File size:1'153'544 bytes
First seen:2020-11-18 21:33:09 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:aixlJHXNN08ufhGFg3BUG0KqLQAtZZ1ZRY+j4MpDlNBC7xNw9TQoqE5lXfY0o9:aUJHLFg3e7QAV6KrpX229TPqE/fY9
TLSH C53533F80B34B22655485CFF2329F48BA5B0BA59D878F9A34D3386D54D4F5B0A20F2B4
Reporter JoulK
Tags:mimikatz zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
151
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Hacktool.Mimikatz
Status:
Malicious
First seen:
2020-05-20 07:06:35 UTC
AV detection:
37 of 47 (78.72%)
Threat level:
  1/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mimikatz

zip b71fc93811b74b31ee4d6d5ab13ed9857947845fdd3366a24007964f00c79212

(this sample)

  
Delivery method
Distributed via web download

Comments