Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Aug. 4, 2024, 1:23 p.m. | Aug. 4, 2024, 1:32 p.m. |
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,DhcpNewPktHook
2556-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,DhcpNewPktHook
2940
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,DhcpServerCalloutEntry
2640-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,DhcpServerCalloutEntry
800
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,DllCanUnloadNow
2732-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,DllCanUnloadNow
3004
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,DllGetClassObject
2820-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,DllGetClassObject
192
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,DnsPluginCleanup
2916-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,DnsPluginCleanup
2264
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,DnsPluginInitialize
1120-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,DnsPluginInitialize
2536
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,DnsPluginQuery
2192-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,DnsPluginQuery
2724
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,ExtensionApiVersion
2504-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,ExtensionApiVersion
2764
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,InitializeChangeNotify
2832-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,InitializeChangeNotify
2320
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,Msv1_0SubAuthenticationFilter
2076-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,Msv1_0SubAuthenticationFilter
2524
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,Msv1_0SubAuthenticationRoutine
2216-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,Msv1_0SubAuthenticationRoutine
3008
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,NPGetCaps
2872-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,NPGetCaps
2112
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,NPLogonNotify
1336-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,NPLogonNotify
2808
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,PasswordChangeNotify
2752-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,PasswordChangeNotify
2824
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,SpLsaModeInitialize
2072-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,SpLsaModeInitialize
2372
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,WinDbgExtensionDllInit
2628-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,WinDbgExtensionDllInit
2660
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,coffee
744-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,coffee
3372
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,mimikatz
3232-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,mimikatz
3400
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,startW
3328-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,startW
3628
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\mimilib.dll,
3540
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
Bkav | W64.AIDetectMalware |
Lionic | Trojan.Win32.Mimikatz.i!c |
Elastic | malicious (high confidence) |
Cynet | Malicious (score: 100) |
Skyhigh | HTool-Mimikatz |
ALYac | Gen:Variant.Mimikatz.10 |
Cylance | Unsafe |
VIPRE | Gen:Variant.Mimikatz.10 |
Sangfor | HackTool.Win64.Mimikatz.uwccg |
K7AntiVirus | Hacktool ( 0043c1591 ) |
BitDefender | Gen:Variant.Mimikatz.10 |
K7GW | Hacktool ( 0043c1591 ) |
Arcabit | Trojan.Mimikatz.10 |
Symantec | ML.Attribute.HighConfidence |
ESET-NOD32 | a variant of Win64/Riskware.Mimikatz.U |
McAfee | HTool-Mimikatz |
Avast | Win64:Malware-gen |
ClamAV | Win.Tool.Mimikatz-10029462-0 |
Kaspersky | HEUR:Trojan-PSW.Win64.Mimikatz.gen |
Alibaba | Trojan:Win32/Mimikatz.4b1 |
MicroWorld-eScan | Gen:Variant.Mimikatz.10 |
Rising | HackTool.Mimikatz!1.B3A7 (CLASSIC) |
Emsisoft | Gen:Variant.Mimikatz.10 (B) |
Zillya | Tool.Mimikatz.Win64.2822 |
TrendMicro | Trojan.Win64.BAZARLOADER.SMYXBIMZ |
McAfeeD | ti!7FDB709E4E16 |
FireEye | Generic.mg.ddbd4a6269c999e0 |
Sophos | ATK/Apteryx-Gen |
Ikarus | HackTool.Mimikatz |
Webroot | W32.Hacktool.Gen |
Detected | |
MAX | malware (ai score=84) |
Antiy-AVL | RiskWare/Win64.Mimikatz |
Kingsoft | Win64.Trojan-PSW.Mimikatz.gen |
Gridinsoft | Virtool.Win64.Mimikatz.dd!n |
Microsoft | HackTool:Win64/Mikatz!dha |
ZoneAlarm | HEUR:Trojan-PSW.Win64.Mimikatz.gen |
GData | Gen:Variant.Mimikatz.10 |
AhnLab-V3 | Trojan/Win.Mimikatz.R453144 |
DeepInstinct | MALICIOUS |
Malwarebytes | HackTool.Mimikatz |
Panda | Trj/GdSda.A |
TrendMicro-HouseCall | HKTL_MIMIKATZ64 |
Tencent | Trojan.Win64.Mimikatz.a |
SentinelOne | Static AI - Malicious PE |
Fortinet | Riskware/Mimikatz |
AVG | Win64:Malware-gen |
Paloalto | generic.ml |
CrowdStrike | win/malicious_confidence_90% (W) |
alibabacloud | HackTool:Win/Mimikatz.k |