tmp00000c01

mimidrv (mimikatz)

Benjamin Delpy

The file tmp00000c01, “mimidrv for Windows (mimikatz)” by Benjamin Delpy has been detected as adware by 13 anti-malware scanners.
Publisher:
gentilkiwi (Benjamin DELPY)  (signed by Benjamin Delpy)

Product:
mimidrv (mimikatz)

Description:
mimidrv for Windows (mimikatz)

Version:
2.0.0.0

MD5:
cdbe91d9d92549570a22856836427371

SHA-1:
251c009aafcdbe1d687a291470929d3fcc22f1d4

SHA-256:
d7f4b72b8f68b2e00feb3d5e07c800da1da3c3b3e058fee208a564b7a5501236

Scanner detections:
13 / 68

Status:
Adware

Analysis date:
4/25/2024 10:56:58 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
HackTool/Win32.Mimikatz
2015.07.17

avast!
Win32:Mimikatz-A [Tool]
2014.9-150722

AVG
HackTool
2016.0.3040

Comodo Security
Application.Win32.HackTool.Mimikatz.DA
22778

ESET NOD32
Win32/HackTool.Mimikatz.H potentially unsafe (variant)
9.11950

F-Prot
W32/Mimikatz.A.gen
v6.4.7.1.166

F-Secure
Hack-Tool:W32/Mimikatz.G
11.2015-22-07_4

Kaspersky
HackTool.Win32.Mimikatz
14.0.0.1696

McAfee
HTool-MimiKatz
5600.6696

Microsoft Security Essentials
HackTool:Win64/Mikatz
1.1.11804.0

NANO AntiVirus
Trojan.Win32.Mimikatz.drhvuv
0.30.24.2487

Reason Heuristics
PUP.BenjaminDelpy (M)
15.7.22.18

Zillya! Antivirus
Tool.Mimikatz.Win32.90
2.0.0.2291

File size:
29.4 KB (30,080 bytes)

Product version:
2.0.0.0

Copyright:
Copyright (c) 2007 - 2014 gentilkiwi (Benjamin DELPY)

Original file name:
mimidrv.sys

Language:
English (United States)

Common path:
C:\windows\temp\tmp00005620\tmp00000c01

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
6/28/2011 10:46:16 AM

Valid to:
6/28/2014 10:46:16 AM

Subject:
CN=Benjamin Delpy, C=FR

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112169417A1C3EF46A301F99385F50680FA0

File PE Metadata
Compilation timestamp:
7/16/2015 12:21:04 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
384:uWKVt4i+QPvZfc/HI2fjAWyzFHIfgGeFXfSaD+dlpKVnVYEH9dUb+MCgWsG8lG:uWqPvSryxkgGkXfSaD+dlpWVHkiMCgT0

Entry address:
0x703E

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 88, A5, FF, FF, CC, CC, A4, 70, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 62, 74, 00, 00, 18, 40, 00, 00, 8C, 70, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, EC, 74, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, BC, 74, 00, 00, A4, 74, 00, 00, 88, 74, 00, 00, 70, 74, 00, 00, D6, 74, 00, 00, 00, 00, 00, 00, B8, 71, 00, 00, C6, 71, 00, 00, DE, 71, 00, 00, F0, 71, 00, 00, 0A, 72, 00, 00, 22, 72, 00, 00, 40, 72...
 
[+]

Entropy:
6.0342

Code size:
12 KB (12,288 bytes)

Remove tmp00000c01 - Powered by Reason Core Security