Mimikatz 또는 Hacktool. Mimikatz는 Windows 운영 체제에서 결정된 기능을 손상시켜 공격자에게 시스템에 대한 액세스 권한을 부여 할 수 있지만 고위험 도구로 분류되지 않습니다. 컴퓨터가 Mimikatz의 공격을 받으면 컨트롤러는 DLL을 임의의 프로세스에 주입하고, 보안 인증서를 내보내고, Windows에서 일반 텍스트 암호를 복구하고, 특정 로그인 및 보안 서비스를 비활성화하고, 일부 권한을 지우고, 몇 가지 그룹 정책 설정을 회피 할 수 있습니다.
Mimikatz가 컴퓨터를 감염시킬 수 있다고 의심되는 경우 쉽게 확인할 수있는 방법이 있습니다. 전용 스캐너를 사용하면 Mimikatz를 감지하고 제거 할 수 있습니다. 그러나 감염되지 않았고 감염을 피하기위한 조치를 취하려는 경우 알 수없는 발신자가 보낸 이메일의 출처 및 신뢰성 확인, 파일 공유시주의, 공유 금지 등 구현할 수있는 몇 가지 전략이 있습니다. 더 심각한 위협에 감염되는 것을 포함하여 수많은 문제를 예방할 수있는 인스턴트 메신저에 대한 많은 정보.
목차
분석 보고서
일반 정보
Family Name:
Trojan.Mimikatz
Signature status:
No Signature
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.
This section lists file attributes found within family samples. These attributes are extracted
from the files’ Windows PE (Portable Executable) specification and various system flags. Portable
Executable Attributes give malware researchers insight into a file’s functionality, executable details,
platform and runtime environment.
File doesn't have "Rich" header
File doesn't have debug information
File doesn't have resources
File doesn't have security information
File has exports table
File is 32-bit executable
File is either console or GUI application
File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
File is Native application (NOT .NET application)
File is not packed
Show More
IMAGE_FILE_DLL is not set inside PE header (Executable)
IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Traits
CryptUnprotectData
dll
HighEntropy
ntdll
VirtualQueryEx
WriteProcessMemory
x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and
comparison with other samples. Blocks can be used to generate malware detection rules and to group file
samples into families based on shared source code, functionality and other distinguishing attributes and
characteristics. This section lists a summary of this block data, as well as its classification by
EnigmaSoft. A visual representation of the block data is also displayed, where available.
This section lists Windows API calls that are used by the samples in this family. Windows API
usage analysis is a valuable tool that can help identify malicious activity, such as keylogging,
security privilege escalation, data encryption, data exfiltration, interference with antivirus software,
and network request manipulation.
Category
API
Syscall Use
ntdll.dll!NtAlpcSendWaitReceivePort
ntdll.dll!NtClose
ntdll.dll!NtCreateFile
ntdll.dll!NtCreateSection
ntdll.dll!NtFreeVirtualMemory
ntdll.dll!NtMapViewOfSection
ntdll.dll!NtOpenFile
ntdll.dll!NtOpenKey
ntdll.dll!NtOpenProcessToken
ntdll.dll!NtProtectVirtualMemory
Show More
ntdll.dll!NtQueryAttributesFile
ntdll.dll!NtQueryDebugFilterState
ntdll.dll!NtQueryInformationProcess
ntdll.dll!NtQueryInformationThread
ntdll.dll!NtQueryInformationToken
ntdll.dll!NtQuerySystemInformationEx
ntdll.dll!NtQueryValueKey
ntdll.dll!NtQueryVirtualMemory
ntdll.dll!NtQueryVolumeInformationFile
ntdll.dll!NtReadFile
ntdll.dll!NtSetEvent
ntdll.dll!NtSetInformationFile
ntdll.dll!NtSetInformationProcess
ntdll.dll!NtTestAlert
ntdll.dll!NtUnmapViewOfSection
ntdll.dll!NtWaitForSingleObject
ntdll.dll!NtWriteFile
ntdll.dll!NtWriteVirtualMemory
win32u.dll!NtUserGetKeyboardLayout
win32u.dll!NtUserGetThreadState
Process Shell Execute
CreateProcess
Anti Debug
NtQuerySystemInformation
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows
Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security
privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data,
and hide malicious activity.
지원 또는 청구 관련 질문에이 메모 시스템을 사용하지 마십시오.
SpyHunter 기술 지원 요청은 SpyHunter를 통해 고객 지원 티켓 을 개설하여 기술 지원 팀에 직접 문의하십시오. 청구 관련 문제는 "청구 관련 질문 또는 문제?"페이지를 참조하십시오. 일반적인 문의 (불만, 법률, 언론, 마케팅, 저작권)는 "문의 및 피드백" 페이지를 참조하십시오.
Enigmasoftware.com uses cookies to provide you with a better browsing experience and analyze how users navigate and utilize the Site. By using this Site or clicking on "OK", you consent to the use of cookies. 자세히 알아보기