Trojan

Trojan-PSW.Win64.Mimikatz (file analysis)

Malware Removal

The Trojan-PSW.Win64.Mimikatz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win64.Mimikatz virus can do?

  • Unconventionial language used in binary resources: Russian
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-PSW.Win64.Mimikatz?


File Info:

crc32: A7B00D88
md5: 59b58e4fda1a5a67870caeaa27ca5545
name: mi.exe
sha1: b437992a53035130a311c16ae22213bcc6509062
sha256: 490ffbedd3fbba137eef682c60bc042900a8878e422d3e0e8ab58f786807c440
sha512: 51749dbff3ea1360bbef1b8a89590cf49c81c54f3504e987dc454ee646f2dc53685e5532fe028fee1aaa9c6201b5f0a3ea9e80857bf095dcc71a4e1cf4d5061e
ssdeep: 196608:eQ3gKYZzDqcRM9mH8cSwE7dGcUFibIQRfG7:eQ3gvJ6mH8cSZdGWIkG7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-PSW.Win64.Mimikatz also known as:

CAT-QuickHealHackTool.Mimikatz.S13719268
McAfeeHTool-MimiKatz!736C963C78ED
ZillyaTrojan.Miner.Script.137
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.a53035
Invinceaheuristic
APEXMalicious
ClamAVWin.Trojan.Mimikatz-6466236-0
KasperskyHEUR:Trojan-PSW.Win64.Mimikatz.gen
NANO-AntivirusTrojan.Win64.MimiKatz.fqcnvp
RisingMalware.Strealer!8.1EF (TFE:dGZlOgUzITxjqpLUYA)
ComodoMalware@#3kihpl7irga81
F-SecureHeuristic.HEUR/AGEN.1127008
DrWebTool.Mimikatz.506
TrendMicroHKTL_MIMIKATZ64
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.59b58e4fda1a5a67
SophosTroj/Mimkatz-T
SentinelOneDFI – Suspicious PE
CyrenW64/S-b61adc75!Eldorado
JiangminTrojan.PSW.Mimikatz.pv
Avirami.exe
Antiy-AVLTrojan[PSW]/Win64.Mimikatz
MicrosoftTrojan:Win32/Wacatac.D!ml
Endgamemalicious (high confidence)
ZoneAlarmHEUR:Trojan-PSW.Win64.Mimikatz.gen
Acronissuspicious
VBA32TrojanPSW.Win64.Mimikatz
MalwarebytesHackTool.Mimikatz
ESET-NOD32a variant of Win64/Riskware.Mimikatz.CB
TrendMicro-HouseCallHKTL_MIMIKATZ64
YandexRiskware.Mimikatz!
IkarusHackTool.Mimikatz
eGambithacktool.mimikatz
FortinetW64/Mimikatz!tr.pws
PandaHackingTool/Mimikatz
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Win64/Trojan.PSW.a2b

How to remove Trojan-PSW.Win64.Mimikatz?

Trojan-PSW.Win64.Mimikatz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment