Skip to content

mimikatz.exe_: self delete #1089

@mike-hunhoff

Description

@mike-hunhoff

Function: 0x45B8DB

What it does: The function calls GetProcAddress for DeleteProcThreadAttributeList and CreateProcess.

Why it matched: capa matched the regex del on the API string DeleteProcThread.... The function creates a process with a specified parent (PID Spoofing), it does not delete itself.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions