Skip to content

mimikatz.exe_: self delete #1089

@mike-hunhoff

Description

@mike-hunhoff

Function: 0x45B8DB

What it does: The function calls GetProcAddress for DeleteProcThreadAttributeList and CreateProcess.

Why it matched: capa matched the regex del on the API string DeleteProcThread.... The function creates a process with a specified parent (PID Spoofing), it does not delete itself.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions