attach.dll

Description: OpenJDK Platform binary

Authors: Copyright © 2024

Version: 21.0.3.0

Architecture: 64-bit

Operating System: Windows

SHA256: 49af8f0c75aa1cc23f1f6ddab7fb8fea

File Size: 18.5 KB

Uploaded At: Dec. 4, 2025, 6:15 a.m.

Views: 10

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: WriteProcessMemory, CreateRemoteThread, VirtualAllocEx, OpenProcess

Exported Functions

  • Java_sun_tools_attach_AttachProviderImpl_enumProcesses (Ordinal: 1, Address: 0x1000)
  • Java_sun_tools_attach_AttachProviderImpl_isLibraryLoadedByProcess (Ordinal: 2, Address: 0x1088)
  • Java_sun_tools_attach_AttachProviderImpl_tempPath (Ordinal: 3, Address: 0x11cc)
  • Java_sun_tools_attach_AttachProviderImpl_volumeFlags (Ordinal: 4, Address: 0x1288)
  • Java_sun_tools_attach_VirtualMachineImpl_closePipe (Ordinal: 5, Address: 0x131c)
  • Java_sun_tools_attach_VirtualMachineImpl_closeProcess (Ordinal: 6, Address: 0x131c)
  • Java_sun_tools_attach_VirtualMachineImpl_connectPipe (Ordinal: 7, Address: 0x1328)
  • Java_sun_tools_attach_VirtualMachineImpl_createPipe (Ordinal: 8, Address: 0x1364)
  • Java_sun_tools_attach_VirtualMachineImpl_enqueue (Ordinal: 9, Address: 0x1454)
  • Java_sun_tools_attach_VirtualMachineImpl_generateStub (Ordinal: 10, Address: 0x187c)
  • Java_sun_tools_attach_VirtualMachineImpl_init (Ordinal: 11, Address: 0x18ec)
  • Java_sun_tools_attach_VirtualMachineImpl_openProcess (Ordinal: 12, Address: 0x1918)
  • Java_sun_tools_attach_VirtualMachineImpl_readPipe (Ordinal: 13, Address: 0x1ab8)

Imported DLLs & Functions

ADVAPI32.dll
  • AdjustTokenPrivileges (Address: 0x180003010)
  • ConvertStringSecurityDescriptorToSecurityDescriptorA (Address: 0x180003020)
  • ImpersonateSelf (Address: 0x180003008)
  • LookupPrivilegeValueA (Address: 0x180003000)
  • OpenThreadToken (Address: 0x180003018)
api-ms-win-crt-heap-l1-1-0.dll
  • free (Address: 0x1800031a0)
  • malloc (Address: 0x180003198)
api-ms-win-crt-runtime-l1-1-0.dll
  • _cexit (Address: 0x1800031b0)
  • _configure_narrow_argv (Address: 0x1800031d8)
  • _execute_onexit_table (Address: 0x1800031b8)
  • _initialize_narrow_environment (Address: 0x1800031d0)
  • _initialize_onexit_table (Address: 0x1800031c0)
  • _initterm (Address: 0x1800031e8)
  • _initterm_e (Address: 0x1800031c8)
  • _seh_filter_dll (Address: 0x1800031e0)
api-ms-win-crt-stdio-l1-1-0.dll
  • __stdio_common_vsprintf (Address: 0x1800031f8)
api-ms-win-crt-string-l1-1-0.dll
  • strcmp (Address: 0x180003208)
  • strcpy (Address: 0x180003210)
  • strncpy (Address: 0x180003218)
java.dll
  • JNU_GetStringPlatformChars (Address: 0x180003250)
  • JNU_NewStringPlatform (Address: 0x180003258)
  • JNU_ReleaseStringPlatformChars (Address: 0x180003238)
  • JNU_ThrowByName (Address: 0x180003230)
  • JNU_ThrowInternalError (Address: 0x180003228)
  • JNU_ThrowIOException (Address: 0x180003248)
  • JNU_ThrowIOExceptionWithLastError (Address: 0x180003240)
KERNEL32.dll
  • CloseHandle (Address: 0x180003090)
  • ConnectNamedPipe (Address: 0x1800030c0)
  • CreateNamedPipeA (Address: 0x180003130)
  • CreateRemoteThread (Address: 0x1800030e0)
  • DisableThreadLibraryCalls (Address: 0x180003050)
  • DuplicateHandle (Address: 0x1800030a8)
  • GetCurrentProcess (Address: 0x1800030d0)
  • GetCurrentProcessId (Address: 0x1800030d8)
  • GetCurrentThread (Address: 0x1800030e8)
  • GetCurrentThreadId (Address: 0x180003030)
  • GetExitCodeThread (Address: 0x1800030f0)
  • GetLastError (Address: 0x1800030b0)
  • GetModuleHandleA (Address: 0x180003118)
  • GetProcAddress (Address: 0x180003120)
  • GetSystemTimeAsFileTime (Address: 0x180003048)
  • GetTempPathA (Address: 0x180003080)
  • GetVolumeInformationA (Address: 0x180003088)
  • InitializeSListHead (Address: 0x180003038)
  • IsDebuggerPresent (Address: 0x180003040)
  • IsProcessorFeaturePresent (Address: 0x180003068)
  • IsWow64Process (Address: 0x180003110)
  • LocalFree (Address: 0x180003128)
  • OpenProcess (Address: 0x180003098)
  • QueryPerformanceCounter (Address: 0x180003060)
  • ReadFile (Address: 0x1800030a0)
  • RtlCaptureContext (Address: 0x180003138)
  • RtlLookupFunctionEntry (Address: 0x180003058)
  • RtlVirtualUnwind (Address: 0x180003148)
  • SetLastError (Address: 0x1800030b8)
  • SetUnhandledExceptionFilter (Address: 0x180003078)
  • TerminateProcess (Address: 0x180003070)
  • UnhandledExceptionFilter (Address: 0x180003140)
  • VirtualAllocEx (Address: 0x1800030f8)
  • VirtualFreeEx (Address: 0x180003108)
  • WaitForSingleObject (Address: 0x1800030c8)
  • WriteProcessMemory (Address: 0x180003100)
PSAPI.DLL
  • EnumProcesses (Address: 0x180003168)
  • EnumProcessModules (Address: 0x180003160)
  • GetModuleBaseNameA (Address: 0x180003158)
VCRUNTIME140.dll
  • __C_specific_handler (Address: 0x180003178)
  • __std_type_info_destroy_list (Address: 0x180003188)
  • memset (Address: 0x180003180)