powerbot.exe

Java Platform SE 8 U25

Oracle Corporation

Publisher:
Oracle Corporation

Product:
Java Platform SE 8 U25

Description:
Setup Launcher

Version:
8.0.250.18

MD5:
59deca6b99d87dae8105d0f3abc420ab

SHA-1:
69ff0e65024ec3b0da56f8f3da825a341c3ccf11

SHA-256:
224ff42c75bce99d560ca06a0252e0efebb74e493b1cd98164f25a3bb41cf516

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 4:37:18 AM UTC  (today)

File size:
3.9 MB (4,067,968 bytes)

Product version:
8.0.250.18

Copyright:
Copyright © 2014

Original file name:
qyt4.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\powerbot.exe

File PE Metadata
Compilation timestamp:
4/26/2015 10:07:56 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:i5aUF0Dq9SmvTyJz5REsIizN6LBe1QYuKOTOl4cxoKiU45qY2MqxkOdPyo:i5zF0STqdREs1hA0qYBZvWUxtBDdL

Entry address:
0x2A9382

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.3583

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2.7 MB (2,782,208 bytes)

The file powerbot.exe has been seen being distributed by the following URL.

Scan powerbot.exe - Powered by Reason Core Security