Suspicious
Suspect

e3588eea4c91251891eb52ce99489c16

PE Executable
MD5: e3588eea4c91251891eb52ce99489c16
Size: 1.12 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 e3588eea4c91251891eb52ce99489c16
Sha1 e94464c2c8cd298ab5288de6206f0cd2f9482b90
Sha256 ae8a1e6cd66929b78a7f4b98911d04650346cefc046eb60f2bfc85eba95686f5
Sha384 dbdc25506f8bfbf5fe1e8fe8e306ba86389cafccec20597ff78548ebb687469ae8f1d35dd3c887532859ea02932f6b36
Sha512 4002355c7cf0edcfe4140d643325fae2d683d4f9fdb47b68023f403e0b2ce3649dd99a384a47fa2faf99643b7b04e010d38d59eadb52241e3626e49cb60af11c
SSDeep 24576:j2uUNuA6gK47/D9GLpPR6r/hkUX9b322DS/g/JLJgiW6asdAQ:iuUggK4sd562UtpG/CJtxSqA
TLSH 2F350254238DD906C6A74BF00D70D3B96BB89E49E911C2039FF9FEEBB56D6593804382
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CaveSystem.CaveForm.resources
CaveSystem.Properties.Resources.resources
Diff
[NBF]root.Data
PSIv
[NBF]root.Data
[NBF]root.Data-preview.png
restart
[NBF]root.Data
[NBF]root.Data-preview.png
rocket
[NBF]root.Data
[NBF]root.Data-preview.png
status_error
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
RbjK.exe
Full Name
RbjK.exe
EntryPoint
System.Void CaveSystem.Program::Main()
Scope Name
RbjK.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
RbjK
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.5
Total Strings
282
Main Method
System.Void CaveSystem.Program::Main()
Main IL Instruction Count
10
Main IL
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void CaveSystem.CaveForm::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
CaveSystem.CaveForm.resources
CaveSystem.Properties.Resources.resources
Diff
[NBF]root.Data
PSIv
[NBF]root.Data
[NBF]root.Data-preview.png
restart
[NBF]root.Data
[NBF]root.Data-preview.png
rocket
[NBF]root.Data
[NBF]root.Data-preview.png
status_error
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙