CAPE Tech Safety Summary

Suspicious / Verify Source

Recommended action: Verify source, signer, and reputation before approving.

Why this verdict: CAPE assigned a moderate to high score, but this report did not find strong behavior-based indicators.

Important: This report should not say a file is absolutely safe. A better phrase is: no obvious malicious behavior was observed in this sandbox run.

Quick Notes

Reputation / External Lookup

VirusTotal: Unavailable/error from CAPE: Unable to complete connection to VirusTotal. Status code: 429

Manual lookup: Open SHA256 in VirusTotal

This report only uses VirusTotal detection counts if they are present in the CAPE JSON. A link alone is not the same as a local detection result.

File Details

File name pbe-remote-help.msi
File type Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: PBE-Remote-Help Installer, Author: PURSLANE, Keywords: Installer, Comments: This installer database contains the logic and data required to install PBE-Remote-Help., Template: x64;1033, Revision Number: {4B986941-1D3F-4C19-B6EB-734021E08AE7}, Create Time/Date: Mon May 4 17:02:28 2026, Last Saved Time/Date: Mon May 4 17:02:28 2026, Number of Pages: 500, Number of Words: 2, Name of Creating Application: WiX Toolset (4.0.5.0), Security: 2
Size 24948736
MD5 3dbb7964296f631bb3288c2e81f34ec5
SHA1 e5f822056e1c892ab7c1d2c4bb5e78825c52ca03
SHA256 a4d98e1ebc0671ab75bfd7202cca24d9afdc2793e69a6f2ca924ff5446a18a7d
VirusTotal lookup Open SHA256 in VirusTotal

Sandbox Run Details

Task ID 12
Started 2026-06-15 19:08:30
Ended 2026-06-15 19:11:43
Duration 193 seconds
Package msi
Route none
Machine cuckoo1
CAPE score 5.9
CAPE status
Digital signature No signer data found in CAPE JSON.

Top CAPE Signatures

SeverityConfidenceSignatureMeaning
2 80% privilege_elevation_check Queries process token information to check for Administrator privileges or UAC elevation status
2 20% mountpoints_volume_discovery Queries the mount points and then resolves volume paths to enumerate storage devices
2 50% creates_suspended_process Creates a process in a suspended state, likely for injection
2 100% resumethread_remote_process Resumed a thread in another process
2 100% network_connection_via_suspicious_process Attempts to make a network connection via suspicious process
2 20% discover_registry_mount_points Queries registry mount points to identify historical or connected removable/network drives
2 80% uses_windows_utilities Uses Windows utilities for basic functionality
1 100% queries_keyboard_layout Queries the keyboard layout
1 40% antidebug_setunhandledexceptionfilter SetUnhandledExceptionFilter detected (possible anti-debug)
1 40% stealth_timeout Possible date expiration check, exits too soon after checking local time
1 100% language_check_registry Checks system language via registry key (possible geofencing)

Behavior Summary

Observed itemCount
Executed commands / child processes5
File writes7
File deletes4
Registry writes0
Created services0
Started services1
CAPE payload-like items0
CAPE extracted configs0
Dropped/related files captured1

Executed Commands / Child Processes

``` C:\WINDOWS\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} ``` ``` C:\WINDOWS\system32\DllHost.exe /Processid:{6C752774-29FB-4E50-8BB1-97098425A77C} ``` ``` "C:\Program Files\WindowsApps\Microsoft.DesktopAppInstaller_1.21.10120.0_x64__8wekyb3d8bbwe\WindowsPackageManagerServer.exe" -Embedding ``` ``` C:\WINDOWS\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B} ``` ``` C:\WINDOWS\system32\wbem\wmiprvse.exe -secured -Embedding ```

File Writes

``` \??\PIPE\wkssvc ``` ``` \??\DamCtrl ``` ``` C:\ProgramData\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\S-1-5-21-3021741035-2986501292-914809479-1000\SystemAppData\Helium\Cache\8b63528ae707e766.dat ``` ``` \Device\VRegDriver ``` ``` \Device\NamedPipe\Sessions\1\AppContainerNamedObjects\S-1-15-2-2473817148-3930944034-1235795307-187980641-3967865409-1804095407-1113801530 ``` ``` \Device\RasAcd ``` ``` C:\Users\IT\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\DiagOutputDir\WinGetCOM-2026-06-15-19-10-07.988.log ```

Registry Writes

None observed.

Created Services

None observed.

Started Services

``` msiserver ```

CAPE Payloads / Extracted Items

No CAPE payload-like items were extracted.

None observed.

Network Activity

No network activity recorded in this report.

Generated 2026-06-15T19:12:02 from /opt/CAPEv2/storage/analyses/12/reports/report.json