PBE IT logo
PBE Security Analysis Report

Clean (high confidence)

Disposition

Recommended action: No CAPE indicators were found after filtering. Release is reasonable if the source matches user expectation.

CAPE Raw Score
1.6
unfiltered, includes baseline noise
v0.2 Filtered Score
0.40
noise removed, weighted
Delta
↓ 1.20
noise correction

This disposition is based on the v0.2 scoring model calibrated against benign Microsoft binaries. It is informational, not a guarantee.

Ticket Response (copy and paste)

Drafted for the requester. Adjust greeting/closing as needed.

Thanks for checking with us on Womans underwear Sna.pdf before you opened it.

IT ran the file in our analysis sandbox for 30 seconds. Our analysis rated this at 0.40 out of 10, which we classify as Clean (high confidence). During the analysis, contacted 45 network indicator(s), did not drop any files to disk.

Based on what we observed, this file is reasonable to open if it came from a source you recognize and expected.

Please continue to forward anything you are unsure about. Catching it before you open is exactly the right move.

PBE IT Security

Visual Evidence

1 screenshot(s) captured during analysis. Showing 1. View all in CAPE

Screenshot 0001
frame 0001

What the Sample Did (Plain English)

Scoring Breakdown — How we got from 1.6 to 0.40

Score Components

STRONG signatures0 signature(s), contributed 0.0
UNBACKED family (capped at 2.0)raw=0.0, applied=0.0
AMBIGUOUS re-amplification0 signature(s), contributed 0.0 (only fires when 2+ STRONG present)
UNKNOWN signatures (half weight)contributed 0.4
Detection floor applied?no
Final v0.2 Score0.40 / 10

STRONG Signatures (real malicious signal)

No strong signatures.

AMBIGUOUS Signatures (common on benign, can be real)

No ambiguous signatures.

UNBACKED Family (capped — common on asm/JIT code, can be real)

No unbacked signatures.

UNKNOWN Signatures (not yet classified, half weight)

SignatureSevWeightConfScore ΔDescription
binary_yara31.080.0%0.4Binary file triggered multiple YARA rules

NOISE Signatures (suppressed, score = 0)

No noise signatures.

SHELL_HOST Signatures (suppressed for non-PE samples)

No shell_host signatures.

File Details
File nameWomans underwear Sna.pdf
File typePDF document, version 2.0, 1 page(s)
Size (bytes)2158394
MD5688b474e33ff1a8bab6fa32d3d34f7e0
SHA168376300d470a263cf33b7b6dd23a356b16dcebb
SHA256a6f6bb36aa28cb2f1c4bedffa40c336f3a367b4d9c7efd5d15607884026d757e
VirusTotalOpen in VirusTotal
Sandbox Run Details
Task ID12
Started2026-06-26 10:41:53
Ended2026-06-26 10:42:23
Duration (sec)30
Packagepdf
Routeinternet
Machinecuckoo2
Tech Override

No override active. The model verdict above is the current classification.

Report generated on 06-30-2026 10:36:27 by PBESANDBOX.PBESECURE.COM