PBE IT logo
PBE Security Analysis Report

Clean (high confidence)

Disposition

Recommended action: No CAPE indicators were found after filtering. Release is reasonable if the source matches user expectation.

CAPE Raw Score
1.0
unfiltered, includes baseline noise
v0.2 Filtered Score
0.50
noise removed, weighted
Delta
↓ 0.50
noise correction

This disposition is based on the v0.2 scoring model calibrated against benign Microsoft binaries. It is informational, not a guarantee.

Ticket Response (copy and paste)

Drafted for the requester. Adjust greeting/closing as needed.

Thanks for checking with us on Vitality_FeedingTub.html before you opened it.

IT ran the file in our analysis sandbox for 3 minute(s) and 43 seconds. Our analysis rated this at 0.50 out of 10, which we classify as Clean (high confidence). During the analysis, the file launched 1 process(es), contacted 897 network indicator(s), did not drop any files to disk.

Based on what we observed, this file is reasonable to open if it came from a source you recognize and expected.

Please continue to forward anything you are unsure about. Catching it before you open is exactly the right move.

PBE IT Security

Visual Evidence

49 screenshot(s) captured during analysis. Showing 11. View all in CAPE

Screenshot 0001
frame 0001
Screenshot 0002
frame 0002
Screenshot 0008
frame 0008
Screenshot 0009
frame 0009
Screenshot 0011
frame 0011
Screenshot 0012
frame 0012
Screenshot 0018
frame 0018
Screenshot 0044
frame 0044
Screenshot 0047
frame 0047
Screenshot 0048
frame 0048
Screenshot 0049
frame 0049

What the Sample Did (Plain English)

Scoring Breakdown — How we got from 1.0 to 0.50

Score Components

STRONG signatures0 signature(s), contributed 0.0
UNBACKED family (capped at 2.0)raw=0.0, applied=0.0
AMBIGUOUS re-amplification0 signature(s), contributed 0.0 (only fires when 2+ STRONG present)
UNKNOWN signatures (half weight)contributed 0.5
Detection floor applied?no
Final v0.2 Score0.50 / 10

STRONG Signatures (real malicious signal)

No strong signatures.

AMBIGUOUS Signatures (common on benign, can be real)

No ambiguous signatures.

UNBACKED Family (capped — common on asm/JIT code, can be real)

No unbacked signatures.

UNKNOWN Signatures (not yet classified, half weight)

SignatureSevWeightConfScore ΔDescription
suspicious_html_title11.0100.0%0.5Sample contains empty HTML title

NOISE Signatures (suppressed, score = 0)

SignatureSevWeightConfScore ΔDescription
stealth_network11.0100.0%0.0Network activity detected but not expressed in monitor API logs

SHELL_HOST Signatures (suppressed for non-PE samples)

No shell_host signatures.

File Details
File nameVitality_FeedingTub.html
File typeHTML document, Unicode text, UTF-8 text, with very long lines (7733)
Size (bytes)36977
MD5813b3c42e8a208907e4c60ad981ce1a7
SHA199d9830a5cca5ba7147d639f28348206e8fb71e4
SHA256e1bde0161f87a7d1f023642397d7ce50ddc1e61895d5ef8f01bfc995ea637a19
VirusTotalOpen in VirusTotal
Sandbox Run Details
Task ID2
Started2026-06-25 14:20:32
Ended2026-06-25 14:24:15
Duration (sec)223
Packageedge
Routeinternet
Machinecuckoo2
Tech Override

No override active. The model verdict above is the current classification.

Report generated on 06-30-2026 10:36:26 by PBESANDBOX.PBESECURE.COM