PBE IT logo
PBE Security Analysis Report

Clean (high confidence)

Disposition

Recommended action: No CAPE indicators were found after filtering. Release is reasonable if the source matches user expectation.

CAPE Raw Score
1.2
unfiltered, includes baseline noise
v0.2 Filtered Score
0.55
noise removed, weighted
Delta
↓ 0.65
noise correction

This disposition is based on the v0.2 scoring model calibrated against benign Microsoft binaries. It is informational, not a guarantee.

Ticket Response (copy and paste)

Drafted for the requester. Adjust greeting/closing as needed.

Thanks for checking with us on 1612464.pdf before you opened it.

IT ran the file in our analysis sandbox for 7 minute(s) and 26 seconds. Our analysis rated this at 0.55 out of 10, which we classify as Clean (high confidence). During the analysis, the file launched 1 process(es), contacted 256 network indicator(s), did not drop any files to disk, triggered indicators of concern (exploit_heapspray).

Based on what we observed, this file is reasonable to open if it came from a source you recognize and expected.

Please continue to forward anything you are unsure about. Catching it before you open is exactly the right move.

PBE IT Security

Visual Evidence

51 screenshot(s) captured during analysis. Showing 19. View all in CAPE

Screenshot 0001
frame 0001
Screenshot 0002
frame 0002
Screenshot 0003
frame 0003
Screenshot 0008
frame 0008
Screenshot 0009
frame 0009
Screenshot 0013
frame 0013
Screenshot 0023
frame 0023
Screenshot 0028
frame 0028
Screenshot 0030
frame 0030
Screenshot 0032
frame 0032
Screenshot 0033
frame 0033
Screenshot 0034
frame 0034
Screenshot 0042
frame 0042
Screenshot 0046
frame 0046
Screenshot 0047
frame 0047
Screenshot 0048
frame 0048
Screenshot 0049
frame 0049
Screenshot 0050
frame 0050
Screenshot 0051
frame 0051

What the Sample Did (Plain English)

Scoring Breakdown — How we got from 1.2 to 0.55

Score Components

STRONG signatures1 signature(s), contributed 0.4
UNBACKED family (capped at 2.0)raw=0.0, applied=0.0
AMBIGUOUS re-amplification0 signature(s), contributed 0.0 (only fires when 2+ STRONG present)
UNKNOWN signatures (half weight)contributed 0.15
Detection floor applied?no
Final v0.2 Score0.55 / 10

STRONG Signatures (real malicious signal)

SignatureSevWeightConfScore ΔDescription
exploit_heapspray11.040.0%0.4A possible heap spray exploit has been detected

AMBIGUOUS Signatures (common on benign, can be real)

No ambiguous signatures.

UNBACKED Family (capped — common on asm/JIT code, can be real)

No unbacked signatures.

UNKNOWN Signatures (not yet classified, half weight)

SignatureSevWeightConfScore ΔDescription
network_http21.030.0%0.15Performs some HTTP requests

NOISE Signatures (suppressed, score = 0)

SignatureSevWeightConfScore ΔDescription
stealth_network11.0100.0%0.0Network activity detected but not expressed in monitor API logs
antidebug_setunhandledexceptionfilter11.040.0%0.0SetUnhandledExceptionFilter detected (possible anti-debug)

SHELL_HOST Signatures (suppressed for non-PE samples)

No shell_host signatures.

File Details
File name1612464.pdf
File typePDF document, version 1.7 (zip deflate encoded)
Size (bytes)184039
MD587b54e08bc2caaed970cc2e8d39847d3
SHA1bf4f227de4ec967f27d4078ee0ba6a6a1186ee7d
SHA25664ce0a73e5ace92666f3cf2d66d33807c705457484cf0393d45db1b4272c65c5
VirusTotalOpen in VirusTotal
Sandbox Run Details
Task ID26
Started2026-06-30 14:51:35
Ended2026-06-30 14:59:01
Duration (sec)446
Packagepdf
Routeinternet
Machinecuckoo1
Tech Override

No override active. The model verdict above is the current classification.

Report generated on 06-30-2026 15:00:02 by PBESANDBOX.PBESECURE.COM