Disposition
Recommended action: No CAPE indicators were found after filtering. Release is reasonable if the source matches user expectation.
This disposition is based on the v0.2 scoring model calibrated against benign Microsoft binaries. It is informational, not a guarantee.
Drafted for the requester. Adjust greeting/closing as needed.
Thanks for checking with us on 1612464.pdf before you opened it.
IT ran the file in our analysis sandbox for 7 minute(s) and 26 seconds. Our analysis rated this at 0.55 out of 10, which we classify as Clean (high confidence). During the analysis, the file launched 1 process(es), contacted 256 network indicator(s), did not drop any files to disk, triggered indicators of concern (exploit_heapspray).
Based on what we observed, this file is reasonable to open if it came from a source you recognize and expected.
Please continue to forward anything you are unsure about. Catching it before you open is exactly the right move.
PBE IT Security
| STRONG signatures | 1 signature(s), contributed 0.4 |
|---|---|
| UNBACKED family (capped at 2.0) | raw=0.0, applied=0.0 |
| AMBIGUOUS re-amplification | 0 signature(s), contributed 0.0 (only fires when 2+ STRONG present) |
| UNKNOWN signatures (half weight) | contributed 0.15 |
| Detection floor applied? | no |
| Final v0.2 Score | 0.55 / 10 |
| Signature | Sev | Weight | Conf | Score Δ | Description |
|---|---|---|---|---|---|
exploit_heapspray | 1 | 1.0 | 40.0% | 0.4 | A possible heap spray exploit has been detected |
No ambiguous signatures.
No unbacked signatures.
| Signature | Sev | Weight | Conf | Score Δ | Description |
|---|---|---|---|---|---|
network_http | 2 | 1.0 | 30.0% | 0.15 | Performs some HTTP requests |
| Signature | Sev | Weight | Conf | Score Δ | Description |
|---|---|---|---|---|---|
stealth_network | 1 | 1.0 | 100.0% | 0.0 | Network activity detected but not expressed in monitor API logs |
antidebug_setunhandledexceptionfilter | 1 | 1.0 | 40.0% | 0.0 | SetUnhandledExceptionFilter detected (possible anti-debug) |
No shell_host signatures.
| File name | 1612464.pdf |
|---|---|
| File type | PDF document, version 1.7 (zip deflate encoded) |
| Size (bytes) | 184039 |
| MD5 | 87b54e08bc2caaed970cc2e8d39847d3 |
| SHA1 | bf4f227de4ec967f27d4078ee0ba6a6a1186ee7d |
| SHA256 | 64ce0a73e5ace92666f3cf2d66d33807c705457484cf0393d45db1b4272c65c5 |
| VirusTotal | Open in VirusTotal |
| Task ID | 26 |
|---|---|
| Started | 2026-06-30 14:51:35 |
| Ended | 2026-06-30 14:59:01 |
| Duration (sec) | 446 |
| Package | |
| Route | internet |
| Machine | cuckoo1 |
No override active. The model verdict above is the current classification.
Report generated on 06-30-2026 15:00:02 by PBESANDBOX.PBESECURE.COM