PBE IT logo
PBE Security Analysis Report

Low Concern

Disposition

Recommended action: No malicious behavior was observed. A small number of low-confidence indicators were noted; verify the source and user expectation.

CAPE Raw Score
3.0
unfiltered, includes baseline noise
v0.2 Filtered Score
1.00
noise removed, weighted
Delta
↓ 2.00
noise correction

This disposition is based on the v0.2 scoring model calibrated against benign Microsoft binaries. It is informational, not a guarantee.

Ticket Response (copy and paste)

Drafted for the requester. Adjust greeting/closing as needed.

Thanks for checking with us on rdonelan_pbenet.com.html before you opened it.

IT ran the file in our analysis sandbox for 3 minute(s) and 42 seconds. Our analysis rated this at 1.00 out of 10, which we classify as Low Concern. During the analysis, the file launched 1 process(es), contacted 99 network indicator(s), did not drop any files to disk. A small number of low-confidence indicators were observed but none were consistent with malicious behavior.

Based on what we observed, this file is reasonable to open if it came from a source you recognize and expected. If anything feels off about the source, hold off and let us know.

Please continue to forward anything you are unsure about. Catching it before you open is exactly the right move.

PBE IT Security

Visual Evidence

42 screenshot(s) captured during analysis. Showing 10. View all in CAPE

Screenshot 0001
frame 0001
Screenshot 0003
frame 0003
Screenshot 0007
frame 0007
Screenshot 0012
frame 0012
Screenshot 0013
frame 0013
Screenshot 0014
frame 0014
Screenshot 0027
frame 0027
Screenshot 0028
frame 0028
Screenshot 0033
frame 0033
Screenshot 0042
frame 0042

What the Sample Did (Plain English)

Scoring Breakdown — How we got from 3.0 to 1.00

Score Components

STRONG signatures0 signature(s), contributed 0.0
UNBACKED family (capped at 2.0)raw=0.0, applied=0.0
AMBIGUOUS re-amplification0 signature(s), contributed 0.0 (only fires when 2+ STRONG present)
UNKNOWN signatures (half weight)contributed 1.0
Detection floor applied?no
Final v0.2 Score1.00 / 10

STRONG Signatures (real malicious signal)

No strong signatures.

AMBIGUOUS Signatures (common on benign, can be real)

No ambiguous signatures.

UNBACKED Family (capped — common on asm/JIT code, can be real)

No unbacked signatures.

UNKNOWN Signatures (not yet classified, half weight)

SignatureSevWeightConfScore ΔDescription
suspicious_html_title11.0100.0%0.5Sample contains empty HTML title
network_icmp31.0100.0%0.5Generates some ICMP traffic

NOISE Signatures (suppressed, score = 0)

SignatureSevWeightConfScore ΔDescription
stealth_network11.0100.0%0.0Network activity detected but not expressed in monitor API logs

SHELL_HOST Signatures (suppressed for non-PE samples)

No shell_host signatures.

File Details
File namerdonelan_pbenet.com.html
File typeHTML document, ASCII text, with CRLF line terminators
Size (bytes)196
MD57a01310cb6a95d3b05e6d6d58629b3cb
SHA18859f841aff1b0d41e5e3ed82002352402a030a1
SHA256fea8935a855f42ee7848680f802ddc094fa8097225bad3722a90dc661531de4c
VirusTotalOpen in VirusTotal
Sandbox Run Details
Task ID48
Started2026-07-13 18:22:55
Ended2026-07-13 18:26:37
Duration (sec)222
Packageedge
Routeinternet
Machinecuckoo1
Tech Override

No override active. The model verdict above is the current classification.

Report generated on 07-13-2026 18:27:02 by PBESANDBOX.PBESECURE.COM