PBE IT logo
PBE Security Analysis Report

Clean (high confidence)

Disposition

Recommended action: No CAPE indicators were found after filtering. Release is reasonable if the source matches user expectation.

CAPE Raw Score
1.0
unfiltered, includes baseline noise
v0.2 Filtered Score
0.50
noise removed, weighted
Delta
↓ 0.50
noise correction

This disposition is based on the v0.2 scoring model calibrated against benign Microsoft binaries. It is informational, not a guarantee.

Ticket Response (copy and paste)

Drafted for the requester. Adjust greeting/closing as needed.

Thanks for checking with us on rdonelan_pbenet.com.html before you opened it.

IT ran the file in our analysis sandbox for 10 minute(s) and 36 seconds. Our analysis rated this at 0.50 out of 10, which we classify as Clean (high confidence). During the analysis, the file launched 1 process(es), contacted 139 network indicator(s), did not drop any files to disk.

Based on what we observed, this file is reasonable to open if it came from a source you recognize and expected.

Please continue to forward anything you are unsure about. Catching it before you open is exactly the right move.

PBE IT Security

Visual Evidence

116 screenshot(s) captured during analysis. Showing 30. View all in CAPE

Screenshot 0001
frame 0001
Screenshot 0005
frame 0005
Screenshot 0007
frame 0007
Screenshot 0013
frame 0013
Screenshot 0014
frame 0014
Screenshot 0017
frame 0017
Screenshot 0020
frame 0020
Screenshot 0023
frame 0023
Screenshot 0037
frame 0037
Screenshot 0039
frame 0039
Screenshot 0041
frame 0041
Screenshot 0043
frame 0043
Screenshot 0049
frame 0049
Screenshot 0059
frame 0059
Screenshot 0060
frame 0060
Screenshot 0062
frame 0062
Screenshot 0064
frame 0064
Screenshot 0067
frame 0067
Screenshot 0070
frame 0070
Screenshot 0071
frame 0071
Screenshot 0074
frame 0074
Screenshot 0075
frame 0075
Screenshot 0080
frame 0080
Screenshot 0083
frame 0083
Screenshot 0084
frame 0084
Screenshot 0088
frame 0088
Screenshot 0089
frame 0089
Screenshot 0092
frame 0092
Screenshot 0105
frame 0105
Screenshot 0109
frame 0109

What the Sample Did (Plain English)

Scoring Breakdown — How we got from 1.0 to 0.50

Score Components

STRONG signatures0 signature(s), contributed 0.0
UNBACKED family (capped at 2.0)raw=0.0, applied=0.0
AMBIGUOUS re-amplification0 signature(s), contributed 0.0 (only fires when 2+ STRONG present)
UNKNOWN signatures (half weight)contributed 0.5
Detection floor applied?no
Final v0.2 Score0.50 / 10

STRONG Signatures (real malicious signal)

No strong signatures.

AMBIGUOUS Signatures (common on benign, can be real)

No ambiguous signatures.

UNBACKED Family (capped — common on asm/JIT code, can be real)

No unbacked signatures.

UNKNOWN Signatures (not yet classified, half weight)

SignatureSevWeightConfScore ΔDescription
suspicious_html_title11.0100.0%0.5Sample contains empty HTML title

NOISE Signatures (suppressed, score = 0)

SignatureSevWeightConfScore ΔDescription
stealth_network11.0100.0%0.0Network activity detected but not expressed in monitor API logs

SHELL_HOST Signatures (suppressed for non-PE samples)

No shell_host signatures.

File Details
File namerdonelan_pbenet.com.html
File typeHTML document, ASCII text, with CRLF line terminators
Size (bytes)196
MD57a01310cb6a95d3b05e6d6d58629b3cb
SHA18859f841aff1b0d41e5e3ed82002352402a030a1
SHA256fea8935a855f42ee7848680f802ddc094fa8097225bad3722a90dc661531de4c
VirusTotalOpen in VirusTotal
Sandbox Run Details
Task ID49
Started2026-07-13 18:31:24
Ended2026-07-13 18:42:00
Duration (sec)636
Packageedge
Routeinternet
Machinecuckoo1
Tech Override

No override active. The model verdict above is the current classification.

Report generated on 07-13-2026 18:43:03 by PBESANDBOX.PBESECURE.COM