PBE IT logo
PBE Security Analysis Report

Clean (high confidence)

Disposition

Recommended action: No CAPE indicators were found after filtering. Release is reasonable if the source matches user expectation.

CAPE Raw Score
10.0
unfiltered, includes baseline noise
v0.2 Filtered Score
0.20
noise removed, weighted
Delta
↓ 9.80
noise correction

This disposition is based on the v0.2 scoring model calibrated against benign Microsoft binaries. It is informational, not a guarantee.

Ticket Response (copy and paste)

Drafted for the requester. Adjust greeting/closing as needed.

Thanks for checking with us on BC1-1D.msi before you opened it.

IT ran the file in our analysis sandbox for 11 minute(s) and 40 seconds. Our analysis rated this at 0.20 out of 10, which we classify as Clean (high confidence). During the analysis, the file launched 13 process(es), contacted 85 network indicator(s), dropped 4 additional file(s).

Based on what we observed, this file is reasonable to open if it came from a source you recognize and expected.

Please continue to forward anything you are unsure about. Catching it before you open is exactly the right move.

PBE IT Security

Visual Evidence

55 screenshot(s) captured during analysis. Showing 14. View all in CAPE

Screenshot 0001
frame 0001
Screenshot 0002
frame 0002
Screenshot 0004
frame 0004
Screenshot 0012
frame 0012
Screenshot 0013
frame 0013
Screenshot 0015
frame 0015
Screenshot 0016
frame 0016
Screenshot 0018
frame 0018
Screenshot 0022
frame 0022
Screenshot 0026
frame 0026
Screenshot 0029
frame 0029
Screenshot 0034
frame 0034
Screenshot 0045
frame 0045
Screenshot 0055
frame 0055

What the Sample Did (Plain English)

Scoring Breakdown — How we got from 10.0 to 0.20

Score Components

STRONG signatures0 signature(s), contributed 0.0
UNBACKED family (capped at 2.0)raw=0.0, applied=0.0
AMBIGUOUS re-amplification0 signature(s), contributed 0.0 (only fires when 2+ STRONG present)
UNKNOWN signatures (half weight)contributed 0.2
Detection floor applied?no
Final v0.2 Score0.20 / 10

STRONG Signatures (real malicious signal)

No strong signatures.

AMBIGUOUS Signatures (common on benign, can be real)

No ambiguous signatures.

UNBACKED Family (capped — common on asm/JIT code, can be real)

No unbacked signatures.

UNKNOWN Signatures (not yet classified, half weight)

SignatureSevWeightConfScore ΔDescription
amsi_enumeration31.040.0%0.2Enumerated Anti-Malware Scan Interface (AMSI) providers, a potential precursor to AMSI bypass or EDR unhooking

NOISE Signatures (suppressed, score = 0)

SignatureSevWeightConfScore ΔDescription
stealth_network11.0100.0%0.0Network activity detected but not expressed in monitor API logs
antivm_checks_available_memory11.0100.0%0.0Checks available memory
queries_keyboard_layout11.0100.0%0.0Queries the keyboard layout
queries_locale_api11.0100.0%0.0Queries the computer locale (possible geofencing)
antidebug_setunhandledexceptionfilter11.040.0%0.0SetUnhandledExceptionFilter detected (possible anti-debug)
driver_filtermanager11.0100.0%0.0Attempts to make use of the Filter Manager
stealth_timeout11.040.0%0.0Possible date expiration check, exits too soon after checking local time
language_check_registry11.0100.0%0.0Checks system language via registry key (possible geofencing)
privilege_elevation_check21.080.0%0.0Queries process token information to check for Administrator privileges or UAC elevation status
mountpoints_volume_discovery21.020.0%0.0Queries the mount points and then resolves volume paths to enumerate storage devices
dllload_suspicious_directory21.050.0%0.0A DLL was loaded from a suspicious directory
registers_vectored_exception_handler21.080.0%0.0Registers a vectored exception handler (VEH), possibly to hijack execution flow
creates_suspended_process21.050.0%0.0Creates a process in a suspended state, likely for injection
resumethread_remote_process21.0100.0%0.0Resumed a thread in another process
terminates_remote_process21.0100.0%0.0Terminates another process
discover_registry_mount_points21.020.0%0.0Queries registry mount points to identify historical or connected removable/network drives
antivm_generic_services31.0100.0%0.0Enumerates services, possibly for anti-virtualization

SHELL_HOST Signatures (suppressed for non-PE samples)

SignatureSevWeightConfScore ΔDescription
mouse_movement_detect21.0100.0%0.0Checks for mouse movement
File Details
File nameBC1-1D.msi
File typeComposite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Brand-Consulting Installer, Author: PURSLANE, Keywords: Installer, Comments: This installer database contains the logic and data required to install Brand-Consulting., Template: x64;1033, Revision Number: {84704059-8CA7-4BE0-9436-76AF5AFDCF98}, Create Time/Date: Mon Aug 4 14:32:42 2025, Last Saved Time/Date: Mon Aug 4 14:32:42 2025, Number of Pages: 500, Number of Words: 2, Name of Creating Application: WiX Toolset (4.0.5.0), Security: 2
Size (bytes)23732224
MD507f5af401b978b11476b8e03ecb61de7
SHA10ffaad2d925b2ea13774180bb27c99f6c51b5c5b
SHA2565a97c03750312f050b1ebe79546a1763184470213139fed9087c0d83fac8fb14
VirusTotalOpen in VirusTotal
Sandbox Run Details
Task ID50
Started2026-07-14 10:44:52
Ended2026-07-14 10:56:32
Duration (sec)700
Packagemsi
Routeinternet
Machinecuckoo2
Tech Override

No override active. The model verdict above is the current classification.

Report generated on 07-14-2026 10:57:03 by PBESANDBOX.PBESECURE.COM