Disposition
Recommended action: No CAPE indicators were found after filtering. Release is reasonable if the source matches user expectation.
This disposition is based on the v0.2 scoring model calibrated against benign Microsoft binaries. It is informational, not a guarantee.
Drafted for the requester. Adjust greeting/closing as needed.
Thanks for checking with us on BC1-1D.msi before you opened it.
IT ran the file in our analysis sandbox for 11 minute(s) and 40 seconds. Our analysis rated this at 0.20 out of 10, which we classify as Clean (high confidence). During the analysis, the file launched 13 process(es), contacted 85 network indicator(s), dropped 4 additional file(s).
Based on what we observed, this file is reasonable to open if it came from a source you recognize and expected.
Please continue to forward anything you are unsure about. Catching it before you open is exactly the right move.
PBE IT Security
| STRONG signatures | 0 signature(s), contributed 0.0 |
|---|---|
| UNBACKED family (capped at 2.0) | raw=0.0, applied=0.0 |
| AMBIGUOUS re-amplification | 0 signature(s), contributed 0.0 (only fires when 2+ STRONG present) |
| UNKNOWN signatures (half weight) | contributed 0.2 |
| Detection floor applied? | no |
| Final v0.2 Score | 0.20 / 10 |
No strong signatures.
No ambiguous signatures.
No unbacked signatures.
| Signature | Sev | Weight | Conf | Score Δ | Description |
|---|---|---|---|---|---|
amsi_enumeration | 3 | 1.0 | 40.0% | 0.2 | Enumerated Anti-Malware Scan Interface (AMSI) providers, a potential precursor to AMSI bypass or EDR unhooking |
| Signature | Sev | Weight | Conf | Score Δ | Description |
|---|---|---|---|---|---|
stealth_network | 1 | 1.0 | 100.0% | 0.0 | Network activity detected but not expressed in monitor API logs |
antivm_checks_available_memory | 1 | 1.0 | 100.0% | 0.0 | Checks available memory |
queries_keyboard_layout | 1 | 1.0 | 100.0% | 0.0 | Queries the keyboard layout |
queries_locale_api | 1 | 1.0 | 100.0% | 0.0 | Queries the computer locale (possible geofencing) |
antidebug_setunhandledexceptionfilter | 1 | 1.0 | 40.0% | 0.0 | SetUnhandledExceptionFilter detected (possible anti-debug) |
driver_filtermanager | 1 | 1.0 | 100.0% | 0.0 | Attempts to make use of the Filter Manager |
stealth_timeout | 1 | 1.0 | 40.0% | 0.0 | Possible date expiration check, exits too soon after checking local time |
language_check_registry | 1 | 1.0 | 100.0% | 0.0 | Checks system language via registry key (possible geofencing) |
privilege_elevation_check | 2 | 1.0 | 80.0% | 0.0 | Queries process token information to check for Administrator privileges or UAC elevation status |
mountpoints_volume_discovery | 2 | 1.0 | 20.0% | 0.0 | Queries the mount points and then resolves volume paths to enumerate storage devices |
dllload_suspicious_directory | 2 | 1.0 | 50.0% | 0.0 | A DLL was loaded from a suspicious directory |
registers_vectored_exception_handler | 2 | 1.0 | 80.0% | 0.0 | Registers a vectored exception handler (VEH), possibly to hijack execution flow |
creates_suspended_process | 2 | 1.0 | 50.0% | 0.0 | Creates a process in a suspended state, likely for injection |
resumethread_remote_process | 2 | 1.0 | 100.0% | 0.0 | Resumed a thread in another process |
terminates_remote_process | 2 | 1.0 | 100.0% | 0.0 | Terminates another process |
discover_registry_mount_points | 2 | 1.0 | 20.0% | 0.0 | Queries registry mount points to identify historical or connected removable/network drives |
antivm_generic_services | 3 | 1.0 | 100.0% | 0.0 | Enumerates services, possibly for anti-virtualization |
| Signature | Sev | Weight | Conf | Score Δ | Description |
|---|---|---|---|---|---|
mouse_movement_detect | 2 | 1.0 | 100.0% | 0.0 | Checks for mouse movement |
| File name | BC1-1D.msi |
|---|---|
| File type | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Brand-Consulting Installer, Author: PURSLANE, Keywords: Installer, Comments: This installer database contains the logic and data required to install Brand-Consulting., Template: x64;1033, Revision Number: {84704059-8CA7-4BE0-9436-76AF5AFDCF98}, Create Time/Date: Mon Aug 4 14:32:42 2025, Last Saved Time/Date: Mon Aug 4 14:32:42 2025, Number of Pages: 500, Number of Words: 2, Name of Creating Application: WiX Toolset (4.0.5.0), Security: 2 |
| Size (bytes) | 23732224 |
| MD5 | 07f5af401b978b11476b8e03ecb61de7 |
| SHA1 | 0ffaad2d925b2ea13774180bb27c99f6c51b5c5b |
| SHA256 | 5a97c03750312f050b1ebe79546a1763184470213139fed9087c0d83fac8fb14 |
| VirusTotal | Open in VirusTotal |
| Task ID | 50 |
|---|---|
| Started | 2026-07-14 10:44:52 |
| Ended | 2026-07-14 10:56:32 |
| Duration (sec) | 700 |
| Package | msi |
| Route | internet |
| Machine | cuckoo2 |
No override active. The model verdict above is the current classification.
Report generated on 07-14-2026 10:57:03 by PBESANDBOX.PBESECURE.COM