Is Tickle Prison Laboratory.exe safe?
No engine detected malware, and the completed sandbox run showed no offensive activity, persistence, dropped payloads, packing, or network communication.
The file produced 0 detections across 75 antivirus engines, including no tier-1 alerts. One completed sandbox run found no offensive techniques, persistence, dropped files, or network contacts, while static analysis found no packing or high-entropy code; the main limitation is that the executable is unsigned.
77f20c7efe32feadbb…df80c6db86faf1Recommended next actions
Before running
Run it only when it came from the developer's official site or another source you independently trust.
If you already ran it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The file produced 0 detections across 75 antivirus engines, including no tier-1 alerts. One completed sandbox run found no offensive techniques, persistence, dropped files, or network contacts, while static analysis found no packing or high-entropy code; the main limitation is that the executable is unsigned.
The antivirus results are consistently benign, with 0 of 75 engines reporting either malware or suspicious content and 11 tier-1 engines returning no detection. A completed sandbox run recorded only five benign-common techniques, no offensive techniques, no persistence, no written files, and no network contacts. Static PE analysis found no packer, no likely packing, and no high-entropy code. The file has also accumulated 104 submissions from 95 sources over 322 days without acquiring detections. Its unsigned status prevents publisher authentication, and no separate host-reputation result was saved, but neither limitation supplies affirmative evidence of harmful activity.
What We Detected
None of the 75 antivirus engines flagged this executable as malicious or suspicious. Eleven tier-1 engines completed their checks without a detection, while several others timed out and therefore contributed no conclusion.
Threat Behavior
One completed sandbox run recorded no offensive techniques, persistence indicators, dropped files, or network contacts. Static PE inspection also found no identified packer, no likely packing, and no high-entropy code. No complete contacted-host reputation cross-check was saved, although the observed run contained no domains, IP addresses, or URLs to evaluate.
What To Do Now
The evidence does not show malware activity. Because the executable is unsigned, obtain it from the expected official source, verify its SHA-256 hash where possible, and keep endpoint protection enabled when opening it.
Where this verdict could be wrong3 caveats
- signing.signed=false for a Win32 executable, leaving its publisher and origin unauthenticated.
- contactedHosts=null means no saved host-reputation cross-check is available, although the observed sandbox run recorded no contacted domains, IPs, or URLs.
- Nine engine scans timed out, including Avast, BitDefender, ESET-NOD32, and Emsisoft, so not every engine completed analysis.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/75 engines reported malicious or suspicious content.
- 11 tier-1 engines completed analysis without a detection.
- One sandbox run recorded 0 offensive techniques and no malicious verdict.
- No persistence indicators, dropped hashes, or written files were observed.
- peAnalysis found no packer, high-entropy code, or likely packing.
- The Win32 executable is unsigned, so its publisher cannot be authenticated.
- Nine engine scans timed out, including several tier-1 products.
- No complete contacted-host reputation cross-check was saved.
Use the file only if it came from the expected source, since it lacks a verifiable publisher signature. Keep endpoint protection enabled and compare SHA-256 77f20c7efe32feadbb0bb59e1a4b78c64fa003f5505239d6b1df80c6db86faf1 with the distributor's published hash if available.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
PartialIndependent reference checks were attempted but are incomplete.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 5MITRE ATT&CK techniques
- 1spawned processes
- 0network contacts
- 0filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 0 / 75engines flagged
- 95sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 75 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
One or more independent reference checks were incomplete or unavailable.
ProvenanceDerivedSourceExternal-intelligence coverageObserved at - 03
The hash has been submitted 104 times from 95 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: Tickle Prison Laboratory.exe — 77f20c7efe32feadbb0bb59e1a4b78c64fa003f5505239d6b1df80c6db86faf1
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\user\Desktop\Tickle Prison Laboratory.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
Available reference checks returned no match, but at least one source was unavailable. This is not a clean result.
YARA rules
No matchesThe rule pass completed without a saved public match.
0 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- Tickle Prison Laboratory.exe
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 638.5 KB
- Last analyzed
- Oct 7, 2026, 7:45 AM UTC
77f20c7efe32feadbb0bb59e1a4b78c64fa003f5505239d6b1df80c6db86faf1Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Run it only when it came from the developer's official site or another source you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Tickle Prison Laboratory.exe safe?
What is Tickle Prison Laboratory.exe?
How many antivirus engines detected Tickle Prison Laboratory.exe?
What is the SHA-256 hash of Tickle Prison Laboratory.exe?
Is it safe to run Tickle Prison Laboratory.exe?
How up to date is this analysis of Tickle Prison Laboratory.exe?
Community
Member reviews and reports for this exact file hash.