Is Degrees of Lewdity 0.5.12.13.zip safe?
No antivirus engine detected the archive, and one sandbox run found no malicious outcome, though isolated evasion-like indicators warrant normal download precautions.
The archive drew 0 detections from 74 antivirus engines, including no tier-1 alerts, and its completed sandbox run produced no malicious verdict or persistence. An evasion-related technique and two behavioral tags are mild counter-signals, but they lack corroboration from engines, threat intelligence, child detections, or network activity.
d513df52983187bbbf…524b7bb7822e69Recommended next actions
Before opening or extracting
Open or extract it only when its sender or download source has been independently verified.
If you already opened or extracted it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The archive drew 0 detections from 74 antivirus engines, including no tier-1 alerts, and its completed sandbox run produced no malicious verdict or persistence. An evasion-related technique and two behavioral tags are mild counter-signals, but they lack corroboration from engines, threat intelligence, child detections, or network activity.
The strongest evidence is the complete absence of malicious or suspicious results across 74 antivirus engines, with 14 tier-1 engines reporting no detection. One completed sandbox run extracted the ZIP and observed no malicious verdict, persistence, registry changes, or network contacts. No YARAify, MalwareBazaar, or CIRCL match independently associates the hash with malware. T1562.001 and the detect-debug-environment and long-sleeps tags deserve caution, but they are isolated and can reflect sandbox-aware content or analysis artifacts. The ten extracted children remain individually unresolved, and no complete host-reputation check was saved, so the evidence is reassuring rather than absolute.
What We Detected
The archive received 0 malicious and 0 suspicious results from 74 antivirus engines. Fourteen tier-1 engines reported no detection, and no engine supplied a malware-family label. YARAify returned zero matching rules, while MalwareBazaar and CIRCL had no record for this hash.
Threat Behavior
One completed sandbox run extracted the ZIP and wrote an HTML file and related content. It produced no malicious sandbox verdict, persistence indicators, registry changes, or recorded domain, IP, or URL contacts. The run did associate the sample with T1562.001, and the file carries detect-debug-environment and long-sleeps tags; these are cautionary but are not corroborated by other threat evidence. Ten extracted children were inspected without a malicious child being identified, although their individual verdicts remain unknown. No complete contacted-host reputation result is available.
What To Do Now
Use the archive only if it came from the expected project or release channel, and keep endpoint protection enabled while extracting or opening it. If the source is unfamiliar or the contents differ from the expected HTML package, discard it and obtain a fresh copy from the official distribution point.
Where this verdict could be wrong3 caveats
- T1562.001 and the detect-debug-environment and long-sleeps tags can indicate evasion, although no engine detection or malicious sandbox verdict corroborates that interpretation.
- droppedChildren.rollup shows 10 unknown child verdicts; hasMaliciousChild=false therefore does not establish that every extracted component is benign.
- contactedHosts=null means no saved host-reputation cross-check is available.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/74 antivirus engines reported a malicious or suspicious result.
- engines.tier1Malicious=0, with 14 tier-1 engines reporting no detection.
- behaviour.hasMaliciousSandboxVerdict=false in one completed sandbox run.
- No persistence, registry modification, or network contacts were recorded.
- No YARAify, MalwareBazaar, or CIRCL threat-intelligence hit was found.
- behaviour.offensiveTechniques includes T1562.001.
- file.tags includes detect-debug-environment and long-sleeps.
- The archive was first submitted only 3 days ago.
- All 10 extracted child verdicts remain unknown.
- contactedHosts is null, so no complete host-reputation result is available.
Confirm that the ZIP came from the expected release channel, then keep endpoint protection enabled while extracting it. Avoid opening unexpected scripts or executables if its contents differ from the anticipated HTML package.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 4MITRE ATT&CK techniques
- 3spawned processes
- 0network contacts
- 6filesystem & mutex artifacts
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
Degrees of Lewdity 0.5.12.13.zip
d513df52983187bbbff94ae2e9f8dc06ba7adea8d12ecc4b75524b7bb7822e69
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
C:\Windows\SysWOW64\unarchiver.exe "C:\Windows\SysWow64\unarchiver.exe" "C:\Users\user\Desktop\Degrees of Lewdity 0.5.12.13.zip"
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\SysWOW64\7za.exe "C:\Windows\System32\7za.exe" x -pinfected -y -o"C:\Users\user\AppData\Local\Temp\hammjcoc.u0k" "C:\Users\user\Desktop\Degrees of Lewdity 0.5.12.13.zip"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
hammjcoc.u0k
C:\Users\user\AppData\Local\Temp\hammjcoc.u0k
04Isolated runtime analysis - Written fileObserved
Degrees of Lewdity
C:\Users\user\AppData\Local\Temp\hammjcoc.u0k\Degrees of Lewdity
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
5 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\Users\user\AppData\Local\Temp\hammjcoc.u0k
- C:\Users\user\AppData\Local\Temp\hammjcoc.u0k\Degrees of Lewdity
- C:\Users\user\AppData\Local\Temp\hammjcoc.u0k\Degrees of Lewdity\Degrees of Lewdity 0.5.12.13.html
- C:\Users\user\AppData\Local\Temp\unarchiver.log
- \Device\ConDrv\\Connect
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- c1c2ede0d01a1596b14a…2eaa36Never scannednever seen before
- c7853ebbbc53974fcbbe…030554Never scannednever seen before
- 380c3edfdf3e0b5cf990…573d2fNever scannednever seen before
- 02d38c9e3009760f91c2…82fbb6Never scannednever seen before
- 32e05a83b687c0d085fd…e297e3Never scannednever seen before
- 1cb8c3cb2199ded7a8cf…de2b6cNever scannednever seen before
- 0a536edb82665c8806c4…dab933Never scannednever seen before
- bbe66ab9e9ec4cca0654…739f9fNever scannednever seen before
- e3ce895e8290c1eb9a7f…324305Never scannednever seen before
- 6a7a8aeadb216e9fd1a1…be5f18Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 0 / 74engines flagged
- 14sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 74 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 14 times from 14 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: Degrees of Lewdity 0.5.12.13.zip — d513df52983187bbbff94ae2e9f8dc06ba7adea8d12ecc4b75524b7bb7822e69
ProvenanceObservedSourceUploaded fileObserved at - 04
Observed process — C:\Windows\SysWOW64\unarchiver.exe "C:\Windows\SysWow64\unarchiver.exe" "C:\Users\user\Desktop\Degrees of Lewdity 0.5.12.13.zip"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 05
Observed process — C:\Windows\SysWOW64\7za.exe "C:\Windows\System32\7za.exe" x -pinfected -y -o"C:\Users\user\AppData\Local\Temp\hammjcoc.u0k" "C:\Users\user\Desktop\Degrees of Lewdity 0.5.12.13.zip"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
File written: hammjcoc.u0k — C:\Users\user\AppData\Local\Temp\hammjcoc.u0k
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Degrees of Lewdity — C:\Users\user\AppData\Local\Temp\hammjcoc.u0k\Degrees of Lewdity
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
0 of 74 engines flagged this file
View all 74 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- Degrees of Lewdity 0.5.12.13.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 23.5 MB
- Last analyzed
- Sep 20, 2026, 7:58 PM UTC
d513df52983187bbbff94ae2e9f8dc06ba7adea8d12ecc4b75524b7bb7822e69Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open or extract it only when its sender or download source has been independently verified.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Degrees of Lewdity 0.5.12.13.zip safe?
What is Degrees of Lewdity 0.5.12.13.zip?
How many antivirus engines detected Degrees of Lewdity 0.5.12.13.zip?
What is the SHA-256 hash of Degrees of Lewdity 0.5.12.13.zip?
Is it safe to open or extract Degrees of Lewdity 0.5.12.13.zip?
How up to date is this analysis of Degrees of Lewdity 0.5.12.13.zip?
Community
Member reviews and reports for this exact file hash.