Is py_more_cells_mod_v2.2.zip safe?
No antivirus engine detected the ZIP, including 17 tier-1 engines, though its recent appearance and absent runtime analysis warrant ordinary caution.
All 74 antivirus engines returned no malicious or suspicious detection, with 17 tier-1 engines among those reporting no detection. The archive is only three days old, and no sandbox run or complete contacted-host check is available, so inspect its extracted contents before opening them.
f478e55f5deea4f616…0abed44df77190Recommended next actions
Before opening or extracting
Open or extract it only when its sender or download source has been independently verified.
If you already opened or extracted it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 74 antivirus engines returned no malicious or suspicious detection, with 17 tier-1 engines among those reporting no detection. The archive is only three days old, and no sandbox run or complete contacted-host check is available, so inspect its extracted contents before opening them.
Static scanning produced no malicious or suspicious result from 74 engines. Seventeen tier-1 engines, including BitDefender, ESET, Kaspersky, and Microsoft, reported no detection. Code-signing evidence does not apply to a ZIP archive, so its absence carries no negative weight. The file is newly observed with only three submissions, limiting the strength of its reputation. No completed runtime observation or complete host-reputation result is available, and two external-intelligence checks were skipped. Overall, the available static evidence strongly favors ordinary mod-archive content, with residual uncertainty about anything executed after extraction.
What We Detected
No malicious or suspicious detections were reported by any of the 74 antivirus engines. This includes 17 tier-1 engines such as BitDefender, ESET-NOD32, Kaspersky, and Microsoft. No threat family or hacktool label was identified.
Threat Behavior
No completed sandbox observation is available, so the behavior of extracted files was not observed. A complete contacted-host reputation result is also unavailable. The archive is newly observed and has appeared in only three submissions, which limits historical assurance.
What To Do Now
Obtain the mod from its official project or community release page and verify the SHA-256 hash when the publisher provides one. Keep endpoint protection enabled, scan the extracted contents, and review scripts or executables before running them.
Where this verdict could be wrong3 caveats
- prevalence.classification=rare_new means the archive has only a short, limited reputation history.
- behaviour=null leaves any code inside the ZIP unobserved at runtime.
- externalIntel.availability shows YARAify and MalwareBazaar were skipped, and similarHashes contains no prior matches.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/74 engines reported malicious
- 0/74 engines reported suspicious
- 17 tier-1 engines reported no detection
- No confirmed hacktool label
- No brand mismatch detected
- Only three days of observed history
- Three submissions from three sources
- No completed runtime analysis
- No complete contacted-host reputation check
- No similar-hash history
- YARAify and MalwareBazaar checks were skipped
Use the archive only if it came from the mod's official distribution channel. Keep protection enabled and scan all extracted files before opening or executing them.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
PartialIndependent reference checks were attempted but are incomplete.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 0 / 74engines flagged
- 3sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 74 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
One or more independent reference checks were incomplete or unavailable.
ProvenanceDerivedSourceExternal-intelligence coverageObserved at - 03
No completed runtime observation is available for this file.
ProvenanceDerivedSourceRuntime coverageObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
Available reference checks returned no match, but at least one source was unavailable. This is not a clean result.
YARA rules
No matchesThe rule pass completed without a saved public match.
0 of 74 engines flagged this file
View all 74 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Barely seen in the wild and first surfaced recently. That limits reputation evidence, but rarity alone is not proof of malware.
Fingerprint and provenance
- File name
- py_more_cells_mod_v2.2.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 394.8 KB
- Last analyzed
- Sep 17, 2026, 9:20 PM UTC
f478e55f5deea4f616b207633482bfc9ed803facf45ed30f030abed44df77190Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open or extract it only when its sender or download source has been independently verified.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is py_more_cells_mod_v2.2.zip safe?
What is py_more_cells_mod_v2.2.zip?
How many antivirus engines detected py_more_cells_mod_v2.2.zip?
What is the SHA-256 hash of py_more_cells_mod_v2.2.zip?
Is it safe to open or extract py_more_cells_mod_v2.2.zip?
How up to date is this analysis of py_more_cells_mod_v2.2.zip?
Community
Member reviews and reports for this exact file hash.