Key | Value |
---|---|
FileSize | 142620 |
MD5 | 9A35E73A7BB58C6F99583A446371AE90 |
PackageDescription | open source tool to perform static analysis on PE malware PEframe is a open source tool to perform static analysis on Portable Executable malware and generic suspicious files. It can help malware researchers to detect packer, xor, digital signature, mutex, anti debug, anti virtual machine, suspicious sections and functions, and much more information about the suspicious files. |
PackageMaintainer | Sascha Steinbiss <satta@debian.org> |
PackageName | peframe |
PackageSection | utils |
PackageVersion | 5.0.1+git20170303.0.e482def+dfsg-3 |
SHA-1 | 069C86B4EEC137A3E48211BD3A93AE6C45DF8E4C |
SHA-256 | A48E808D942DD7CA332699E35E0B25EC1DD451F81F55EB0F72BD6F9DFBC08015 |
hashlookup:children-total | 44 |
hashlookup:trust | 50 |
The searched file hash includes 44 children files known and seen by metalookup. A sample is included below:
Key | Value |
---|---|
CRC32 | 3A2720ED |
FileName | ws2_32.py |
FileSize | 3032 |
MD5 | 55E027063196AF2B10E977AA0FFA753B |
OpSystemCode | 362 |
ProductCode | 17409 |
RDS:package_id | 222721 |
SHA-1 | 03A0892D22997DCDE7EE1A551D5AA43CEDE5B671 |
SHA-256 | F9ED386E469089297D620FBE0436B7D736C4068960D76900EF6A109ECB3DCABE |
SSDEEP | 48:dBP+VvcLTspKQqUyIhVldouQQ6IbWE6Zx8B0qMZ/jfexRsByhz4eUtrfrtEh6ltJ:n2zXdoNQ6IWTZx8BXMZLexKByhEeUtr/ |
SpecialCode | |
TLSH | T11F513B30665E89AF10C9FE02AF5E94365C09134B9C173875FBD90ACA4F6ED0CB6F5622 |
db | nsrl_modern_rds |
insert-timestamp | 1727040564.6444898 |
source | RDS.db |
tar:gname | wheel |
tar:uname | root |
Key | Value |
---|---|
CRC32 | 7689CCBA |
FileName | ./usr/lib/python2.7/dist-packages/peframe-5.0.1.egg-info/top_level.txt |
FileSize | 8 |
MD5 | 1B61C7688A5A736661D1E55BF7AAADDD |
OpSystemCode | 362 |
ProductCode | 163709 |
RDS:package_id | 294806 |
SHA-1 | 091D7B1D5DE2735E8E56FF2BEF915F8261B0B396 |
SHA-256 | BF6A379FBA1F51EAD6604F27E88E5F733CA1522DC86F8202E0CBBB98C5B423DF |
SSDEEP | 3:aon:l |
SpecialCode | |
TLSH | |
db | nsrl_modern_rds |
insert-timestamp | 1696437670.156451 |
source | db.sqlite |
tar:gname | root |
tar:uname | root |
Key | Value |
---|---|
CRC32 | 1E422650 |
FileName | ./usr/lib/python2.7/dist-packages/peframe/modules/help.py |
FileSize | 2062 |
MD5 | EEDC7BC2D220DCEBA7199C778BA14FF7 |
OpSystemCode | 362 |
ProductCode | 163709 |
SHA-1 | 1153F6576E34C3CED0BEA53EF983DFBA793FD0EC |
SHA-256 | 56A7B875E6FA6B1A7E88BB3C8E64EA0B9E48B0A16B34F79BAA2972B42517BF28 |
SSDEEP | 48:7WAhJMlwEbTGQHW10s5PxTzj1FfjZsgtobgGRMVRes5bmf:7WbneQHWNRn+EobgGyVws5bmf |
SpecialCode | |
TLSH | T15A41A617BE0A13211A5BCB96AD907D9AF207E36B76B63D594076E351233186840FD808 |
db | nsrl_modern_rds |
insert-timestamp | 1646984268.3682497 |
source | NSRL |
Key | Value |
---|---|
CRC32 | 8C30A5E1 |
FileName | ./usr/lib/python2.7/dist-packages/peframe/modules/strings.py |
FileSize | 1430 |
MD5 | 272FA6A23C93912EFB805985729637FD |
OpSystemCode | 362 |
ProductCode | 163709 |
SHA-1 | 1526C20238DFC635FA6D7AD83F700432F3B7E013 |
SHA-256 | FF516BF09E4DBCA5DD94FA6A9C762281587A5F2C245A14845ABEECB096894CC2 |
SSDEEP | 24:7SZ2ySCUuiyUVOkHxHqTbVcbyn1f3tnGJkD:75vz9yUjHoV9nckD |
SpecialCode | |
TLSH | T19021320E1C01477ED884C5BC2A8A52FBE34966533BB82030384DA7686F1B9B314FD9DC |
db | nsrl_modern_rds |
insert-timestamp | 1646985920.7226727 |
source | NSRL |
Key | Value |
---|---|
CRC32 | 04199F97 |
FileName | ./usr/lib/python2.7/dist-packages/peframe/modules/stdoutput.py |
FileSize | 6708 |
MD5 | DA93390236B09E38664417AC0ACF8568 |
OpSystemCode | 362 |
ProductCode | 163709 |
SHA-1 | 1ADA7EFAD884859B2BC12863064286781121D267 |
SHA-256 | C3883F6F8643D5F1D16215CA9C08863514F17024016EFAF1E22CE248A94C09EC |
SSDEEP | 192:7lJYj2X+9fm5f6R2F6RkZeVtPd0ZcAnXyO+YSZoHG:7lJ9X+9f8yoU6YdWcAXT+YSZoHG |
SpecialCode | |
TLSH | T1E9D123279F4C946F405AEAEEC50A424BEA4FC0B751B4B8636C58873C1B6207763BD0E5 |
db | nsrl_modern_rds |
insert-timestamp | 1646988482.2756414 |
source | NSRL |
Key | Value |
---|---|
CRC32 | DD85CE85 |
FileName | ./usr/lib/python2.7/dist-packages/peframe/modules/stringstat.py |
FileSize | 3048 |
MD5 | FE1C8A48C989DD754A76FE0E511EB6D7 |
OpSystemCode | 362 |
ProductCode | 163709 |
SHA-1 | 2BE38E62BB11A07FFC20830E5CCFFB1B25FBEDBD |
SHA-256 | 0EF359C6BCC187072C56B67D1012FD44BBF054FFFE986B65AFE2678107B7F513 |
SSDEEP | 48:3AhJMlwEbTGQHW10s5PxTzj1FpXSrPyzT3bcVaxf0Q3oPjhpwJgZ:3bneQHWNRxCrPiL4VaRx3Us2Z |
SpecialCode | |
TLSH | T1C751B6CCED5E3256BB45EA595084B80DF24DB1B7662F7550ACD8E3385328412F1FD40D |
db | nsrl_modern_rds |
insert-timestamp | 1646994758.4304545 |
source | NSRL |
Key | Value |
---|---|
FileName | ./usr/share/doc/peframe/changelog.gz |
FileSize | 569 |
MD5 | EA03F47C9BE8818CBC0D3DB97C108667 |
SHA-1 | 4B497D91CCF771409001F4C623B8DE0ECF3C13FC |
SHA-256 | 57739F1C9FB269076E8E4494CDD4D9D05DCF36CA237D019032B5576E5E4B261C |
SSDEEP | 12:X+u1wwiZ0Ah0RkxPi0KcvJv0H49QwA+RA5Vn7dLl92RtToExib6Ko7J:X+OwfZ4RkxPibchMHNMAT7dLmRtTPA+v |
TLSH | T143F09614290994D889C37B3511B4A588797EFB5C4A07DBD12B333033D56CDE91225C3A |
Key | Value |
---|---|
CRC32 | 923F26A5 |
FileName | ./usr/lib/python2.7/dist-packages/peframe/modules/sections.py |
FileSize | 1973 |
MD5 | 43661DE95A5873A377BE6AB33CA11195 |
OpSystemCode | 362 |
ProductCode | 163709 |
SHA-1 | 537D008A4ECC542C32A6133A78068E554BF2B2EE |
SHA-256 | B7044F2851364E8BB9411792A1AED5C6175C2A59DF9722C1EFDC85B1F2060D15 |
SSDEEP | 48:7WAhJMlwEbTGQHW10s5PxTzj1F4KX260ob0hTzXM6N4:7WbneQHWNR59FMTbM6N4 |
SpecialCode | |
TLSH | T15341B3883E25737504A7E2B6B9925534F336A20C752F2100687DE6146B3E46F60FF8BE |
db | nsrl_modern_rds |
insert-timestamp | 1647009156.577921 |
source | NSRL |
Key | Value |
---|---|
CRC32 | B60FB280 |
FileName | ./usr/lib/python2.7/dist-packages/peframe/modules/loadfile.py |
FileSize | 1090 |
MD5 | 258D523D8B94F057625B631175B6F7E5 |
OpSystemCode | 362 |
ProductCode | 163709 |
SHA-1 | 539CF5171EFEECF000569E4F804F9C2A5D67F320 |
SHA-256 | 3ADD381A24C70EB68EF61697B7BDD356C5FA6CF1BE85F60ABACA3AC65E0D7759 |
SSDEEP | 24:7SZ2ySCUuiyUVOkHxHqTbVcbyKRlIi+C/yCKalA:75vz9yUjH06qP |
SpecialCode | |
TLSH | T10811214E6C02EB7BCA80C29A384612DFF24AD6E375DC54240846975A700593324FD5EC |
db | nsrl_modern_rds |
insert-timestamp | 1647009196.826592 |
source | NSRL |
Key | Value |
---|---|
CRC32 | 83E84FF2 |
FileName | oleaut32.py |
FileSize | 10081 |
MD5 | F54663127490F7A68E827B0C6EC10AFC |
OpSystemCode | 362 |
ProductCode | 17409 |
RDS:package_id | 222721 |
SHA-1 | 56B892E94CE466A626812BFD4AB8A29697DF1C01 |
SHA-256 | AC731DD6E3D17E2A3074A58312E329D1B21FFE66C271C346FE44353951BBDBCC |
SSDEEP | 192:7ReJs4jmZYXqIlwnqF0YeJftynZhZEADq3rk7D+xOugOtTjF32CYQUTBmOWEREpu:teW2sYXqIlwnqF9eJftyW7k7DTg1jF3G |
SpecialCode | |
TLSH | T14B222F35A80B1CC9606DEB90284C51291C19FB9BDD31B45DBA88DD8D8F4C90C6BFD2FA |
db | nsrl_modern_rds |
insert-timestamp | 1727040564.6489794 |
source | RDS.db |
tar:gname | wheel |
tar:uname | root |