Result for 07DF7599F7D74908569C7302CF7227A2FA382F0F

Query result

Key Value
FileName./usr/share/pyshared/pefile.py
FileSize139621
MD5671EBE1AE070B6EDE3BF993CB154258D
SHA-107DF7599F7D74908569C7302CF7227A2FA382F0F
SHA-256BAA9FB87F1071D8297557E2395AFA28834AEE9FD8E7AE01A1672974A5D94C164
SSDEEP3072:N16AIhSsoikp2d6/I82SLct4woVPzYiIgF6b6rDEU:N1LIhopMr82SQt4woVPzYiIgF6b6rDEU
TLSHT1F0D3A563F9223A669293A87E4456E0031765744B059C6C3C7CBC81642FA867CEEF3EF5
hashlookup:parent-total2
hashlookup:trust60

Network graph view

Parents (Total: 2)

The searched file hash is included in 2 parent files which include package known and seen by metalookup. A sample is included below:

Key Value
FileSize37830
MD549487AC4DDE6337EF5807297528B9DEF
PackageDescriptionPortable Executable (PE) parsing module for Python pefile is a Python module to read and work with Portable Executable (PE) files. Most of the information in the PE header is accessible, as well as all the sections, section information and data. . All the basic PE file structures are available with their default names as attributes of the returned instance. . Processed elements such as the import table are made available with lowercase names, to differentiate them from the upper case basic structure names. . pefile has been tested against the limits of valid PE headers; that is, Windows malware. Lots of packed malware attempt to abuse the format beyond its standard use. . Some of the tasks that pefile makes possible are: * Modifying and writing back to the PE image * Header inspection * Section analysis * Retrieving data * Warnings for suspicious and malformed values * Packer detection with PEiD signatures * PEiD signature generation
PackageMaintainerUbuntu Developers <ubuntu-devel-discuss@lists.ubuntu.com>
PackageNamepython-pefile
PackageSectionpython
PackageVersion1.2.9.1-1.1
SHA-152EDB52945D255D8EC388BB2591BF139128794DA
SHA-25668D9F6730C8722BD1038E73CB7CFF0302B7D7117C824BAB41F155069BEE0F1D7
Key Value
FileSize41134
MD5B433625B14C6BEB8F12AEC0E7482DE3E
PackageDescriptionPortable Executable (PE) parsing module for Python pefile is a Python module to read and work with Portable Executable (PE) files. Most of the information in the PE header is accessible, as well as all the sections, section information and data. . All the basic PE file structures are available with their default names as attributes of the returned instance. . Processed elements such as the import table are made available with lowercase names, to differentiate them from the upper case basic structure names. . pefile has been tested against the limits of valid PE headers; that is, Windows malware. Lots of packed malware attempt to abuse the format beyond its standard use. . Some of the tasks that pefile makes possible are: * Modifying and writing back to the PE image * Header inspection * Section analysis * Retrieving data * Warnings for suspicious and malformed values * Packer detection with PEiD signatures * PEiD signature generation
PackageMaintainerRobert S. Edmonds <edmonds@debian.org>
PackageNamepython-pefile
PackageSectionpython
PackageVersion1.2.9.1-1.1
SHA-1EC69A8A839ADCE99EE3DF2374C400BE50BA4277C
SHA-256A53604AA2F71F2867E59F747C5EC8DF6E07A826E127E06874FE38A6B4C230012