Result for 1153F6576E34C3CED0BEA53EF983DFBA793FD0EC

Query result

Key Value
CRC321E422650
FileName./usr/lib/python2.7/dist-packages/peframe/modules/help.py
FileSize2062
MD5EEDC7BC2D220DCEBA7199C778BA14FF7
OpSystemCode{'MfgCode': '1006', 'OpSystemCode': '362', 'OpSystemName': 'TBD', 'OpSystemVersion': 'none'}
ProductCode{'ApplicationType': 'Operating System', 'Language': 'English', 'MfgCode': '1722', 'OpSystemCode': '599', 'ProductCode': '163709', 'ProductName': 'BlackArch Linux', 'ProductVersion': '2017.03.01'}
SHA-11153F6576E34C3CED0BEA53EF983DFBA793FD0EC
SHA-25656A7B875E6FA6B1A7E88BB3C8E64EA0B9E48B0A16B34F79BAA2972B42517BF28
SSDEEP48:7WAhJMlwEbTGQHW10s5PxTzj1FfjZsgtobgGRMVRes5bmf:7WbneQHWNRn+EobgGyVws5bmf
SpecialCode
TLSHT15A41A617BE0A13211A5BCB96AD907D9AF207E36B76B63D594076E351233186840FD808
dbnsrl_modern_rds
insert-timestamp1646984268.3682497
sourceNSRL
hashlookup:parent-total3
hashlookup:trust65

Network graph view

Parents (Total: 3)

The searched file hash is included in 3 parent files which include package known and seen by metalookup. A sample is included below:

Key Value
FileSize144884
MD5D79C047AE73AF45F9F79C5195D291A87
PackageDescriptionopen source tool to perform static analysis on PE malware PEframe is a open source tool to perform static analysis on Portable Executable malware and generic suspicious files. It can help malware researchers to detect packer, xor, digital signature, mutex, anti debug, anti virtual machine, suspicious sections and functions, and much more information about the suspicious files.
PackageMaintainerSascha Steinbiss <satta@debian.org>
PackageNamepeframe
PackageSectionutils
PackageVersion5.0.1+git20170303.0.e482def+dfsg-1~bpo9+1
SHA-13E6A89FD597C0E4465AD3273DC429749AAB1218E
SHA-256B46773004D3784164A8ADD3F55A845FB4738275B4803666F400D8B5374C4BF9B
Key Value
FileSize142620
MD59A35E73A7BB58C6F99583A446371AE90
PackageDescriptionopen source tool to perform static analysis on PE malware PEframe is a open source tool to perform static analysis on Portable Executable malware and generic suspicious files. It can help malware researchers to detect packer, xor, digital signature, mutex, anti debug, anti virtual machine, suspicious sections and functions, and much more information about the suspicious files.
PackageMaintainerSascha Steinbiss <satta@debian.org>
PackageNamepeframe
PackageSectionutils
PackageVersion5.0.1+git20170303.0.e482def+dfsg-3
SHA-1069C86B4EEC137A3E48211BD3A93AE6C45DF8E4C
SHA-256A48E808D942DD7CA332699E35E0B25EC1DD451F81F55EB0F72BD6F9DFBC08015
Key Value
FileSize144248
MD58E285E04DFF0C3DCF15864F8B39B2DB9
PackageDescriptionopen source tool to perform static analysis on PE malware PEframe is a open source tool to perform static analysis on Portable Executable malware and generic suspicious files. It can help malware researchers to detect packer, xor, digital signature, mutex, anti debug, anti virtual machine, suspicious sections and functions, and much more information about the suspicious files.
PackageMaintainerUbuntu Developers <ubuntu-devel-discuss@lists.ubuntu.com>
PackageNamepeframe
PackageSectionutils
PackageVersion5.0.1+git20170303.0.e482def+dfsg-1
SHA-164D201C7AACD3E9924501C4A4ACD4192FEA04892
SHA-2562E70D9D84F9258B20DBABE4CD5C520EE15C729261A4662BFA45671C012318D89