Key | Value |
---|---|
CRC32 | 8C30A5E1 |
FileName | ./usr/lib/python2.7/dist-packages/peframe/modules/strings.py |
FileSize | 1430 |
MD5 | 272FA6A23C93912EFB805985729637FD |
OpSystemCode | {'MfgCode': '1006', 'OpSystemCode': '362', 'OpSystemName': 'TBD', 'OpSystemVersion': 'none'} |
ProductCode | {'ApplicationType': 'Operating System', 'Language': 'English', 'MfgCode': '1722', 'OpSystemCode': '599', 'ProductCode': '163709', 'ProductName': 'BlackArch Linux', 'ProductVersion': '2017.03.01'} |
SHA-1 | 1526C20238DFC635FA6D7AD83F700432F3B7E013 |
SHA-256 | FF516BF09E4DBCA5DD94FA6A9C762281587A5F2C245A14845ABEECB096894CC2 |
SSDEEP | 24:7SZ2ySCUuiyUVOkHxHqTbVcbyn1f3tnGJkD:75vz9yUjHoV9nckD |
SpecialCode | |
TLSH | T19021320E1C01477ED884C5BC2A8A52FBE34966533BB82030384DA7686F1B9B314FD9DC |
db | nsrl_modern_rds |
insert-timestamp | 1646985920.7226727 |
source | NSRL |
hashlookup:parent-total | 3 |
hashlookup:trust | 65 |
The searched file hash is included in 3 parent files which include package known and seen by metalookup. A sample is included below:
Key | Value |
---|---|
FileSize | 144884 |
MD5 | D79C047AE73AF45F9F79C5195D291A87 |
PackageDescription | open source tool to perform static analysis on PE malware PEframe is a open source tool to perform static analysis on Portable Executable malware and generic suspicious files. It can help malware researchers to detect packer, xor, digital signature, mutex, anti debug, anti virtual machine, suspicious sections and functions, and much more information about the suspicious files. |
PackageMaintainer | Sascha Steinbiss <satta@debian.org> |
PackageName | peframe |
PackageSection | utils |
PackageVersion | 5.0.1+git20170303.0.e482def+dfsg-1~bpo9+1 |
SHA-1 | 3E6A89FD597C0E4465AD3273DC429749AAB1218E |
SHA-256 | B46773004D3784164A8ADD3F55A845FB4738275B4803666F400D8B5374C4BF9B |
Key | Value |
---|---|
FileSize | 142620 |
MD5 | 9A35E73A7BB58C6F99583A446371AE90 |
PackageDescription | open source tool to perform static analysis on PE malware PEframe is a open source tool to perform static analysis on Portable Executable malware and generic suspicious files. It can help malware researchers to detect packer, xor, digital signature, mutex, anti debug, anti virtual machine, suspicious sections and functions, and much more information about the suspicious files. |
PackageMaintainer | Sascha Steinbiss <satta@debian.org> |
PackageName | peframe |
PackageSection | utils |
PackageVersion | 5.0.1+git20170303.0.e482def+dfsg-3 |
SHA-1 | 069C86B4EEC137A3E48211BD3A93AE6C45DF8E4C |
SHA-256 | A48E808D942DD7CA332699E35E0B25EC1DD451F81F55EB0F72BD6F9DFBC08015 |
Key | Value |
---|---|
FileSize | 144248 |
MD5 | 8E285E04DFF0C3DCF15864F8B39B2DB9 |
PackageDescription | open source tool to perform static analysis on PE malware PEframe is a open source tool to perform static analysis on Portable Executable malware and generic suspicious files. It can help malware researchers to detect packer, xor, digital signature, mutex, anti debug, anti virtual machine, suspicious sections and functions, and much more information about the suspicious files. |
PackageMaintainer | Ubuntu Developers <ubuntu-devel-discuss@lists.ubuntu.com> |
PackageName | peframe |
PackageSection | utils |
PackageVersion | 5.0.1+git20170303.0.e482def+dfsg-1 |
SHA-1 | 64D201C7AACD3E9924501C4A4ACD4192FEA04892 |
SHA-256 | 2E70D9D84F9258B20DBABE4CD5C520EE15C729261A4662BFA45671C012318D89 |