Key | Value |
---|---|
CRC32 | D5E04E34 |
FileName | ./usr/lib/python3/dist-packages/ordlookup/ws2_32.py |
FileSize | 3266 |
MD5 | 54EC359B34DEA6DD37B2DAA78A8E3381 |
OpSystemCode | {'MfgCode': '1006', 'OpSystemCode': '362', 'OpSystemName': 'TBD', 'OpSystemVersion': 'none'} |
ProductCode | {'ApplicationType': 'Operating System', 'Language': 'English', 'MfgCode': '1722', 'OpSystemCode': '599', 'ProductCode': '163709', 'ProductName': 'BlackArch Linux', 'ProductVersion': '2017.03.01'} |
RDS:package_id | 294806 |
SHA-1 | 255BA3DFD1D9DAD5998118F4E3103720755725AE |
SHA-256 | C3FB9BAEAC37F472CECC61F1F7946D7E135CB40E8DE152C429AE6316E761D74C |
SSDEEP | 96:rU5xJSfm5iYc5Hf8zeHv6dcPm9edoCrnzyy:eSfmJc53gcPm9SoCrney |
SpecialCode | |
TLSH | T10A61273845458BA81FCDBF476C5E544E4804163F9F227866FB9A098A4FAEC2C71BD623 |
db | nsrl_modern_rds |
insert-timestamp | 1696438392.5768983 |
source | db.sqlite |
tar:gname | root |
tar:uname | root |
hashlookup:parent-total | 184 |
hashlookup:trust | 100 |
The searched file hash is included in 184 parent files which include package known and seen by metalookup. A sample is included below:
Key | Value |
---|---|
MD5 | C871FF7C93551FD65F75CA2594C0FD66 |
PackageArch | noarch |
PackageDescription | Portable Executable reader module. All the PE file basic structures are available with their default names as attributes of the instance returned. Processed elements such as the import table are made available with lowercase names, to differentiate them from the upper case basic structure names. pefile has been tested against many edge cases such as corrupted and malformed PEs as well as malware, which often attempts to abuse the format way beyond its standard use. To the best of my knowledge most of the abuse is handled gracefully. |
PackageName | python36-pefile |
PackageRelease | 11.24 |
PackageVersion | 2019.4.18 |
SHA-1 | 025DEA75193A96698E23022CF7C28C105D8D7520 |
SHA-256 | F3B546CE48E247D836EC684798937BC3794C011FBEC8D20F7106C6A2A9606308 |
Key | Value |
---|---|
MD5 | EFF7EA2FCD241366D3378722D7EA9C07 |
PackageArch | noarch |
PackageDescription | Portable Executable reader module. All the PE file basic structures are available with their default names as attributes of the instance returned. Processed elements such as the import table are made available with lowercase names, to differentiate them from the upper case basic structure names. pefile has been tested against many edge cases such as corrupted and malformed PEs as well as malware, which often attempts to abuse the format way beyond its standard use. To the best of my knowledge most of the abuse is handled gracefully. |
PackageName | python310-pefile |
PackageRelease | 11.26 |
PackageVersion | 2019.4.18 |
SHA-1 | 02E35C40CB320BACFDAC55C6BCA50E77893F6E08 |
SHA-256 | D6FA045E269981ADFFAE6BC120688F32565136521ADDBCAF235C276D6D867441 |
Key | Value |
---|---|
FileSize | 52792 |
MD5 | B0268C147DE5BAA6B7F701AED5936784 |
PackageDescription | Portable Executable (PE) parsing module for Python pefile is a Python module to read and work with Portable Executable (PE) files. Most of the information in the PE header is accessible, as well as all the sections, section information and data. . All the basic PE file structures are available with their default names as attributes of the returned instance. . Processed elements such as the import table are made available with lowercase names, to differentiate them from the upper case basic structure names. . pefile has been tested against the limits of valid PE headers; that is, Windows malware. Lots of packed malware attempt to abuse the format beyond its standard use. . Some of the tasks that pefile makes possible are: * Modifying and writing back to the PE image * Header inspection * Section analysis * Retrieving data * Warnings for suspicious and malformed values * Packer detection with PEiD signatures * PEiD signature generation |
PackageMaintainer | Hilko Bengen <bengen@debian.org> |
PackageName | python-pefile |
PackageSection | python |
PackageVersion | 2016.3.28-4 |
SHA-1 | 04057B14EE2E55772297D797ACC01D23260D83D6 |
SHA-256 | E4EF0530E8F958905E7D2C23B99FCD2554FF925A68E14831FB27B38DDAF826D3 |
Key | Value |
---|---|
MD5 | 6AFA9A373ECCA2EA96C0C081D1EC7028 |
PackageArch | noarch |
PackageDescription | Portable Executable reader module. All the PE file basic structures are available with their default names as attributes of the instance returned. Processed elements such as the import table are made available with lowercase names, to differentiate them from the upper case basic structure names. pefile has been tested against many edge cases such as corrupted and malformed PEs as well as malware, which often attempts to abuse the format way beyond its standard use. To the best of my knowledge most of the abuse is handled gracefully. |
PackageName | python2-pefile |
PackageRelease | lp151.11.2 |
PackageVersion | 2019.4.18 |
SHA-1 | 05EC1F14186CD02BEEC8E6F034CB5F45CC0DBCB3 |
SHA-256 | 872DBF5DF3D188481A7236AC21BE51705E7353C255AAC0EA69308AFB9317A2F4 |
Key | Value |
---|---|
FileName | https://ftp.lysator.liu.se/pub/OpenBSD/6.5/packages//mips64el//py3-pefile-2018.8.8.tgz |
MD5 | 80611AB21BC9AF9D514984C3A47BD9C3 |
SHA-1 | 07AB0C0FB7A73F13A8C4572BCC08399CBD8EEDF7 |
SHA-256 | 1BD17A71B5080879ED9ADF252CACFC2AF2E058E9A95C7E1ACEE7BB6A9441E067 |
SSDEEP | 1536:nN27blmva0WCOVCTQxWwpUTPHFK/QfHDxa/nWPGIh+aPMD4/rNMX++n+D/ADYQap:UMSnpdxW6K2kwWeKPX/rNXeau22S |
TLSH | T1D8C31319D1B0FE2FB906286461C1264BC96698FD34027FB372C998BEE3D9359E08765C |
Key | Value |
---|---|
FileName | https://ftp.lysator.liu.se/pub/OpenBSD/6.9/packages//sparc64//py-pefile-2018.8.8p1.tgz |
MD5 | 61C150FAF7551A585CAF48C7E42C7B1C |
SHA-1 | 081314708DD7466AA9B14C896FF82E458EE5E81F |
SHA-256 | 93209A5930F9B3C24F01EC9BAFCA25C45009D6914833955077223397C393F69B |
SSDEEP | 3072:cqhqg0BkZKs4LTYuylwhvlG9jbL07jZ64EIAS:/qgVZlSfkbLKZ64j |
TLSH | T19DC312EB83F5F06E6A8F97900177A87E20DD6D96D0F166244472D3D0167C2503AE7BB8 |
Key | Value |
---|---|
FileSize | 56388 |
MD5 | 5322B93AF8902F94A9BFCF50BEEE3E5D |
PackageDescription | Portable Executable (PE) parsing module for Python pefile is a Python module to read and work with Portable Executable (PE) files. Most of the information in the PE header is accessible, as well as all the sections, section information and data. . All the basic PE file structures are available with their default names as attributes of the returned instance. . Processed elements such as the import table are made available with lowercase names, to differentiate them from the upper case basic structure names. . pefile has been tested against the limits of valid PE headers; that is, Windows malware. Lots of packed malware attempt to abuse the format beyond its standard use. . Some of the tasks that pefile makes possible are: * Modifying and writing back to the PE image * Header inspection * Section analysis * Retrieving data * Warnings for suspicious and malformed values * Packer detection with PEiD signatures * PEiD signature generation |
PackageMaintainer | Hilko Bengen <bengen@debian.org> |
PackageName | python3-pefile |
PackageSection | python |
PackageVersion | 2019.4.18-1.1 |
SHA-1 | 083D134A746DDF47A2C37E5DC288DBF0A192BAA2 |
SHA-256 | D8FB32BE8275F88EBBC54BEE310E4719D4AED9615B68050C1C0B5CCD41BD8135 |
Key | Value |
---|---|
FileName | https://ftp.lysator.liu.se/pub/OpenBSD/6.6/packages//i386//py-pefile-2018.8.8p0.tgz |
MD5 | A4DF3E8BFDD8BFE521F2A6CD54BE60F3 |
SHA-1 | 0998919CAC7D995A48F28748B70E3932D74BAE4A |
SHA-256 | A435E5FFD7B580A6A727B3D0830718F1D203FB0C7E0F3800B6AE8810D57E67AB |
SSDEEP | 3072:EdS6ed2vfCs9EQURTAB4Z45b0AdSzz3hdLm49D+bGkhtz57+:EdSqynB84Zfzz3hdS4ZuGkLF7+ |
TLSH | T116C3129180DE39F1285F75C19B005F84CDA0D891766CBA0B2DF121F8EEA4525AF5A87F |
Key | Value |
---|---|
FileName | https://ftp.lysator.liu.se/pub/OpenBSD/6.3/packages//powerpc//py3-pefile-2017.11.5.tgz |
MD5 | 4E181DE6A979841C07023BF18873FFBA |
SHA-1 | 0A7274177135BF03328F24FF0D0DF99FE1144773 |
SHA-256 | 9DDC664C0490430C5E06C292C44E182724AE65D773B0802C57382D4B2803DDF3 |
SSDEEP | 3072:nRtRj9Th9f9wq+fLOxN1LolLt9QnMuAeFkTrN:nrTh91so0luk8kTrN |
TLSH | T167C312AD76F8A0C8EBDFF88F696280DAD1112DF09A11C5411B8025F472957CD6027EBB |
Key | Value |
---|---|
MD5 | EA99AC3996A14B5B3942ABF2EC8A25D8 |
PackageArch | noarch |
PackageDescription | Portable Executable reader module. All the PE file basic structures are available with their default names as attributes of the instance returned. Processed elements such as the import table are made available with lowercase names, to differentiate them from the upper case basic structure names. pefile has been tested against many edge cases such as corrupted and malformed PEs as well as malware, which often attempts to abuse the format way beyond its standard use. To the best of my knowledge most of the abuse is handled gracefully. |
PackageName | python3-pefile |
PackageRelease | lp152.2.7 |
PackageVersion | 2019.4.18 |
SHA-1 | 0BB7BE05A7D0AE2F761520EDA7E21ECF52BE662D |
SHA-256 | 58C4C0A0209F039AC6E7ACBA668B9210C743E57C4873093A8E9EE7DD92BCBE3E |