Result for 72B470C2181F7292A5F15A678F79C02166C8D99A

Query result

Key Value
CRC323861CA0D
FileName__init__.py
FileSize715
MD5579107947A1351A83533FFED2338233A
OpSystemCode{'MfgCode': '1006', 'OpSystemCode': '362', 'OpSystemName': 'TBD', 'OpSystemVersion': 'none'}
ProductCode{'ApplicationType': 'Operating System', 'Language': 'English', 'MfgCode': '1722', 'OpSystemCode': '599', 'ProductCode': '163709', 'ProductName': 'BlackArch Linux', 'ProductVersion': '2017.03.01'}
SHA-172B470C2181F7292A5F15A678F79C02166C8D99A
SHA-256CAE25D63FBB022F3E2393188BBDCCD2FB9C2A51F5F99471FD925F0055D3D9208
SSDEEP12:1RjCeuiHJRTFUzjsXwIzrsJ8xFWvhEJZWvhcoiejhmjMAs2vCK03a6LN1AMZhER8:1R24HJF6zQhU8jW5eW5KCkMAs2vrl6L1
SpecialCode
TLSHT14D01C09D4CD6AD0213114AEA194F71056B6C70272B082A267CDD625ABF90A29D1B086B
dbnsrl_modern_rds
insert-timestamp1647020197.794219
sourceNSRL
hashlookup:parent-total2
hashlookup:trust60

Network graph view

Parents (Total: 2)

The searched file hash is included in 2 parent files which include package known and seen by metalookup. A sample is included below:

Key Value
FileSize52792
MD5B0268C147DE5BAA6B7F701AED5936784
PackageDescriptionPortable Executable (PE) parsing module for Python pefile is a Python module to read and work with Portable Executable (PE) files. Most of the information in the PE header is accessible, as well as all the sections, section information and data. . All the basic PE file structures are available with their default names as attributes of the returned instance. . Processed elements such as the import table are made available with lowercase names, to differentiate them from the upper case basic structure names. . pefile has been tested against the limits of valid PE headers; that is, Windows malware. Lots of packed malware attempt to abuse the format beyond its standard use. . Some of the tasks that pefile makes possible are: * Modifying and writing back to the PE image * Header inspection * Section analysis * Retrieving data * Warnings for suspicious and malformed values * Packer detection with PEiD signatures * PEiD signature generation
PackageMaintainerHilko Bengen <bengen@debian.org>
PackageNamepython-pefile
PackageSectionpython
PackageVersion2016.3.28-4
SHA-104057B14EE2E55772297D797ACC01D23260D83D6
SHA-256E4EF0530E8F958905E7D2C23B99FCD2554FF925A68E14831FB27B38DDAF826D3
Key Value
FileSize50306
MD5BD67BAC7C2E4D0D4B26DC193BD1ED9F5
PackageDescriptionPortable Executable (PE) parsing module for Python pefile is a Python module to read and work with Portable Executable (PE) files. Most of the information in the PE header is accessible, as well as all the sections, section information and data. . All the basic PE file structures are available with their default names as attributes of the returned instance. . Processed elements such as the import table are made available with lowercase names, to differentiate them from the upper case basic structure names. . pefile has been tested against the limits of valid PE headers; that is, Windows malware. Lots of packed malware attempt to abuse the format beyond its standard use. . Some of the tasks that pefile makes possible are: * Modifying and writing back to the PE image * Header inspection * Section analysis * Retrieving data * Warnings for suspicious and malformed values * Packer detection with PEiD signatures * PEiD signature generation
PackageMaintainerHilko Bengen <bengen@debian.org>
PackageNamepython3-pefile
PackageSectionpython
PackageVersion2016.3.28-4
SHA-124A8BAF74F36E6950816B955FAE89698724A6697
SHA-256AFE30350802059FDD4A22BB7F8A51C6A7B1E8CF24FE9DB2C125C381FE8F3CDA0