Result for B3645134D4297882B53A1327404C19A4053655FD

Query result

Key Value
FileName./usr/share/pyshared/pefile-1.2.9.1.egg-info
FileSize1525
MD566CB6C4A126F520961A3B8F11F4F7DE5
SHA-1B3645134D4297882B53A1327404C19A4053655FD
SHA-2566C062779FF3BD4F60E816034338D37E277180C611CF6409627A62D10EC99228B
SSDEEP24:DHLcIBzlFFXGDWEoGw/PX++fRpCVuv2xPP4gQ6kQIF3A13g:DHLcIplzXbFGw/PXFvv254/QIO13g
TLSHT19231834A34C07BF11AA78AE9D10C85959C1A8202862E58A430ED120E3F59E73D2FD4FE
hashlookup:parent-total2
hashlookup:trust60

Network graph view

Parents (Total: 2)

The searched file hash is included in 2 parent files which include package known and seen by metalookup. A sample is included below:

Key Value
FileSize37830
MD549487AC4DDE6337EF5807297528B9DEF
PackageDescriptionPortable Executable (PE) parsing module for Python pefile is a Python module to read and work with Portable Executable (PE) files. Most of the information in the PE header is accessible, as well as all the sections, section information and data. . All the basic PE file structures are available with their default names as attributes of the returned instance. . Processed elements such as the import table are made available with lowercase names, to differentiate them from the upper case basic structure names. . pefile has been tested against the limits of valid PE headers; that is, Windows malware. Lots of packed malware attempt to abuse the format beyond its standard use. . Some of the tasks that pefile makes possible are: * Modifying and writing back to the PE image * Header inspection * Section analysis * Retrieving data * Warnings for suspicious and malformed values * Packer detection with PEiD signatures * PEiD signature generation
PackageMaintainerUbuntu Developers <ubuntu-devel-discuss@lists.ubuntu.com>
PackageNamepython-pefile
PackageSectionpython
PackageVersion1.2.9.1-1.1
SHA-152EDB52945D255D8EC388BB2591BF139128794DA
SHA-25668D9F6730C8722BD1038E73CB7CFF0302B7D7117C824BAB41F155069BEE0F1D7
Key Value
FileSize41134
MD5B433625B14C6BEB8F12AEC0E7482DE3E
PackageDescriptionPortable Executable (PE) parsing module for Python pefile is a Python module to read and work with Portable Executable (PE) files. Most of the information in the PE header is accessible, as well as all the sections, section information and data. . All the basic PE file structures are available with their default names as attributes of the returned instance. . Processed elements such as the import table are made available with lowercase names, to differentiate them from the upper case basic structure names. . pefile has been tested against the limits of valid PE headers; that is, Windows malware. Lots of packed malware attempt to abuse the format beyond its standard use. . Some of the tasks that pefile makes possible are: * Modifying and writing back to the PE image * Header inspection * Section analysis * Retrieving data * Warnings for suspicious and malformed values * Packer detection with PEiD signatures * PEiD signature generation
PackageMaintainerRobert S. Edmonds <edmonds@debian.org>
PackageNamepython-pefile
PackageSectionpython
PackageVersion1.2.9.1-1.1
SHA-1EC69A8A839ADCE99EE3DF2374C400BE50BA4277C
SHA-256A53604AA2F71F2867E59F747C5EC8DF6E07A826E127E06874FE38A6B4C230012