Result for EA25A9AED517D4F36F17E6F4AC28FCFE202F495B

Query result

Key Value
FileName./usr/lib/python3/dist-packages/pefile.py
FileSize215934
MD552B7BCBC4D32FC2143326A1C1E7A091A
SHA-1EA25A9AED517D4F36F17E6F4AC28FCFE202F495B
SHA-2560C1FA67AAE405E3C79A4290A51AB60FF6D4C0A0B41E1802FCB4CD5FA45964807
SSDEEP6144:cJIA4zCvnWzAi+M7SiAaEuAoV/DYiIglKb6rDERt:ct4zgniz8N1
TLSHT18724C623B92126A29293986E48DBE0035775744B059C643CBDBC81542FA85BCDBF3FF9
hashlookup:parent-total2
hashlookup:trust60

Network graph view

Parents (Total: 2)

The searched file hash is included in 2 parent files which include package known and seen by metalookup. A sample is included below:

Key Value
FileSize52792
MD5B0268C147DE5BAA6B7F701AED5936784
PackageDescriptionPortable Executable (PE) parsing module for Python pefile is a Python module to read and work with Portable Executable (PE) files. Most of the information in the PE header is accessible, as well as all the sections, section information and data. . All the basic PE file structures are available with their default names as attributes of the returned instance. . Processed elements such as the import table are made available with lowercase names, to differentiate them from the upper case basic structure names. . pefile has been tested against the limits of valid PE headers; that is, Windows malware. Lots of packed malware attempt to abuse the format beyond its standard use. . Some of the tasks that pefile makes possible are: * Modifying and writing back to the PE image * Header inspection * Section analysis * Retrieving data * Warnings for suspicious and malformed values * Packer detection with PEiD signatures * PEiD signature generation
PackageMaintainerHilko Bengen <bengen@debian.org>
PackageNamepython-pefile
PackageSectionpython
PackageVersion2016.3.28-4
SHA-104057B14EE2E55772297D797ACC01D23260D83D6
SHA-256E4EF0530E8F958905E7D2C23B99FCD2554FF925A68E14831FB27B38DDAF826D3
Key Value
FileSize50306
MD5BD67BAC7C2E4D0D4B26DC193BD1ED9F5
PackageDescriptionPortable Executable (PE) parsing module for Python pefile is a Python module to read and work with Portable Executable (PE) files. Most of the information in the PE header is accessible, as well as all the sections, section information and data. . All the basic PE file structures are available with their default names as attributes of the returned instance. . Processed elements such as the import table are made available with lowercase names, to differentiate them from the upper case basic structure names. . pefile has been tested against the limits of valid PE headers; that is, Windows malware. Lots of packed malware attempt to abuse the format beyond its standard use. . Some of the tasks that pefile makes possible are: * Modifying and writing back to the PE image * Header inspection * Section analysis * Retrieving data * Warnings for suspicious and malformed values * Packer detection with PEiD signatures * PEiD signature generation
PackageMaintainerHilko Bengen <bengen@debian.org>
PackageNamepython3-pefile
PackageSectionpython
PackageVersion2016.3.28-4
SHA-124A8BAF74F36E6950816B955FAE89698724A6697
SHA-256AFE30350802059FDD4A22BB7F8A51C6A7B1E8CF24FE9DB2C125C381FE8F3CDA0