python27.dll

Python

Python Software Foundation

python27.dll is the module is part of the Core Python redistributable which allows application to run on a Pythin code base. The file has been seen being downloaded from mega.nz and multiple other hosts.
Publisher:
Python Software Foundation

Product:
Python

Description:
Python Core

Version:
2.7.3

MD5:
fb9ecb14a14328711eef9aace1686614

SHA-1:
bd76a10cd66ff833bc24b6008cd502c4d2eabc1a

SHA-256:
7731e2cdb12d3bbf6c9c64e29f1883c36cb9d443a6fb5770a7d8b0e57d95c2be

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/26/2024 4:49:06 AM UTC  (today)

Scan engine
Detection
Engine version

XVirus List
Win.Detected
2.3.31

File size:
2.2 MB (2,303,488 bytes)

Product version:
2.7.3

Copyright:
Copyright © 2001-2008 Python Software Foundation. Copyright © 2000 BeOpen.com. Copyright © 1995-2001 CNRI. Copyright © 1991-1995 SMC.

Original file name:
python27.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\insync\app\python27.dll

File PE Metadata
Compilation timestamp:
4/10/2012 4:31:51 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:H9euLUwe3VLmI6C1mGrPKZo1KPen8MZEHHo5IvTj+j2D9/:HcuLUwrpCciKZo138MeHIm+C5/

Entry address:
0x3B021

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 15, 03, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, CC, FE, FF, FF, 59, 5D, C2, 0C, 00, 68, C0, 25, 22, 1E, E8, 8E, 03, 00, 00, 59, C3, 6A, 14, 68, 90, 6E, 1C, 1E, E8, 6C, 02, 00, 00, FF, 35, C0, B1, 22, 1E, 8B, 35, 18, E4, 0F, 1E, FF, D6, 59, 89, 45, E4, 83, F8, FF, 75, 0C, FF, 75, 08, FF, 15, 40, E4, 0F, 1E, 59, EB, 67, 6A, 08, E8, 68, 03, 00, 00, 59, 83, 65, FC, 00, FF, 35, C0, B1, 22, 1E, FF, D6, 89, 45, E4, FF, 35, BC, B1, 22, 1E, FF, D6, 59, 59, 89...
 
[+]

Entropy:
6.6750

Code size:
1009 KB (1,033,216 bytes)

The file python27.dll has been seen being distributed by the following 2 URLs.

https://mega.nz/temporary/.../vloEHS6K

Scan python27.dll - Powered by Reason Core Security