Glossary
Imphash (import hash)
An MD5 of a PE file's ordered import list, introduced by Mandiant in 2014 to group malware samples built from the same code.
The imphash is computed from the import table: each import becomes a lower-case dll.function pair (DLL extension removed, functions imported by ordinal named from known tables or written ordN), the pairs are joined with commas in file order, and the result is hashed with MD5. The reference implementation is get_imphash() in pefile (Mandiant).
Builds of one project often share an imphash; packed files and .NET assemblies share theirs with many unrelated files. See imphash, Rich header hash and TLSH.