Result for 04F847A3D9F75CBB2F65C37D124F649A219ABBAB

Query result

Key Value
FileName./usr/sbin/samhain
FileSize769552
MD528C45FDF2207B66EA94AAE8DD01E14FB
SHA-104F847A3D9F75CBB2F65C37D124F649A219ABBAB
SHA-25656ADD81F579B19610B9FA63A5B22426DD4E1E7710433D57009ECCE11A0D531D8
SSDEEP12288:9qtf7FHBM+m0aKNGaikX6Zd3iLhmMiDPuTzXCgpEp:9qbKaNOzPiLgM
TLSHT155F42A95EF089E42D4A9CF72C979D1F60A3C689363510662AEDD1A287A0FBDD4FC3D01
hashlookup:parent-total1
hashlookup:trust55

Network graph view

Parents (Total: 1)

The searched file hash is included in 1 parent files which include package known and seen by metalookup. A sample is included below:

Key Value
FileSize1167930
MD53263D85BD189E8CD17677D682EA0D333
PackageDescriptionData integrity and host intrusion alert system Samhain is an integrity checker and host intrusion detection system that can be used on single hosts as well as large, UNIX-based networks. It supports central monitoring as well as powerful (and new) stealth features to run undetected on memory using steganography. . Main features * Complete integrity check + uses cryptographic checksums of files to detect modifications, + can find rogue SUID executables anywhere on disk, and * Centralized monitoring + native support for logging to a central server via encrypted and authenticated connections * Tamper resistance + database and configuration files can be signed + logfile entries and e-mail reports are signed + support for stealth operation
PackageMaintainerJavier Fernández-Sanguino Peña <jfs@debian.org>
PackageNamesamhain
PackageSectionadmin
PackageVersion4.1.4-2
SHA-1031E305F8527ACE04B433B458DAD2093A86B0A8D
SHA-256F66323E03D71A74192F51640ADEED5F6FD1E9EA1231167FFAFA5EB5CD70FA678