| Key | Value |
|---|---|
| FileSize | 4156928 |
| MD5 | E4904B493151DD087AFE7039313997F1 |
| PackageDescription | Powerful, efficient and modular digital forensic framework DFF is a powerful open source tool with a flexible module system which will help you in your digital forensics works, including files recovery due to error or crash, evidence research and analysis, etc. . The modules allows you to examine the layout of disk images, devices and other media, to identify partitions, search for files using name, attributes, files magic etc. Files can also be analyzed or extracted using file analysis modules. . The source code is written in C++ and Python, allowing performances and great extensibility, and provides both graphical and command line interface. |
| PackageMaintainer | Pierre Chifflier <pollux@debian.org> |
| PackageName | dff |
| PackageSection | admin |
| PackageVersion | 1.3.0+dfsg.1-4.1+b2 |
| SHA-1 | 0C07C2F165118F0C08ADF9ADB96AC70061A50FC6 |
| SHA-256 | 70BE1267309378D7A6A17953ED292DD0FD2A39856B8256C2AF6FDEE4546D8694 |
| hashlookup:children-total | 389 |
| hashlookup:trust | 50 |
The searched file hash includes 389 children files known and seen by metalookup. A sample is included below:
| Key | Value |
|---|---|
| FileName | ./usr/lib/python2.7/dist-packages/dff/modules/viewer/media/videothumbnailviewer.py |
| FileSize | 3442 |
| MD5 | 3DC8ED68BF9F530FF33BABF18B67BC41 |
| SHA-1 | 0058D642A78B193902BCE79077D4B4C2F22D34E3 |
| SHA-256 | 515F66002A9DCA07EAF850C17FF5C94240F1455230F32845EF2E13E31E4CDF15 |
| SSDEEP | 96:l/9zAgHvtFTFTahdJNK4OeX54RuhRRguZeHYa3W:l/9cgFt4nRRKNW |
| TLSH | T1CA616515B90AD41381B7888AF9736E17D72F538BAA1C0406783DD4296F70989B9D4FEC |
| Key | Value |
|---|---|
| CRC32 | BC81FFE5 |
| FileName | ./usr/lib/python2.7/dist-packages/dff/modules/viewer/web/__init__.py |
| FileSize | 552 |
| MD5 | E279DAD1A4D79A10AED248C0B5881861 |
| OpSystemCode | 362 |
| ProductCode | 163709 |
| SHA-1 | 0337F11583BF81EA46D992222AA4B6A349123CAD |
| SHA-256 | 43DCD8619C49D6C142E822D71B9CBA374DDC44C10FEC45B4C6C76489EBDA56CD |
| SSDEEP | 6:Sb9DbPB853iB+1xeCJBMuNkOybM9OF4D2Fj9vAllD4DeWroXbGMKePweRGerfupp:0dE3nRWEs/viYKaed0HywOXS8CGYP |
| SpecialCode | |
| TLSH | T1BFF0EB1EBA50823164405BC3FB5B9BC6B24E8A20A2DCFC021498C0468291E2DA2E96FD |
| db | nsrl_modern_rds |
| insert-timestamp | 1646979022.3505478 |
| source | NSRL |
| Key | Value |
|---|---|
| CRC32 | 9511DC24 |
| FileName | ./usr/lib/python2.7/dist-packages/dff/modules/viewer/hexedit/right.py |
| FileSize | 1591 |
| MD5 | B5262240DD0315CBF3F8A2FA21ACCF3B |
| OpSystemCode | 362 |
| ProductCode | 163709 |
| SHA-1 | 040501090F77390E04F3A204F50A85FC39616646 |
| SHA-256 | 663B60E411374B43D232F8088E28C777DFB40591CFDFA854ADF923439EC9D7AD |
| SSDEEP | 24:6T/nRcLp0H8XSq5z/GEAJINb6KPn1pAPnAHk2no+0Agj+iGgHO5Yl4:4JcLp0mvTAv+Ukk2orbHaYi |
| SpecialCode | |
| TLSH | T1A431EF6722265627434BCF83E557A613FB2F1907A94C180A74FC53E18B529288BD6EF8 |
| db | nsrl_modern_rds |
| insert-timestamp | 1646979301.7871003 |
| source | NSRL |
| Key | Value |
|---|---|
| FileName | ./usr/lib/python2.7/dist-packages/dff/ui/gui/resources/ui_browser_toolbar.py |
| FileSize | 6367 |
| MD5 | 109272404AABCF796ECC7866CBFD2076 |
| SHA-1 | 069B3185BB28A99421EAD9EA8149AFAE1120BA6D |
| SHA-256 | A696B0AFB1F4DB8F8C0DEE85017E24DAB4E66B6EA135A95C009D5AEA36DD56FB |
| SSDEEP | 192:BnBX9MAIpA0DcZlBa4vfraO/mrbIjBEAEjbwbMhRPzsFI5SG:L+cF7efIjGA2MQPrsFoSG |
| TLSH | T190D1AB14240471A35393BD528286BD8EFD3E3447D528A824B43E82F4DF6C8F562E6DEE |
| Key | Value |
|---|---|
| CRC32 | 43B8B838 |
| FileName | ./usr/lib/python2.7/dist-packages/dff/modules/ram/volatility/memory_plugins/example1.py |
| FileSize | 4347 |
| MD5 | C26FAC5A2748D87AAB7D7A139FA1B3B2 |
| OpSystemCode | 362 |
| ProductCode | 13792 |
| SHA-1 | 078F8DC20BF579095AF4962DFDE64EBCB62448F2 |
| SHA-256 | CA74C7A453BFCDFB0B716076B031BDEF4B715315E83E8F172DCD25DD349AB269 |
| SSDEEP | 48:HYyUjoSoZXlnXZFYOJRx7qfRu3B7Bhlwq7x65PpMsVUvUoIOn1qPzlBNQaz3HBY1:PlTPJdhlv4ZpMsxin1qPz5Qaz3HBY1 |
| SpecialCode | |
| TLSH | T1EA918205997CD07A40E7069A78C3D0CAD3DED79742046BA83D2DD2584F52E3982B7EE5 |
| db | nsrl_modern_rds |
| insert-timestamp | 1646980554.7894726 |
| source | NSRL |
| Key | Value |
|---|---|
| CRC32 | F4AF110A |
| FileName | ./usr/share/doc/dff-1.3.0/README.gz |
| FileSize | 2238 |
| MD5 | 3709B48962E4E04B554D590298AE1042 |
| OpSystemCode | 362 |
| ProductCode | 13792 |
| SHA-1 | 07C5D9B937DF0EB7710A0D00100E7CFDDA8716AA |
| SHA-256 | AC163CA6FA5433B833DDA5DBBFE56BA1561F76E88F53656DEFDEA854FACAA4B5 |
| SSDEEP | 48:X7iJDg59rR3jeejK/AEa1v1KDk/tJhYHKyidCSt69z4NVQ:oA9rxjM/m1//tMHridahaQ |
| SpecialCode | |
| TLSH | T116411989B69B5F65BD1BEAEE60D614AC2ED0F402EA287AD16436018C7C1240BD2E3D45 |
| db | nsrl_modern_rds |
| insert-timestamp | 1646980632.8787453 |
| source | NSRL |
| Key | Value |
|---|---|
| CRC32 | F6E77C8B |
| FileName | ./usr/lib/python2.7/dist-packages/dff/modules/builtins/fg.py |
| FileSize | 1904 |
| MD5 | 1088F7FBBDF8E6BA29FD6E40A837FEDC |
| OpSystemCode | 362 |
| ProductCode | 163709 |
| SHA-1 | 0915C5A65240AE33C8086F8D63027A14FA12C240 |
| SHA-256 | 714BE96FE5264BBEBFD3FAED9DC1A71AD9838F5AB1AB5C608C8FC9B89AB0EDF2 |
| SSDEEP | 48:46Lp0m0RhCCvZawWCe0pIYEeaH1aKoZKfYAe8bZWF:4EumkTvZ3deHH1/oZKwKoF |
| SpecialCode | |
| TLSH | T1AE411212DA355C33908F8E57F8A057131E9F19975B9CE82430FCD0390F9A86B55E4DE9 |
| db | nsrl_modern_rds |
| insert-timestamp | 1646981105.3471022 |
| source | NSRL |
| Key | Value |
|---|---|
| CRC32 | 17DAAB31 |
| FileName | ./usr/lib/python2.7/dist-packages/dff/modules/search/__init__.py |
| FileSize | 631 |
| MD5 | B6390E7B83380F12EC0CAC8514889159 |
| OpSystemCode | 362 |
| ProductCode | 163709 |
| SHA-1 | 09902CF85A360258D52D471B4EFF59129E526BAD |
| SHA-256 | 443931ED541D00152863EAB4175BA489A12669F36B2ABB6C5409A92B41AB380B |
| SSDEEP | 12:0dE3nRWEs/viYKaed0HywOXS8CDSAFYP9YaR6:6T/niLp0H8XSnSEmho |
| SpecialCode | |
| TLSH | T170F0DD19B660853269011BC7EB578FC2B34F4E2066E8FC025449C046C290D1E62EE2ED |
| db | nsrl_modern_rds |
| insert-timestamp | 1646981266.2430801 |
| source | NSRL |
| Key | Value |
|---|---|
| CRC32 | DBFD5A27 |
| FileName | ./usr/lib/python2.7/dist-packages/dff/modules/ram/volatility/vtypes.py |
| FileSize | 13474 |
| MD5 | 1F4DD9974DE0731B792EC51F6922D638 |
| OpSystemCode | 362 |
| ProductCode | 13792 |
| SHA-1 | 0C3B8469185E1E7D4442B0855867DFA686B44131 |
| SHA-256 | 8BA85C452ED74C27BA9F8D6B8D2CFE2ED4DB08478093C2C8BAFC2FC97FD589EB |
| SSDEEP | 96:FlwlmlGwM2AU8xRCNAjbOw1HHy/psCmvVKQvVVvVlCnbrNmoqvkX7rmk83vdqoXd:El0JAU8xRCNkhHE8lCnGaO3vdqo86XB |
| SpecialCode | |
| TLSH | T11752D05939139522622DE36E2B25DD1A438D1F07AAD49CA17CCD75C837D7032CAEB2AC |
| db | nsrl_modern_rds |
| insert-timestamp | 1646982215.5410187 |
| source | NSRL |
| Key | Value |
|---|---|
| FileName | ./usr/lib/python2.7/dist-packages/dff/ui/gui/resources/ui_interpreter.py |
| FileSize | 2834 |
| MD5 | A4C1CCF7734649BB22C521FFDC72C654 |
| SHA-1 | 0E1042F9B2DDC4AC205BEF7EA0B3995D9D96EC04 |
| SHA-256 | A51D45BF5278A213CF5B877310BFCEBA15253129B250BAEA16B32164C44C3C0B |
| SSDEEP | 48:O7DT3naZGXBlxZl7moXyLVyLbyLoyL5HyLpkyLdul9w/cizAKyqP8:knaIXEoXyZyPyEypy2ypyw/ci0Kyqk |
| TLSH | T18A5198B15A4B789187038D6A2259D8CAFF2DB84FCAB25021735CC1B49F9F5F6E5C8208 |