| Key | Value | 
|---|---|
| FileName | ./usr/bin/shed | 
| FileSize | 34448 | 
| MD5 | A62A40173AB6919EB92EDD1DBED56079 | 
| SHA-1 | 30EF7D395BB131ABCF2B5247727C04CB7997AA5B | 
| SHA-256 | DA7C60B919A704DEE245DF3151D2F60187F7032E30D49339E2E4A56E9DA83B0A | 
| SSDEEP | 384:iwHT8mK0J9tdfXnnvjojjvp1gLNpFWLSQBGIJjiLJcWAPY6jDeLzdbK1pncZWguF:lT8p0znvqvp1DBGQdfQ6j6P01eFkfZs | 
| TLSH | T15EF20C8D7743CFB6D9E342F85D9B472966B28101D333F3D3FA0B36152622299BA25361 | 
| hashlookup:parent-total | 1 | 
| hashlookup:trust | 55 | 
The searched file hash is included in 1 parent files which include package known and seen by metalookup. A sample is included below:
| Key | Value | 
|---|---|
| FileSize | 21956 | 
| MD5 | 373CF7D0DA83DF968A6FF9C2A2955D4E | 
| PackageDescription | simple hex editor with a pico-style interface shed (Simple Hex Editor) is an easy application for viewing and editing files in text mode, using ncurses. The main features are: . - Displays each byte as ascii, hex, decimal, octal and binary; - Allows changes to be input in all of the above displayed modes, with bit toggling in the binary column; - Simple Pico-style interface; - Search resource; - Can dump information to file; - Small memory requirements because file is not loaded into memory; - Large file support. . shed is useful in forensics investigations. | 
| PackageMaintainer | Debian Forensics <forensics-devel@lists.alioth.debian.org> | 
| PackageName | shed | 
| PackageSection | admin | 
| PackageVersion | 1.15-3+b1 | 
| SHA-1 | 6584CD3AD87F8A9C8B2DA692B0DB9C28B8CC8B7D | 
| SHA-256 | D76B68B4D8F1171D65AA58621DDFD424D9DB8CECDDEBC091BE6FF48F714C8B4E |