Key | Value |
---|---|
MD5 | D41A687BE6B30BFAFD15A301AA2CAD7E |
PackageArch | armv7hl |
PackageDescription | Prelude-Correlator allows conducting multi-stream correlations thanks to a powerful programming language for writing correlation rules. With any type of alert able to be correlated, event analysis becomes simpler, quicker and more incisive. This correlation alert then appears within the Prewikka interface and indicates the potential target information via the set of correlation rules. |
PackageMaintainer | Fedora Project |
PackageName | prelude-correlator |
PackageRelease | 2.fc34 |
PackageVersion | 5.2.0 |
SHA-1 | 455213688B021A5A7F87167DA7BA320C783994B5 |
SHA-256 | 9F45D639F183BC7B2D737374A42F57B53878162D95164074395485D5B0CC4C6C |
hashlookup:children-total | 22 |
hashlookup:trust | 50 |
The searched file hash includes 22 children files known and seen by metalookup. A sample is included below:
Key | Value |
---|---|
FileName | ./var/lib/prelude-correlator/prelude-correlator/ciarmy.dat |
FileSize | 215845 |
MD5 | 4D74A48FCAF9BE65572B7865A7914C52 |
SHA-1 | 027D69A6CBF1A522A6F39F891AAA5FF3C252D556 |
SHA-256 | A8F69235B1B442A1515DD6E44B5CA0D299B3CE25F1EE6596D88015BC987CFD40 |
SSDEEP | 3072:Wn+qhnASubteC9PmpdYQP22ybNY40LIbZxSqy+lZX2YGPrbqy+1IwN2:Wn+KnTC9lMwN2 |
TLSH | T1E824885573BF2FF5CEC6808E5382C4A6609A51A7DAA3F5E49FDB36807D01080FAF4652 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/BusinessHourPlugin.py |
FileSize | 1782 |
MD5 | B9456CC17B7D83D5E4984E4439EF42BD |
SHA-1 | 05A8AA84DAC3B52538900E92145E40289595E223 |
SHA-256 | 35D495CACCEBD01F14BC4802C385B6E248DF80C027919676CEDBAD171CE53D22 |
SSDEEP | 24:efbmIjvUpbkgK2ahJiyUVOkHxHqTbVloY5AwHF4kqTPs+wcGSHyAH7pCyZE1aryk:efyIjvU9xDg4yUjHTYh45TP4SSAbpCaj |
TLSH | T15C31438E91719DB16A1103E5348F55DEB22A1A97D29A98983D5C818C7F04EF202B73E4 |
Key | Value |
---|---|
FileName | ./usr/share/doc/packages/prelude-correlator/NEWS |
FileSize | 17991 |
MD5 | 54B012B09947277031B17573041F98DC |
SHA-1 | 1AC708B9825A5BC046D3C4A53A1933E361DFE4C7 |
SHA-256 | CF6F7B31ED5AD5E133C3B5E24EFBF9AB581DD7541BD8036B7CF3D6718C3A94C9 |
SSDEEP | 384:OKAQJMpN4mtKUdLA+pR+Y9DQFBKmWOgyrx:I+wHvWmOgw |
TLSH | T1C78287E277343712799227A6D2CB41DAB718A1EB9233D0747B9895C87A03063D3776CB |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/EventScanPlugin.py |
FileSize | 2191 |
MD5 | 47B28463DDB94268C26E550C37C7EA8D |
SHA-1 | 1CD68BD9325E29448D88FF96FD8A351CFB8BB61E |
SHA-256 | 1E9720EE73766F85F460974AED30D9D297C82DA289F585F3D3D7FBAC0FB34253 |
SSDEEP | 48:efyIjvRW4FDg4yUjHTYyFIZN8rF2TtWSCsFEP:efyaVEwT/qZuuWStF0 |
TLSH | T16141B84E9320DAB05D0906B5104791DC732916C3962E5C08BD2CD38D7BA5EB681755FC |
Key | Value |
---|---|
FileName | ./usr/share/doc/packages/prelude-correlator/AUTHORS |
FileSize | 125 |
MD5 | CD2BB2FA7D21CFA818A39915F219C78D |
SHA-1 | 36BEADC5993E89C3CB13B50245BA1420B2699517 |
SHA-256 | 6597296AA1A8E5A55E8B9C3116BD9AD93A7C435D54E0B17B38D776C8E906EE16 |
SSDEEP | 3:L2bKgJEiMEuR9D9Vf0S4FQXMk1aENzpzeLKbvn:L2rQEe9T4+Mk1aeNLn |
TLSH | T11EB02BCC151000073C438C446251C5D644C23CE0C5FC80406210F05136380005514293 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/SpamhausDropPlugin.py |
FileSize | 4217 |
MD5 | 3514F0C244B66448FCD5B437B34C34EC |
SHA-1 | 49DE807A426CB87FB65AF518E4A099541BC093DA |
SHA-256 | C2D8E7050A5EB3610BC31F9DEDA4C1719925990413507DE4423033AC55784DD0 |
SSDEEP | 48:efyIjfgODg4yUjHTYuHMjRM6mdohTFH93U7uv5QWt75Ojo75x5uzXBitHg:efyyDEwT5Mj+8hTFH67uhQNs74QtHg |
TLSH | T14A91D5AF2535D462AA17019050EBD1D1732AABC7844D90ADB4FCE288BF95C70D2B18EA |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/EventStormPlugin.py |
FileSize | 1979 |
MD5 | BEE5F84988F3457B630339BB8C5FAA6D |
SHA-1 | 4B66A27DAA796C365940E9E2B73DAF608D19B24D |
SHA-256 | EA1F0F41D5AA5C8152CEF4140867D288DE2BEAB1501BBA098A157CD254F55E2C |
SSDEEP | 48:efyIjvnF4FDg4yUjHTYyEKnwVF6FoTpKBPX:efya2EwT/EKY8qKBf |
TLSH | T15941978D5171DB705E0803F4214BE4DD73290AC7A769AC08B81CE98DBB99EB582366F8 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/WormPlugin.py |
FileSize | 3377 |
MD5 | B879D7AFBEC94FF3835C9F14C01A2C5B |
SHA-1 | 4BCBB5B93ECDB2F0C822D301E3BDED718C7ACD67 |
SHA-256 | 729159D9CAD824F8C95C9BC5E9C9F7BD5984F0C5DA574A55501EB4CBE355B1E1 |
SSDEEP | 96:efyaQEwT+xpn31ZQKhz/r7/N/Kv9OZGFB:AyaNwT+731xjV/i4c |
TLSH | T11A61A85D1320DBF66B8702B2208BB2E67315C6D3861B6C2C797DC29C6F62DB541729F8 |
Key | Value |
---|---|
CRC32 | 4E46F4A1 |
FileName | usr/share/doc/vifm/COPYING |
FileSize | 18092 |
KnownMalicious | malshare.com |
MD5 | B234EE4D69F5FCE4486A80FDAF4A4263 |
OpSystemCode | 362 |
ProductCode | 15109 |
RDS:package_id | 318968 |
SHA-1 | 4CC77B90AF91E615A64AE04893FDFFA7939DB84C |
SHA-256 | 8177F97513213526DF2CF6184D8FF986C675AFB514D4E68A404010521B880643 |
SHA-512 | AEE80B1F9F7F4A8A00DCF6E6CE6C41988DCAEDC4DE19D9D04460CBFB05D99829FFE8F9D038468EABBFBA4D65B38E8DBEF5ECF5EB8A1B891D9839CDA6C48EE957 |
SSDEEP | 384:ghUwi5rpL676yV12rPd34ZomzM2FR+dWF7jUI:gmFWixMFzMdm7jUI |
SpecialCode | |
TLSH | T13A82A42E770443F205C202A16A4F68DFA32AD5B9723E1155386DC15E236FE35C3BFA99 |
db | nsrl_legacy |
insert-timestamp | 1735817250.2027707 |
mimetype | text/plain |
nsrl-sha256 | rds241-sha256.zip |
source | snap:OtzMxnIemajqYJlxNY3Ed4r6TROQn7lo_813 |
tar:gname | root |
tar:uname | root |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/CIArmyPlugin.py |
FileSize | 3228 |
MD5 | C2E7AF5E6F9491574D0AEE6A70712BE7 |
SHA-1 | 4F20A3783F000BC757F8796710A77B21F809441A |
SHA-256 | F7318CE1A6C6C40403FE0411FBDF34E6927DBD41912E12ED3BAC9ECB85EA2BD6 |
SSDEEP | 48:efyIjNu4OHDg4yUjHTYr5TF2XD43SqdQWW5HxY7pOXO3qWptHc:efyqOHEwTgTFaqdQBxXkptHc |
TLSH | T11461A5BF5676C962A79741C4608B50C4331DBAC7940DA064B8BCE18CAFB9D71D2B2CD9 |