Key | Value |
---|---|
MD5 | 28B62EB9801B93675088FE1A64D42B2F |
PackageArch | noarch |
PackageDescription | Prelude-Correlator allows conducting multi-stream correlations thanks to a powerful programming language for writing correlation rules. With any type of alert able to be correlated, event analysis becomes simpler, quicker and more incisive. This correlation alert then appears within the Prewikka interface and indicates the potential target information via the set of correlation rules. |
PackageMaintainer | https://bugs.opensuse.org |
PackageName | prelude-correlator |
PackageRelease | lp152.1.1 |
PackageVersion | 5.1.0 |
SHA-1 | 52F6859CE6F2A4B25824C861ECF3F170EBB91927 |
SHA-256 | 6EC963541F6EAD5B25F3987CA7C1D52DD1BA301E2088E55F33748649792E9175 |
hashlookup:children-total | 24 |
hashlookup:trust | 50 |
The searched file hash includes 24 children files known and seen by metalookup. A sample is included below:
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/EventSweepPlugin.py |
FileSize | 2557 |
MD5 | 438F3FBF4D84969AD190217F9BF1C5ED |
SHA-1 | 0F343FF6FAE76228E447377A03EFBCD68F62A9A2 |
SHA-256 | 9CF39AC46A292F147E979EAD9E564AB97D9153E588C1D84C4EF1ACD768B1A798 |
SSDEEP | 48:efyajvqCgHDg4yUjHTYyZVY1ZN8HFoTJc7ICsPlZGUA3:efy8QHEwT/ZMZGoc7ItPTGp3 |
TLSH | T1D851CA4E5520DEB0190906B5118BA1D9332549D3EA6F5C1CBC2EC24EAFE9EB782715EC |
Key | Value |
---|---|
FileName | ./var/lib/prelude-correlator/prelude-correlator/spamhaus_drop.dat |
FileSize | 23462 |
MD5 | 2E8B0769E7870B126E9443938EF8DBF2 |
SHA-1 | 19CB1831C2D535E48F682AF417260AAB7C958A90 |
SHA-256 | BA1C8C20EAD1C3F2806E33C5395C7F2C1AA3AEB5DA2FD103092C21D60350DE9E |
SSDEEP | 384:jmrtXIiAhWpChsVsSuTlejtz5mupgJWGt8r/KB9dsv/Tef80mLuIVC3qKclFe6Tn:jg4PPNJz/u |
TLSH | T1C5B235F1AEF51AFF88E0609BD63FC639B117A5C1B1E2B7525F4F2214781A480762F918 |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/WormPlugin.py |
FileSize | 3357 |
MD5 | B3C6B0D1AB042B4E768EBAAEC4FEC5F0 |
SHA-1 | 1D31FBF8F13ECB795099849F589E2C8F005BB4E2 |
SHA-256 | 41034847A0810EF3406111A67CB61CCD4D487DBD7FA27C19C72B49E5D3013441 |
SSDEEP | 96:efy8mEwT+xpn31ZQKhz/r7/N/Kv9OZGFB:Ay8LwT+731xjV/i4c |
TLSH | T1B961A85D1320DFB6668302B2208BB2E67315C6E3461B6C2C796DC29C6FA2DB541739F8 |
Key | Value |
---|---|
FileName | ./usr/share/doc/packages/prelude-correlator/NEWS |
FileSize | 17216 |
MD5 | 9FA57560F9FF7B1748AE4854386DDDB6 |
SHA-1 | 28C2D3930919BC88533EAE50F21B6225B6F32965 |
SHA-256 | 23B119EF5E18826502B1ACFDE8A9FF71E0FE10F3DD1DDF347A3FFAC581BFAE85 |
SSDEEP | 384:MAQJMpN4mtKUdLA+pR+Y9DQFBKmWOgyrx:7+wHvWmOgw |
TLSH | T16072A8E277343722799227A6D2CB41D97718A1EB9233D0347B9895C87A03063D3776CB |
Key | Value |
---|---|
FileName | ./etc/prelude-correlator/rules/python/DshieldPlugin.py |
FileSize | 3536 |
MD5 | 911A6228F1B4C7F0AC711DC78102B526 |
SHA-1 | 2A3C499F9B005C9DAA00E17F8612BE60FE1573E6 |
SHA-256 | FD25F1CCE4332857A9F62D2F7EC6AACEFFF3926C03F567C81916994567616970 |
SSDEEP | 96:efy/lHEwTATFd08rQQBfTO1MMpy686PHiH:AySwTJ8RipPrviH |
TLSH | T12C71B7BF157AC9929783528665CA20C1332DB6C3801F8044FEBCE288BFA4D71C2B1DD5 |
Key | Value |
---|---|
FileName | ./usr/share/doc/packages/prelude-correlator/AUTHORS |
FileSize | 128 |
MD5 | 32AAD8CED8E624DBAE0EEF31DD5C5DA2 |
SHA-1 | 2DCA4EF98E77B78023183690BE189F207D0CBEB5 |
SHA-256 | 9F03F7E1D1DA2CC073BA5352210820D7FCF8E8BD72D849D0BA20003D958A51D9 |
SSDEEP | 3:L2bKgJEiMEuR9j9Vf0S4ie82ZsM+aENzpzeLKbvn:L2rQEe59J4r82aaeNLn |
TLSH | T1A5B02BCC166031372C0388083252C9E3014038E186FC8090B610D0C275330015400242 |
Key | Value |
---|---|
FileName | ./usr/lib/systemd/system/prelude-correlator.service |
FileSize | 194 |
MD5 | 1F1D940001273114605E9B99F80D4405 |
SHA-1 | 3FE6BB59CDA8E4BF01163C7674E014F9CDF2E058 |
SHA-256 | C079F30A8EEA2B91640571A4EFDEC7E3152A68487C975660C1DB98FD0FC379AD |
SSDEEP | 6:z83Xn6vAf8D2ClEXN5aXjyADMzdK+aA2LQmWA4Rv:z9vfiCeXNwTTDOK+aA2LHWrv |
TLSH | T19FC02281A7A234E99E192A2EAB13C3C019A510C90B5AE1603FF128ACB4D1A9581305E6 |
Key | Value |
---|---|
CRC32 | 4E46F4A1 |
FileName | usr/share/doc/vifm/COPYING |
FileSize | 18092 |
KnownMalicious | malshare.com |
MD5 | B234EE4D69F5FCE4486A80FDAF4A4263 |
OpSystemCode | 362 |
ProductCode | 15109 |
RDS:package_id | 318968 |
SHA-1 | 4CC77B90AF91E615A64AE04893FDFFA7939DB84C |
SHA-256 | 8177F97513213526DF2CF6184D8FF986C675AFB514D4E68A404010521B880643 |
SHA-512 | AEE80B1F9F7F4A8A00DCF6E6CE6C41988DCAEDC4DE19D9D04460CBFB05D99829FFE8F9D038468EABBFBA4D65B38E8DBEF5ECF5EB8A1B891D9839CDA6C48EE957 |
SSDEEP | 384:ghUwi5rpL676yV12rPd34ZomzM2FR+dWF7jUI:gmFWixMFzMdm7jUI |
SpecialCode | |
TLSH | T13A82A42E770443F205C202A16A4F68DFA32AD5B9723E1155386DC15E236FE35C3BFA99 |
db | nsrl_legacy |
insert-timestamp | 1735817250.2027707 |
mimetype | text/plain |
nsrl-sha256 | rds241-sha256.zip |
source | snap:OtzMxnIemajqYJlxNY3Ed4r6TROQn7lo_813 |
tar:gname | root |
tar:uname | root |
Key | Value |
---|---|
FileName | ./usr/share/doc/packages/prelude-correlator/HACKING.README |
FileSize | 770 |
MD5 | 4022F3C9167B8E3F4F00AB7463FC72D9 |
SHA-1 | 4CDCF00FC5E307B193B88F9B3F2F9AE24A895A02 |
SHA-256 | AC6E0BBCBD0C7DB39C5E7EDBDB02F995C3763D2605EFD3B40272ED2CCC7ECE8A |
SSDEEP | 12:hBeVtOrqLRh1y4A4gnFbyE0MevyCmFQMl9Kr1yAHkxbpfgtthcAkU5tDWg2:XG4rqLvw4PgxM5yCmFjqNHkxNEeAvW |
TLSH | T12101F11EF26C2264184105A17682E3E2620B41DA8B319432B206D4C573BBA7E853F5DD |
Key | Value |
---|---|
CRC32 | E19D9AD2 |
FileName | ./usr/sbin/rcznc |
FileSize | 7 |
MD5 | AAABF0D39951F3E6C3E8A7911DF524C2 |
OpSystemCode | 362 |
ProductCode | 183711 |
RDS:package_id | 263811 |
SHA-1 | 4CF5BC59BEE9E1C44C6254B5F84E7F066BD8E5FE |
SHA-256 | 9DF6B026A8C6C26E3C3ACD2370A16E93FFFDC0015FF5BD879218788025DB0280 |
SSDEEP | 3:jg:jg |
SpecialCode | |
TLSH | |
db | nsrl_modern_rds |
insert-timestamp | 1654961073.836576 |
source | modern.db |