Key | Value |
---|---|
MD5 | A1FD9591193692496E96BD96C819F5F7 |
PackageArch | i586 |
PackageDescription | The Prelude Log Monitoring Lackey (LML) is the host-based sensor program part of the Prelude SIEM suite. It can act as a centralized log collector for local or remote systems, or as a simple log analyzer (such as swatch). It can run as a network server listening on a syslog port or analyze log files. It supports logfiles in the BSD syslog format and is able to analyze any logfile by using the PCRE library. It can apply logfile-specific analysis through plugins such as PAX. It can send an alert to the Prelude Manager when a suspicious log entry is detected. |
PackageMaintainer | squidf <squidf> |
PackageName | prelude-lml |
PackageRelease | 5.mga9 |
PackageVersion | 5.2.0 |
SHA-1 | E02CDEBFF7D534225816F2709FBC434BA998FBAD |
SHA-256 | A12652C3A81C40841728898C8342FDDE795B7C435FF4A3B3884326BA959E1038 |
hashlookup:children-total | 15 |
hashlookup:trust | 50 |
The searched file hash includes 15 children files known and seen by metalookup. A sample is included below:
Key | Value |
---|---|
FileName | ./etc/rc.d/init.d/prelude-lml |
FileSize | 1356 |
MD5 | F37EBF9D3EFA954629F54C42F758B519 |
SHA-1 | F1E5A2D6E6BDA5458F3D3723EA0BCD10AB7C41E8 |
SHA-256 | 317DF5AAA76C2B228B7141F74781454BBD3D42138A2589DCF6520CEBA85741AF |
SSDEEP | 24:F/Cvr+MbWqswPIuJ6yMb/MbPNqRIJq/EHOx20Tv7GPrJuZ94WDjK:FqDUNwwE66N+MHOhTCOTjK |
TLSH | T1A32111F73034B9318D2F0A98C49DE7F92D31A10F81A3FCFAA03A66D1108919A85B8875 |
Key | Value |
---|---|
FileName | ./usr/share/doc/packages/prelude-lml/NEWS |
FileSize | 31061 |
MD5 | 85B8445552C67AD410134D4E0C752101 |
SHA-1 | E4B5A542C525561450711F7278BC05699264D725 |
SHA-256 | 0B8685A1B42DCC25D7D295A8EE7A6300520E43BA74BB44096D72C52707042D43 |
SSDEEP | 384:xrPK/o951i9ipVVMebv4r9zOXIgMRbEmY/ZzzA+g6ha5FTjTzl+xcJYUDD7a4EW:ZS/e6ipVBy9CXI5FEmazzA+gMg9Kqau |
TLSH | T1A5D2E8A2B66833261A521DBAD1CA81D3EF7C786FD353B5A039CD45C83F01471D2F6A98 |
Key | Value |
---|---|
FileName | ./etc/prelude-lml/plugins.rules |
FileSize | 836 |
MD5 | 446480A94DE7E09917ACD9C48361234B |
SHA-1 | CCC52AC2BE9F8DCFFA54115CD8F46FC7995DC8D5 |
SHA-256 | 6E009A53AD344BD1563EA2A2B79A8D3F53886948567979355EA3FCCD2C3F6BF9 |
SSDEEP | 24:SslZ+0CJBxd1ayS3EPSR0LSjTWdEkoF7lS5EPgLRSaAgm:S++0CJBX1ayS3yS+LSncEnS5ygLqgm |
TLSH | T172014C1F878D253101E584E23099E1D9462AD2D9ABF0E091F7DE855C6B3497E51A9D40 |
tar:gname | bin |
tar:uname | root |
Key | Value |
---|---|
FileName | ./usr/sbin/prelude-lml |
FileSize | 135904 |
MD5 | DC32427CDABA585B17CD80937E691FF3 |
SHA-1 | 911D5D0FCD5C2BCD89217214E2525D1530DD85CA |
SHA-256 | FD0EA61352545C5F1226DDCB8FA4D82FB820B6532866E31A9E18181F919ADBA7 |
SSDEEP | 3072:AAAUMVDUkRweA64NZhKJdlPZvHD/JJahokDiSGKTYUV:RMlRweZ06JdlPh7/aokGSGKEU |
TLSH | T1E1D31959B347C8F2E2E209F8075B83A125215509F193F6B2FE4DA7A83432658BF1B375 |
Key | Value |
---|---|
FileName | ./usr/share/doc/packages/prelude-lml/HACKING.README |
FileSize | 780 |
MD5 | CE979EC4C4C9FD55949BA6867F0EB356 |
SHA-1 | 2D6ACFF0197B79132F46DBE5FAFAC14975C0E1F0 |
SHA-256 | 5CE75927A9FE75588107C5E2A7BF5979807A22A5AA9F21DFB3EB7497F9FB6DDB |
SSDEEP | 12:hBe+oVOrqLRh15X2voInFi2yE0MevyCmFQMl9Kr1yAHkxbpfgtthcAkU5tDWg2:XywrqLvzHIE2M5yCmFjqNHkxNEeAvW |
TLSH | T13E01F11EF36C62A8254609917282E3F6A20F41DACB214431E116D4C533BAA7E853F5DD |
Key | Value |
---|---|
CRC32 | 4E46F4A1 |
FileName | ./usr/share/cmake/Templates/fedora/gpl-2.0.txt |
FileSize | 18092 |
KnownMalicious | malshare.com |
MD5 | B234EE4D69F5FCE4486A80FDAF4A4263 |
OpSystemCode | 362 |
ProductCode | 15109 |
RDS:package_id | 313212 |
SHA-1 | 4CC77B90AF91E615A64AE04893FDFFA7939DB84C |
SHA-256 | 8177F97513213526DF2CF6184D8FF986C675AFB514D4E68A404010521B880643 |
SHA-512 | AEE80B1F9F7F4A8A00DCF6E6CE6C41988DCAEDC4DE19D9D04460CBFB05D99829FFE8F9D038468EABBFBA4D65B38E8DBEF5ECF5EB8A1B891D9839CDA6C48EE957 |
SSDEEP | 384:ghUwi5rpL676yV12rPd34ZomzM2FR+dWF7jUI:gmFWixMFzMdm7jUI |
SpecialCode | |
TLSH | T13A82A42E770443F205C202A16A4F68DFA32AD5B9723E1155386DC15E236FE35C3BFA99 |
db | nsrl_legacy |
insert-timestamp | 1728991626.679368 |
mimetype | text/plain |
nsrl-sha256 | rds241-sha256.zip |
source | snap:MmD5jWldYNMNgb2rFFht3FNKGJx1FLLV_613 |
tar:gname | root |
tar:uname | root |
Key | Value |
---|---|
FileName | ./usr/lib/prelude-lml/debug.so |
FileSize | 14608 |
MD5 | 81D0F8501611CF150B64BFF7B00815CD |
SHA-1 | 0DB35E27E222CBDE2CA679857AA372ADA39E461C |
SHA-256 | F963501EABAFE5313136E533A94684DE4B8A17D1B03DDF3AFF89D47CB68C70E1 |
SSDEEP | 96:tx1V/2GMBWBcO976L5uXX3Qa/c2mtcJw+BaTBhTXPTamyRhZ9uvcbKXOoroVvMb4:L/E80tuXX3Qgc2T2fXL6wk2XOVPk |
TLSH | T1E062F657BB69C932E2825B38406747A172328135C6B3C7737F2823982D613A4EF63679 |
Key | Value |
---|---|
FileName | ./usr/lib/prelude-lml/pcre.so |
FileSize | 40232 |
MD5 | 1B59241E99583E8B8F1E12EA757880C1 |
SHA-1 | 7676F098C14348D88861895C86540D8D4B8F9796 |
SHA-256 | 0BD41C6BCDC2087BDD65845E2E80A9AAA54F13E609F952E6D906FB6B8F7B6C29 |
SSDEEP | 768:JKSXpXcrgAcIRrfTRlHCc5pJDNwscUaP+tkssHnKqY/C:LpXcrgAcsrtXnJ44ksbR/ |
TLSH | T19403195BF786C4B5F29206F54B47C3A5A6308006D267F1A0FB09735EB8723146E3A27D |
Key | Value |
---|---|
FileName | ./usr/lib/.build-id/63/02b6bfc25846d647ba4dec993ff3f4dd83ed58 |
FileSize | 32 |
MD5 | 5E93B0CD1DA9245551389EFF574F33AD |
SHA-1 | AD0C142622AB684C99FF78FF69DF971427E5E5BF |
SHA-256 | 38BEDF3DAE95EA1618C2076D21DAA4468A8F3E85C5C777CC68A612ADED4C6F78 |
SSDEEP | 3:gCD2MI:X2R |
TLSH |
Key | Value |
---|---|
FileName | ./usr/share/doc/packages/prelude-lml/README |
FileSize | 1742 |
MD5 | A5924B09DE4B82B6F15A5BE943CA79F2 |
SHA-1 | CBF9D34C6A6077CE6250E1E681663EBFF1E19795 |
SHA-256 | E36B8D95200965696F8FB79B0338C070E7A370B6B52F1227F7187AC201B3B4E0 |
SSDEEP | 24:ykwdzTaLVNECo7w5QlXlunfy1XICIrYKZQgDnJkt8MswCHJfVKcDwaq+ygXA:SwECo7Hlua1XtKZQg1kt8DXJfVsP |
TLSH | T1AE3116FFA2687270734525C87216E0FBCBA375AEE2602571FC9C94D5632A39C4236B85 |
Key | Value |
---|---|
FileName | ./usr/lib/.build-id/f6/26592f65c719541dad587990993c382e698b90 |
FileSize | 40 |
MD5 | 58499137AF55413F1A790DF1276475BE |
SHA-1 | F8A28EE6FC70F1DCF6281DC75C135E4437D25341 |
SHA-256 | D384406137AF099CE08DE644E5C71F51BC6011AE0C5F0B2706F94E0ADCAF0177 |
SSDEEP | 3:gCD/43BEN:X/cEN |
TLSH |
Key | Value |
---|---|
FileName | ./etc/prelude-lml/prelude-lml.conf |
FileSize | 7191 |
MD5 | 9F413DD828C3D401762CECA4E2CFC919 |
SHA-1 | 3200F3F42A0E4F69CADCE4AF0D8E14A8675C0503 |
SHA-256 | FC654F5231D96AEB077CD59B575F729FD8BCE12F7D216BD4316727488150E851 |
SSDEEP | 192:mKqkehijEnNUiMyB0Xus6vzGogpcNadGSO25e:mkSkUsW+OP |
TLSH | T12DE17566D24D363B13CF13A150AEE2DD9B3D904D6E73302162DD98687201E7892FBBE5 |
Key | Value |
---|---|
FileName | ./usr/lib/.build-id/42/11fcc96abda84a0084958a012692ab7b290626 |
FileSize | 39 |
MD5 | 6F87625166C749D56E7DE47B4540D9CC |
SHA-1 | 1B8FB5D8F908ADA66F834EAF2300867BED10D070 |
SHA-256 | 177A01BD24FE3F54F653D5C1345A4FF32C40BD456E7A6B7E414B37051AB1B1E8 |
SSDEEP | 3:gCD/43VwKn:X/IwK |
TLSH |
Key | Value |
---|---|
FileName | ./usr/share/doc/prelude-lml-devel/ChangeLog |
FileSize | 771768 |
MD5 | 83C8AA0A95497A11ED226358F445FAE6 |
SHA-1 | 937A27D61489121D4D9BFB59944AD48017AFDD2F |
SHA-256 | 5193D5C7D963831CBEAD5B77EA8EB9119BCE8BCC84B17AB7AF748898199D2509 |
SSDEEP | 6144:Hg9tZYmUQdDwhi0dps2aj5UnQX7fJUDSdLnD76H/1TslUWBIpzB+KgQg:A9tZYmUQdDwFMbVUU7fJUDenD7QCBI9g |
TLSH | T11DF44ED79E3E25132175E3B385A06092BE4BF2DF6325A4B8397DB1C4DF0971412BEA09 |
Key | Value |
---|---|
FileName | ./usr/share/doc/prelude-lml/AUTHORS |
FileSize | 114 |
MD5 | CF3E49FA50248D0A0C89D6BF622736A3 |
SHA-1 | FE9280DEC27F2D0D2AD673B55345C7574355FBF0 |
SHA-256 | EC48BA539A4569DC26AF5D609E14ECB759A63231760E2ABB7D920A0BA1D5A811 |
SSDEEP | 3:L2UorMXR9D9Vf0S4FQXMqKEL1pz0tYMKn:L2UorMB9T4+MqKEh+YMKn |
TLSH | T144B012ED2138B05B7F43984C5265D4E79DD33DEAC17080D77A30F4D107740515428381 |