mirror of
https://github.com/zeek/zeek.git
synced 2025-10-09 10:08:20 +00:00

Conflicts: scripts/base/protocols/ftp/file-analysis.bro scripts/base/protocols/http/file-analysis.bro scripts/base/protocols/irc/file-analysis.bro scripts/base/protocols/smtp/file-analysis.bro src/file_analysis/File.cc src/file_analysis/File.h src/file_analysis/Manager.cc src/file_analysis/Manager.h testing/btest/Baseline/scripts.base.frameworks.file-analysis.logging/file_analysis.log testing/btest/Baseline/scripts.base.protocols.ftp.ftp-extract/ftp-item-0.dat testing/btest/Baseline/scripts.base.protocols.ftp.ftp-extract/ftp-item-1.dat testing/btest/Baseline/scripts.base.protocols.ftp.ftp-extract/ftp-item-2.dat testing/btest/Baseline/scripts.base.protocols.ftp.ftp-extract/ftp-item-3.dat testing/btest/Baseline/scripts.base.protocols.ftp.ftp-extract/ftp-item-BTsa70Ua9x7-1.dat testing/btest/Baseline/scripts.base.protocols.ftp.ftp-extract/ftp-item-BTsa70Ua9x7.dat testing/btest/Baseline/scripts.base.protocols.ftp.ftp-extract/ftp-item-Rqjkzoroau4-0.dat testing/btest/Baseline/scripts.base.protocols.ftp.ftp-extract/ftp-item-Rqjkzoroau4.dat testing/btest/Baseline/scripts.base.protocols.ftp.ftp-extract/ftp-item-VLQvJybrm38-2.dat testing/btest/Baseline/scripts.base.protocols.ftp.ftp-extract/ftp-item-VLQvJybrm38.dat testing/btest/Baseline/scripts.base.protocols.ftp.ftp-extract/ftp-item-zrfwSs9K1yk-3.dat testing/btest/Baseline/scripts.base.protocols.ftp.ftp-extract/ftp-item-zrfwSs9K1yk.dat testing/btest/Baseline/scripts.base.protocols.ftp.ftp-extract/ftp.log testing/btest/Baseline/scripts.base.protocols.http.http-extract-files/http-item-BFymS6bFgT3-0.dat testing/btest/Baseline/scripts.base.protocols.http.http-extract-files/http-item-BFymS6bFgT3.dat testing/btest/Baseline/scripts.base.protocols.http.http-extract-files/http-item.dat testing/btest/Baseline/scripts.base.protocols.http.http-extract-files/http.log testing/btest/Baseline/scripts.base.protocols.irc.dcc-extract/irc-dcc-item-wqKMAamJVSb-0.dat testing/btest/Baseline/scripts.base.protocols.irc.dcc-extract/irc-dcc-item-wqKMAamJVSb.dat testing/btest/Baseline/scripts.base.protocols.irc.dcc-extract/irc-dcc-item.dat testing/btest/Baseline/scripts.base.protocols.irc.dcc-extract/irc.log testing/btest/Baseline/scripts.base.protocols.smtp.mime-extract/smtp-entity-0.dat testing/btest/Baseline/scripts.base.protocols.smtp.mime-extract/smtp-entity-1.dat testing/btest/Baseline/scripts.base.protocols.smtp.mime-extract/smtp-entity-Ltd7QO7jEv3-1.dat testing/btest/Baseline/scripts.base.protocols.smtp.mime-extract/smtp-entity-Ltd7QO7jEv3.dat testing/btest/Baseline/scripts.base.protocols.smtp.mime-extract/smtp-entity-cwR7l6Zctxb-0.dat testing/btest/Baseline/scripts.base.protocols.smtp.mime-extract/smtp-entity-cwR7l6Zctxb.dat testing/btest/Baseline/scripts.base.protocols.smtp.mime-extract/smtp_entities.log testing/btest/scripts/base/protocols/ftp/ftp-extract.bro testing/btest/scripts/base/protocols/http/http-extract-files.bro testing/btest/scripts/base/protocols/irc/dcc-extract.test testing/btest/scripts/base/protocols/smtp/mime-extract.test
68 lines
1.8 KiB
Text
68 lines
1.8 KiB
Text
FILE_NEW
|
|
file #0, 0, 0
|
|
FILE_BOF_BUFFER
|
|
/*^J********
|
|
MIME_TYPE
|
|
text/plain
|
|
FILE_STATE_REMOVE
|
|
file #0, 2675, 0
|
|
[orig_h=192.168.1.104, orig_p=1673/tcp, resp_h=63.245.209.11, resp_p=80/tcp]
|
|
source: HTTP
|
|
MD5: b932c3310ce47e158d1a5a42e0b01279
|
|
SHA1: 0e42ae17eea9b074981bd3a34535ad3a22d02706
|
|
SHA256: 5b037a2c5e36f56e63a3012c73e46a04b27741d8ff8f8b62c832fb681fc60f42
|
|
FILE_NEW
|
|
file #1, 0, 0
|
|
FILE_BOF_BUFFER
|
|
//-- Google
|
|
MIME_TYPE
|
|
text/plain
|
|
FILE_STATE_REMOVE
|
|
file #1, 21421, 0
|
|
[orig_h=192.168.1.104, orig_p=1673/tcp, resp_h=63.245.209.11, resp_p=80/tcp]
|
|
source: HTTP
|
|
MD5: e732f7bf1d7cb4eedcb1661697d7bc8c
|
|
SHA1: 8f241117afaa8ca5f41dc059e66d75c283dcc983
|
|
SHA256: 6a509fd05aa7c8fa05080198894bb19e638554ffcee0e0b3d7bc8ff54afee1da
|
|
FILE_NEW
|
|
file #2, 0, 0
|
|
FILE_BOF_BUFFER
|
|
GIF89a^D\0^D\0\xb3
|
|
MIME_TYPE
|
|
image/gif
|
|
FILE_STATE_REMOVE
|
|
file #2, 94, 0
|
|
[orig_h=192.168.1.104, orig_p=1673/tcp, resp_h=63.245.209.11, resp_p=80/tcp]
|
|
total bytes: 94
|
|
source: HTTP
|
|
MD5: d903de7e30db1691d3130ba5eae6b9a7
|
|
SHA1: 81f5f056ce5e97d940854bb0c48017b45dd9f15e
|
|
SHA256: 6fb22aa9d780ea63bd7a2e12b92b16fcbf1c4874f1d3e11309a5ba984433c315
|
|
FILE_NEW
|
|
file #3, 0, 0
|
|
FILE_BOF_BUFFER
|
|
\x89PNG^M^J^Z^J\0\0\0
|
|
MIME_TYPE
|
|
image/png
|
|
FILE_STATE_REMOVE
|
|
file #3, 2349, 0
|
|
[orig_h=192.168.1.104, orig_p=1673/tcp, resp_h=63.245.209.11, resp_p=80/tcp]
|
|
total bytes: 2349
|
|
source: HTTP
|
|
MD5: e0029eea80812e9a8e57b8d05d52938a
|
|
SHA1: 560eab5a0177246827a94042dd103916d8765ac7
|
|
SHA256: e0b4500c1fd1d675da4137461cbe64d3c8489f4180d194e47683b20e7fb876f4
|
|
FILE_NEW
|
|
file #4, 0, 0
|
|
FILE_BOF_BUFFER
|
|
\x89PNG^M^J^Z^J\0\0\0
|
|
MIME_TYPE
|
|
image/png
|
|
FILE_STATE_REMOVE
|
|
file #4, 27579, 0
|
|
[orig_h=192.168.1.104, orig_p=1673/tcp, resp_h=63.245.209.11, resp_p=80/tcp]
|
|
total bytes: 27579
|
|
source: HTTP
|
|
MD5: 30aa926344f58019d047e85ba049ca1e
|
|
SHA1: ee2b41bdef85de14ef332da14fc392f110b84249
|
|
SHA256: eb482bda230a215b90aedbfe1eee72b8193608df76a319aaf11fb85511579a1e
|