diff --git a/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7 b/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7 new file mode 100644 index 0000000..9d64b94 Binary files /dev/null and b/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7 differ diff --git a/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/analysis.yaml b/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/analysis.yaml new file mode 100644 index 0000000..dcbb5e9 --- /dev/null +++ b/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/analysis.yaml @@ -0,0 +1,14 @@ +analysis: + duration_sec: 60 + timestamp: '2024-07-02T08:42:53.080025+00:00' +kunai: + args: + - --include=all + - --send-data-min-len=0 + version: kunai 0.2.4 +sample: + args: [] +system: + kernel: 5.10.0-30-cloud-amd64 + uname: 'Linux kunai-sandbox 5.10.0-30-cloud-amd64 #1 SMP Debian 5.10.218-1 (2024-06-01) + x86_64 GNU/Linux' diff --git a/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/dump.pcap b/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/dump.pcap new file mode 100644 index 0000000..0914a9d Binary files /dev/null and b/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/dump.pcap differ diff --git a/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/kunai.jsonl.gz b/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/kunai.jsonl.gz new file mode 100644 index 0000000..1a33cae Binary files /dev/null and b/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/kunai.jsonl.gz differ diff --git a/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/kunai.stderr b/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/kunai.stderr new file mode 100644 index 0000000..d61efcd --- /dev/null +++ b/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/kunai.stderr @@ -0,0 +1,2 @@ +[2024-06-17T10:05:51Z WARN kunai] syscalls_sys_exit_execve probe is not compatible with current kernel: min=KernelVersion::MIN max=5.9.0 current=5.10.0 +[2024-06-17T10:05:52Z WARN kunai] syscalls_sys_exit_execveat probe is not compatible with current kernel: min=KernelVersion::MIN max=5.9.0 current=5.10.0 diff --git a/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/sample.stderr b/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/sample.stderr new file mode 100644 index 0000000..8d8b30a --- /dev/null +++ b/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/sample.stderr @@ -0,0 +1 @@ +sh: 1: esxcli: not found diff --git a/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/sample.stdout b/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/sample.stdout new file mode 100644 index 0000000..e69de29 diff --git a/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/sample.svg b/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/sample.svg new file mode 100644 index 0000000..2b58ac4 --- /dev/null +++ b/linux/776ea636ee33aab6b2db5f46889b027c297280db37400efb091e0d4a9001a7d7/analysis/sample.svg @@ -0,0 +1,835 @@ + + + + + + +%3 + + + +guuid=6124f83f-0b00-0000-c59d-34a863040000 pid=1123 + +/usr/bin/sudo + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124 + +/tmp/sample.bin + +write-file + + + +guuid=6124f83f-0b00-0000-c59d-34a863040000 pid=1123->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124 + + +execve + + + +guuid=ac61e840-0b00-0000-c59d-34a865040000 pid=1125 + +/usr/bin/dash + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=ac61e840-0b00-0000-c59d-34a865040000 pid=1125 + + +execve + + + +guuid=29aa1741-0b00-0000-c59d-34a868040000 pid=1128 + +/usr/bin/dash + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=29aa1741-0b00-0000-c59d-34a868040000 pid=1128 + + +execve + + + +guuid=09487741-0b00-0000-c59d-34a86b040000 pid=1131 + +/usr/bin/dash + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=09487741-0b00-0000-c59d-34a86b040000 pid=1131 + + +execve + + + +guuid=ca40b644-0b00-0000-c59d-34a86d040000 pid=1133 + +/usr/bin/dash + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=ca40b644-0b00-0000-c59d-34a86d040000 pid=1133 + + +execve + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1136 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1136 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1137 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1137 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1138 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1138 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1139 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1139 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1140 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1140 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1141 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1141 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1142 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1142 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1143 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1143 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1144 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1144 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1145 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1145 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1146 + +/tmp/sample.bin + +write-file + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1146 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1147 + +/tmp/sample.bin + +write-file + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1147 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1148 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1148 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1149 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1149 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1150 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1150 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1151 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1151 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1152 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1152 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1153 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1153 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1154 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1154 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1155 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1155 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1156 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1156 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1157 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1157 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1158 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1158 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1159 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1159 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1160 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1160 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1161 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1161 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1162 + +/tmp/sample.bin + +write-file + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1162 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1163 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1163 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1164 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1164 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1165 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1165 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1166 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1166 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1167 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1167 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1168 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1168 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1169 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1169 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1170 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1170 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1171 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1171 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1172 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1172 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1173 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1173 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1174 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1174 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1175 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1175 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1176 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1176 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1177 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1177 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1178 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1178 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1179 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1179 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1180 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1180 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1181 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1181 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1182 + +/tmp/sample.bin + +write-file + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1182 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1183 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1183 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1184 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1184 + + +clone + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1185 + +/tmp/sample.bin + + + +guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1124->guuid=9ff89940-0b00-0000-c59d-34a864040000 pid=1185 + + +clone + + + +guuid=9cabf840-0b00-0000-c59d-34a866040000 pid=1126 + +/usr/bin/uname + + + +guuid=ac61e840-0b00-0000-c59d-34a865040000 pid=1125->guuid=9cabf840-0b00-0000-c59d-34a866040000 pid=1126 + + +execve + + + +guuid=82340841-0b00-0000-c59d-34a867040000 pid=1127 + +/usr/bin/hostname + + + +guuid=ac61e840-0b00-0000-c59d-34a865040000 pid=1125->guuid=82340841-0b00-0000-c59d-34a867040000 pid=1127 + + +execve + + + +guuid=087d2441-0b00-0000-c59d-34a869040000 pid=1129 + +/usr/bin/uname + + + +guuid=29aa1741-0b00-0000-c59d-34a868040000 pid=1128->guuid=087d2441-0b00-0000-c59d-34a869040000 pid=1129 + + +execve + + + +guuid=cefa3141-0b00-0000-c59d-34a86a040000 pid=1130 + +/usr/bin/hostname + + + +guuid=29aa1741-0b00-0000-c59d-34a868040000 pid=1128->guuid=cefa3141-0b00-0000-c59d-34a86a040000 pid=1130 + + +execve + + + +guuid=b24f9a41-0b00-0000-c59d-34a86c040000 pid=1132 + +/usr/bin/pgrep + + + +guuid=09487741-0b00-0000-c59d-34a86b040000 pid=1131->guuid=b24f9a41-0b00-0000-c59d-34a86c040000 pid=1132 + + +execve + + + +guuid=e82ce244-0b00-0000-c59d-34a86e040000 pid=1134 + +/usr/bin/dash + + + +guuid=ca40b644-0b00-0000-c59d-34a86d040000 pid=1133->guuid=e82ce244-0b00-0000-c59d-34a86e040000 pid=1134 + + +clone + + + +guuid=c163e444-0b00-0000-c59d-34a86f040000 pid=1135 + +/usr/bin/mawk + + + +guuid=ca40b644-0b00-0000-c59d-34a86d040000 pid=1133->guuid=c163e444-0b00-0000-c59d-34a86f040000 pid=1135 + + +execve + + +