malware-dataset/linux/b87ad7dba1d367c437db51045e57835f77e8d9735d5c917c6d16984fbde8a3c5/analysis/sample.svg

76 lines
6.8 KiB
XML

<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN"
"http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
<!-- Generated by graphviz version 11.0.0 (0)
-->
<!-- Pages: 1 -->
<svg width="354pt" height="223pt"
viewBox="0.00 0.00 354.00 222.50" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink">
<g id="graph0" class="graph" transform="scale(1 1) rotate(0) translate(4 218.5)">
<polygon fill="white" stroke="none" points="-4,4 -4,-218.5 350,-218.5 350,4 -4,4"/>
<!-- guuid=b11c622b&#45;0b00&#45;0000&#45;bc0f&#45;2f2859040000 pid=1113 -->
<g id="node1" class="node">
<title>guuid=b11c622b&#45;0b00&#45;0000&#45;bc0f&#45;2f2859040000 pid=1113</title>
<path fill="white" stroke="black" d="M81.75,-178C81.75,-178 151,-178 151,-178 157,-178 163,-184 163,-190 163,-190 163,-202 163,-202 163,-208 157,-214 151,-214 151,-214 81.75,-214 81.75,-214 75.75,-214 69.75,-208 69.75,-202 69.75,-202 69.75,-190 69.75,-190 69.75,-184 75.75,-178 81.75,-178"/>
<text text-anchor="middle" x="116.38" y="-190.57" font-family="Arial" font-size="14.00">/usr/bin/sudo</text>
</g>
<!-- guuid=57ed1f2c&#45;0b00&#45;0000&#45;bc0f&#45;2f285a040000 pid=1114 -->
<g id="node2" class="node">
<title>guuid=57ed1f2c&#45;0b00&#45;0000&#45;bc0f&#45;2f285a040000 pid=1114</title>
<path fill="white" stroke="black" d="M74.25,-89.25C74.25,-89.25 158.5,-89.25 158.5,-89.25 164.5,-89.25 170.5,-95.25 170.5,-101.25 170.5,-101.25 170.5,-113.25 170.5,-113.25 170.5,-119.25 164.5,-125.25 158.5,-125.25 158.5,-125.25 74.25,-125.25 74.25,-125.25 68.25,-125.25 62.25,-119.25 62.25,-113.25 62.25,-113.25 62.25,-101.25 62.25,-101.25 62.25,-95.25 68.25,-89.25 74.25,-89.25"/>
<text text-anchor="middle" x="116.38" y="-101.83" font-family="Arial" font-size="14.00">/usr/bin/newgrp</text>
</g>
<!-- guuid=b11c622b&#45;0b00&#45;0000&#45;bc0f&#45;2f2859040000 pid=1113&#45;&gt;guuid=57ed1f2c&#45;0b00&#45;0000&#45;bc0f&#45;2f285a040000 pid=1114 -->
<g id="edge1" class="edge">
<title>guuid=b11c622b&#45;0b00&#45;0000&#45;bc0f&#45;2f2859040000 pid=1113&#45;&gt;guuid=57ed1f2c&#45;0b00&#45;0000&#45;bc0f&#45;2f285a040000 pid=1114</title>
<path fill="none" stroke="black" d="M116.38,-177.86C116.38,-166.17 116.38,-150.42 116.38,-136.85"/>
<polygon fill="black" stroke="black" points="119.88,-137.16 116.38,-127.16 112.88,-137.16 119.88,-137.16"/>
<text text-anchor="middle" x="137.75" y="-146.2" font-family="Arial" font-size="14.00">execve</text>
</g>
<!-- guuid=b8c1c52c&#45;0b00&#45;0000&#45;bc0f&#45;2f285c040000 pid=1116 -->
<g id="node5" class="node">
<title>guuid=b8c1c52c&#45;0b00&#45;0000&#45;bc0f&#45;2f285c040000 pid=1116</title>
<path fill="white" stroke="black" d="M12,-0.5C12,-0.5 100.75,-0.5 100.75,-0.5 106.75,-0.5 112.75,-6.5 112.75,-12.5 112.75,-12.5 112.75,-24.5 112.75,-24.5 112.75,-30.5 106.75,-36.5 100.75,-36.5 100.75,-36.5 12,-36.5 12,-36.5 6,-36.5 0,-30.5 0,-24.5 0,-24.5 0,-12.5 0,-12.5 0,-6.5 6,-0.5 12,-0.5"/>
<text text-anchor="middle" x="56.38" y="-13.07" font-family="Arial" font-size="14.00">/tmp/sample.bin</text>
</g>
<!-- guuid=57ed1f2c&#45;0b00&#45;0000&#45;bc0f&#45;2f285a040000 pid=1114&#45;&gt;guuid=b8c1c52c&#45;0b00&#45;0000&#45;bc0f&#45;2f285c040000 pid=1116 -->
<g id="edge3" class="edge">
<title>guuid=57ed1f2c&#45;0b00&#45;0000&#45;bc0f&#45;2f285a040000 pid=1114&#45;&gt;guuid=b8c1c52c&#45;0b00&#45;0000&#45;bc0f&#45;2f285c040000 pid=1116</title>
<path fill="none" stroke="black" stroke-dasharray="1,5" d="M104.52,-89.11C96.03,-76.83 84.43,-60.07 74.75,-46.06"/>
<polygon fill="black" stroke="black" points="77.84,-44.38 69.27,-38.15 72.08,-48.36 77.84,-44.38"/>
<text text-anchor="middle" x="108.5" y="-57.45" font-family="Arial" font-size="14.00">clone</text>
</g>
<!-- guuid=cae6f62e&#45;0b00&#45;0000&#45;bc0f&#45;2f285d040000 pid=1117 -->
<g id="node6" class="node">
<title>guuid=cae6f62e&#45;0b00&#45;0000&#45;bc0f&#45;2f285d040000 pid=1117</title>
<path fill="white" stroke="black" d="M142.75,-0.5C142.75,-0.5 212,-0.5 212,-0.5 218,-0.5 224,-6.5 224,-12.5 224,-12.5 224,-24.5 224,-24.5 224,-30.5 218,-36.5 212,-36.5 212,-36.5 142.75,-36.5 142.75,-36.5 136.75,-36.5 130.75,-30.5 130.75,-24.5 130.75,-24.5 130.75,-12.5 130.75,-12.5 130.75,-6.5 136.75,-0.5 142.75,-0.5"/>
<text text-anchor="middle" x="177.38" y="-13.07" font-family="Arial" font-size="14.00">/usr/bin/bash</text>
</g>
<!-- guuid=57ed1f2c&#45;0b00&#45;0000&#45;bc0f&#45;2f285a040000 pid=1114&#45;&gt;guuid=cae6f62e&#45;0b00&#45;0000&#45;bc0f&#45;2f285d040000 pid=1117 -->
<g id="edge4" class="edge">
<title>guuid=57ed1f2c&#45;0b00&#45;0000&#45;bc0f&#45;2f285a040000 pid=1114&#45;&gt;guuid=cae6f62e&#45;0b00&#45;0000&#45;bc0f&#45;2f285d040000 pid=1117</title>
<path fill="none" stroke="black" d="M128.43,-89.11C137.06,-76.83 148.85,-60.07 158.7,-46.06"/>
<polygon fill="black" stroke="black" points="161.38,-48.33 164.27,-38.14 155.65,-44.31 161.38,-48.33"/>
<text text-anchor="middle" x="173.75" y="-57.45" font-family="Arial" font-size="14.00">execve</text>
</g>
<!-- guuid=a493e31f&#45;0000&#45;0000&#45;bc0f&#45;2f2801000000 pid=1 -->
<g id="node3" class="node">
<title>guuid=a493e31f&#45;0000&#45;0000&#45;bc0f&#45;2f2801000000 pid=1</title>
<path fill="white" stroke="black" d="M192.75,-178C192.75,-178 334,-178 334,-178 340,-178 346,-184 346,-190 346,-190 346,-202 346,-202 346,-208 340,-214 334,-214 334,-214 192.75,-214 192.75,-214 186.75,-214 180.75,-208 180.75,-202 180.75,-202 180.75,-190 180.75,-190 180.75,-184 186.75,-178 192.75,-178"/>
<text text-anchor="middle" x="263.38" y="-190.57" font-family="Arial" font-size="14.00">/usr/lib/systemd/systemd</text>
</g>
<!-- guuid=2f5bc22c&#45;0b00&#45;0000&#45;bc0f&#45;2f285b040000 pid=1115 -->
<g id="node4" class="node">
<title>guuid=2f5bc22c&#45;0b00&#45;0000&#45;bc0f&#45;2f285b040000 pid=1115</title>
<path fill="white" stroke="black" d="M220.5,-89.25C220.5,-89.25 306.25,-89.25 306.25,-89.25 312.25,-89.25 318.25,-95.25 318.25,-101.25 318.25,-101.25 318.25,-113.25 318.25,-113.25 318.25,-119.25 312.25,-125.25 306.25,-125.25 306.25,-125.25 220.5,-125.25 220.5,-125.25 214.5,-125.25 208.5,-119.25 208.5,-113.25 208.5,-113.25 208.5,-101.25 208.5,-101.25 208.5,-95.25 214.5,-89.25 220.5,-89.25"/>
<text text-anchor="middle" x="263.38" y="-101.83" font-family="Arial" font-size="14.00">/usr/bin/passwd</text>
</g>
<!-- guuid=a493e31f&#45;0000&#45;0000&#45;bc0f&#45;2f2801000000 pid=1&#45;&gt;guuid=2f5bc22c&#45;0b00&#45;0000&#45;bc0f&#45;2f285b040000 pid=1115 -->
<g id="edge2" class="edge">
<title>guuid=a493e31f&#45;0000&#45;0000&#45;bc0f&#45;2f2801000000 pid=1&#45;&gt;guuid=2f5bc22c&#45;0b00&#45;0000&#45;bc0f&#45;2f285b040000 pid=1115</title>
<path fill="none" stroke="black" d="M263.38,-177.86C263.38,-166.17 263.38,-150.42 263.38,-136.85"/>
<polygon fill="black" stroke="black" points="266.88,-137.16 263.38,-127.16 259.88,-137.16 266.88,-137.16"/>
<text text-anchor="middle" x="284.75" y="-146.2" font-family="Arial" font-size="14.00">execve</text>
</g>
</g>
</svg>