rm Rtap167801663963033 Exit:normal exit 2022-09-24 03:57:29 [Info] ClientDisConnectNotify : Rtap167801663963033 2022-09-24 03:59:08 [Info] start DownLoadNakedBuffer 100.100.100.200/2016-01-01/global-config 2022-09-24 03:59:08 [Info] DownLoadNakedBuffer ok 100.100.100.200/2016-01-01/global-config 2022-09-24 03:59:08 [Info] get empty metaserver config 2022-09-24 03:59:08 [Info] HttpPostFromBuffer Success:update2.aegis.aliyun.com/uuidRequest,code:200, ret:0 2022-09-24 03:59:08 [Info] http request ret : {"result":{"uuid":"1086fd44-ed48-4b5a-9193-fc764c9de59b"},"code":1} 2022-09-24 03:59:08 [Info] Currentuid Ret : 1086fd44-ed48-4b5a-9193-fc764c9de59b 2022-09-24 03:59:08 [Info] start DownLoadBuffer update.aegis.aliyun.com/download/cert/root.md5 2022-09-24 03:59:08 [Info] HttpGetToBuffer Success : aegis.alicdn.com/download/cert/root.md5,code:200, ret:0 2022-09-24 03:59:08 [Info] DownLoadBuffer ok update.aegis.aliyun.com/download/cert/root.md5 2022-09-24 03:59:08 [Info] empty md5 buf 2022-09-24 03:59:08 [Info] cert file in C:/Program Files (x86)/Alibaba/Aegis/globalcfg/aegis.crt not need sync 2022-09-24 03:59:19 [Info] webshell scan count, tn:12500 2022-09-24 04:01:43 [Info] GetMessage : T_MSG_CHECK 2022-09-24 04:01:43 [Info] task eyJhbGciOiJIUzI1NiJ9.eyJpYXQiOjE2NjM5NjMzMDMsImlzcyI6IlJUQVAiLCJhdWQiOiJSVEFQIiwiZXhwIjoxNjYzOTY1MTAzLCJzdWIiOiJSVEFQX0lEWF81NDg5OF8xNjYzOTYzMzAzMDQ5In0.eXdeQQjtUsgkQrYOKk-WeiEvUKpW1TYlsMl9vBBraeM has 1 items, priority is 1, aggregate is 0 2022-09-24 04:01:43 [Info] start DownLoadBuffer update.aegis.aliyun.com/download/SecureCheck/GrayList 2022-09-24 04:01:44 [Info] HttpGetToBuffer Success : aegis.alicdn.com/download/SecureCheck/GrayList,code:200, ret:0 2022-09-24 04:01:44 [Info] HttpGetToBuffer Success : aegis.alicdn.com/download/SecureCheck/GrayList.md5,code:200, ret:0 2022-09-24 04:01:44 [Info] DownLoadBuffer ok update.aegis.aliyun.com/download/SecureCheck/GrayList 2022-09-24 04:01:44 [Info] start to check remote md5 2022-09-24 04:01:44 [Info] start DownLoadFile update.aegis.aliyun.com/download/SecureCheck/Gray/win32/AliSecureCheckAdvanced.zip.md5 2022-09-24 04:01:44 [Info] HttpGetToBuffer Success : aegis.alicdn.com/download/SecureCheck/Gray/win32/AliSecureCheckAdvanced.zip.md5,code:200, ret:0 2022-09-24 04:01:44 [Info] DownLoadFile ok C:/Program Files (x86)/Alibaba/Aegis/PythonLoader/AliSecureCheckAdvanced.zip.md5.tmp 2022-09-24 04:01:44 [Info] run rtap work --sca 2022-09-24 04:01:44 [Info] ipc client:Rtap176651663963304_handler Reg client_name:Rtap176651663963304 on WhiteList 2022-09-24 04:01:44 [Info] New ClientConnectNotify : Rtap176651663963304 2022-09-24 04:01:44 [Info] ipc client:Rtap176651663963304 Reg msg_type:T_MSG_IPC_NETWORK_NOTIFY on WhiteList 2022-09-24 04:01:44 [Info] ipc client:Rtap176651663963304 Reg client_name:protocol_ipc_client on WhiteList 2022-09-24 04:01:44 [Info] Rtap Platform Rtap176651663963304 execv work --sca on pid 2452 2022-09-24 04:02:32 [Warn] GetMaxCpu : 12 2022-09-24 04:02:32 [Warn] GetWarningCpu : 12 2022-09-24 04:02:33 [Info] bin info:c:/hwshostmaster/phpweb/mysql/bin/mysqld.exe bf528def0d9516c028742340e61b8a3b 8060 2022-09-24 04:02:54 [Info] Done Work --sca:1 2022-09-24 04:02:54 [Info] Rtap Platform Rtap176651663963304 Exit:normal exit 2022-09-24 04:02:56 [Info] ClientDisConnectNotify : Rtap176651663963304 2022-09-24 04:26:56 [Info] start to update proc chain rule, path C:/Program Files (x86)/Alibaba/Aegis/aegis_client/aegis_11_38/rule/procchain.data 2022-09-24 04:26:56 [Info] md5 equal:C:/Program Files (x86)/Alibaba/Aegis/aegis_client/aegis_11_38/rule/procchain.data:26a4eab7534891fb1eed4d78ca99f4e7 2022-09-24 04:26:56 [Info] update rule procchain.data success 2022-09-24 04:26:56 [Info] start to update script rule, path C:/Program Files (x86)/Alibaba/Aegis/aegis_client/aegis_11_38/rule/scriptfilter.data 2022-09-24 04:26:56 [Warn] No Type about script_filter_windows 2022-09-24 04:26:56 [Info] start to update event log rule, path C:/Program Files (x86)/Alibaba/Aegis/aegis_client/aegis_11_38/rule/evtlog.data 2022-09-24 04:9-4,ja-9-15"/>