paris/i-07e2fdd31fb619fad
by SadServersMore by SadServers
rm: cannot remove 'libmpfr6_4.1.0-3_amd64.deb': Permission denied rm: cannot remove 'libpython3.9_3.9.2-1_amd64.deb': Permission denied rm: cannot remove 'libsource-highlight-common_3.1.9-3_all.deb': Permission denierm: cannot remove 'libsource-highlight4v5_3.1.9-3+b1_amd64.deb': Permission denirm: cannot remove 'libunwind8_1.3.2-2_amd64.deb': Permission denied rm: cannot remove 'lock': Permission denied rm: cannot remove 'lsof_4.93.2+dfsg-1.1_amd64.deb': Permission denied rm: cannot remove 'lua-lpeg_1.0.2-1_amd64.deb': Permission denied rm: cannot remove 'lvm2_2.03.11-2.1_amd64.deb': Permission denied rm: cannot remove 'nmap-common_7.91+dfsg1+really7.80+dfsg1-2_all.deb': Permissiorm: cannot remove 'nmap_7.91+dfsg1+really7.80+dfsg1-2_amd64.deb': Permission denrm: cannot remove 'partial': Permission denied rm: cannot remove 'strace_5.10-1_amd64.deb': Permission denied rm: cannot remove 'thin-provisioning-tools_0.9.0-1_amd64.deb': Permission deniedadmin@i-0f67f02eee8a35fb3:/var/cache/apt/archives$ sudo rm
kihei/i-0f67f02eee8a35fb3 05:29
by SadServers[:delay_enter=DELAY][:delay_exit=DELAY][:when=WHEN], --inject=SET[:error=ERRNO|:retval=VALUE][:signal=SIG][:syscall=SYSCALL] [:delay_enter=DELAY][:delay_exit=DELAY][:when=WHEN] perform syscall tampering for the syscalls in SET delay: microseconds or NUMBER{s|ms|us|ns} when: FIRST[..LAST][+[STEP]] -e fault=SET[:error=ERRNO][:when=WHEN], --fault=SET[:error=ERRNO][:when=WHEN] synonym for -e inject with default ERRNO set to ENOSYS. Miscellaneous: -d, --debug enable debug output to stderr -h, --help print help message --seccomp-bpf enable seccomp-bpf filtering -V, --version print version admin@i-054157b3157fdc4cd:~$ strace ./kihei -v
kihei/i-054157b3157fdc4cd 01:21
by SadServers559 ? S<sl 0:00 /home/admin/agent/sadagent 562 ? Ss 0:00 /usr/sbin/cron -f 563 ? Ss 0:00 /usr/bin/dbus-daemon --system --address=systemd: -- 575 ? Ss 0:00 /usr/bin/python3 /home/admin/webserver.py 576 ? Ssl 0:00 /usr/sbin/rsyslogd -n -iNONE 582 ? Ss 0:00 /lib/systemd/systemd-logind 584 ? Ss 0:00 sshd: /usr/sbin/sshd -D [listener] 0 of 10-100 star 585 tty1 Ss+ 0:00 /sbin/agetty -o -p -- \u --noclear tty1 linux 586 ttyS0 Ss+ 0:00 /sbin/agetty -o -p -- \u --keep-baud 115200,57600,3 588 ? S 0:00 /usr/sbin/chronyd -F 1 589 ? S 0:00 \_ /usr/sbin/chronyd -F 1 606 ? Ss 0:00 /usr/bin/python3 /usr/share/unattended-upgrades/unaadmin@i-04f25c68fa11fb6a2:~$ curl -A "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5it/537.36 (KHTML, like Gecko) Chrome/W.X.Y.Z Mobile Safari/537.36 (compatible; G.google.com/bot.html)"