paris/i-0bed7ad43768ade6d
by SadServersMore by SadServers
-rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout drwxr-xr-x 3 root root 4096 Sep 17 16:44 .. drwx------ 2 admin admin 4096 Sep 17 16:44 .ssh drwx------ 3 admin admin 4096 Sep 20 15:52 .ansible drwxr-xr-x 3 admin admin 4096 Sep 20 15:56 .config drwxr-xr-x 8 admin admin 4096 Sep 30 17:45 .git drwxr-xr-x 2 admin root 4096 Sep 30 17:45 agent -rw-r--r-- 1 admin admin 109 Oct 1 17:06 curler.sh -rw------- 1 admin admin 1294 Oct 1 17:06 .viminfo drwxr-xr-x 7 admin admin 4096 Oct 1 17:06 . -rw------- 1 admin admin 289 Oct 1 17:06 .bash_history admin@i-0ee2f3007d5494cc2:~$ less .bash_history admin@i-0ee2f3007d5494cc2:~$ less .viminfo admin@i-0ee2f3007d5494cc2:~$ less
monaco/i-0ee2f3007d5494cc2 02:34
by SadServersadmin@i-05d27a7439a0e6399:~$ ls agent data datafile kihei admin@i-05d27a7439a0e6399:~$ file kihei kihei: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, G7tVbey9uC58oKsR, not stripped admin@i-05d27a7439a0e6399:~$ ps aux | grep "kihei" admin 704 0.6 4.1 98188 19192 pts/0 S<l+ 10:38 0:00 /usr/bin/pythi-05d27a7439a0e6399 admin 707 0.0 3.0 24456 14448 pts/0 S<+ 10:38 0:00 /usr/bin/pythi-05d27a7439a0e6399 admin 715 0.0 0.1 5264 704 pts/1 S<+ 10:38 0:00 grep kihei admin@i-05d27a7439a0e6399:~$
kihei/i-05d27a7439a0e6399 00:26
by SadServerswrite(2, ":", 1:) = 1 write(2, "64", 264) = 2 write(2, " +", 2 +) = 2 write(2, "0x47d", 50x47d) = 5 write(2, "\n", 1 ) = 1 exit_group(2) = ? +++ exited with 2 +++ admin@i-0383999b6e9ab8158:~$ ls agent data datafile kihei admin@i-0383999b6e9ab8158:~$ ls datafile datafile admin@i-0383999b6e9ab8158:~$ ls /usr/local/sbin/fallocate ls: cannot access '/usr/local/sbin/fallocate': No such file or directory admin@i-0383999b6e9ab8158:~$ whereis fallo