command-line-murders/i-0f85d88ceb0b908f1
by SadServersMore by SadServers
lsof 1008 1000 mem REG 259,1 149520inux-gnu/libpthread-2.31.so lsof 1008 1000 mem REG 259,1 18688inux-gnu/libdl-2.31.so lsof 1008 1000 mem REG 259,1 617128inux-gnu/libpcre2-8.so.0.10.1 lsof 1008 1000 mem REG 259,1 1901536inux-gnu/libc-2.31.so lsof 1008 1000 mem REG 259,1 166120inux-gnu/libselinux.so.1 lsof 1008 1000 mem REG 259,1 177928inux-gnu/ld-2.31.so lsof 1008 1000 4r FIFO 0,11 0t0lsof 1008 1000 7w FIFO 0,11 0t0admin@i-096a29f104e7847fe:~$ lsof -i
paris/i-096a29f104e7847fe 07:14
by SadServersfile"] /var/log/cast/i-008b0220d06b61fa7:[297.457658, "o", "\b\b\b\b\b\b\b\b\b\b\b-name/var/log/cast/i-008b0220d06b61fa7:[301.266025, "o", "\b\b\b\b\b\b\b\b\b\b\b\b\b\/var/log -name newdatafile"] /var/log/cast/i-008b0220d06b61fa7:[339.22969, "o", "\b\b\b\b\b\b\b\b\b\b\b\b\b\btafile /var/log"] /var/log/cast/i-008b0220d06b61fa7:[339.527642, "o", "\b\b\b\b\b\b\b\b\b\b\b\b\b\file"] /var/log/cast/i-008b0220d06b61fa7:[340.82254, "o", "\b\b\b\b\b\b\b\b\b\b\b-name /var/log/cast/i-008b0220d06b61fa7:[347.397351, "o", "\b\b\b\b\b\b\b\b\b\b\b\b\b\atafile /var/log"] grep: /var/log/btmp: Permission denied grep: /var/log/private: Permission denied grep: /var/log/chrony: Permission denied admin@i-008b0220d06b61fa7:~$ /home/admin/kihei
kihei/i-008b0220d06b61fa7 06:01
by SadServers-rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Sep 20 2023 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 2023 .ssh drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-08e8c3662820c3288:~$ curl -D- -H "User-Agent: admin" http://127.0.0.1:50HTTP/1.1 200 OK Server: Werkzeug/2.3.7 Python/3.9.2 Date: Sat, 12 Apr 2025 09:51:27 GMT Content-Type: text/html; charset=utf-8 Content-Length: 35 Connection: close Welcome! Password is FDZPmh5AX3oiJtadmin@i-08e8c3662820c3288:~$
paris/i-08e8c3662820c3288 00:29
by SadServers/cpu.CacheLineSizeinternal/cpu.X86internal/cpu.optionsinternal/cpu.maxExtendedFunittaskpath.ErrBadPatterngo.itab.*flag.boolValue,flag.Valuego.itab.*os.File,io.WmError,errorgo.itab.*reflect.rtype,reflect.Typego.itab.*flag.durationValue,flag.64Value,flag.Valuego.itab.*flag.intValue,flag.Valuego.itab.*flag.int64Value,flagngValue,flag.Valuego.itab.*flag.uintValue,flag.Valuego.itab.*flag.uint64Value,fl.Builder,io.Writergo.itab.*errors.errorString,errorgo.itab.*fmt.wrapError,errorggo.itab.*os.File,io.Readergo.itab.syscall.Signal,os.Signalgo.itab.*io/fs.PathErrallError,errorgo.itab.syscall.Errno,errorgo.itab.os.onlyWriter,io.Writergo.itab.nfogo.itab.*io.LimitedReader,io.Readergo.itab.*os.File,io.Closergo.itab.*os/exec*os/exec.Error,errorgo.itab.*bufio.Reader,io.Readergo.itab.os/user.UnknownUserIdrnal/reflectlite.rtype,internal/reflectlite.Typego.itab.time.fileSizeError,errort.SortedMap,sort.Interfacego.itab.runtime.errorString,error_cgo_init_cgo_thread__init_done_cgo_callers_cgo_yield_cgo_mmap_cgo_munmap_cgo_sigactionruntime.mainPCeadlineExceededError,errorgo.itab.internal/poll.errNetClosing,errorruntime.defaudVersion.strruntime.modinfo.strtype.*runtime.textsectionmapadmin@i-062042b0fb20a