command-line-murders/i-09b87c15485fbf9f2
by SadServersMore by SadServers
root 590 0.0 0.9 220796 4244 ? Ssl 14:15 0:00 /usr/sbin/rsyroot 594 0.1 1.1 13488 5416 ? Ss 14:15 0:00 /lib/systemd/_chrony 595 0.0 0.7 10856 3724 ? S 14:15 0:00 /usr/sbin/chr_chrony 600 0.0 0.1 10724 556 ? S 14:15 0:00 /usr/sbin/chrroot 601 0.2 0.3 2872 1740 tty1 Ss+ 14:15 0:00 /sbin/agetty root 603 0.0 0.4 4396 2144 ttyS0 Ss+ 14:15 0:00 /sbin/agetty root 604 0.0 1.5 13348 7020 ? Ss 14:15 0:00 sshd: /usr/sbroot 620 0.1 3.7 26612 17336 ? Ss 14:15 0:00 /usr/bin/pythadmin 675 0.0 0.7 5920 3632 pts/0 S<s+ 14:15 0:00 bash -l admin 678 0.4 4.1 98188 19388 pts/0 R<l+ 14:15 0:00 /usr/bin/pythadmin 681 0.0 3.0 24456 14432 pts/0 R<+ 14:15 0:00 /usr/bin/pythadmin 682 0.0 0.1 2480 508 pts/1 S<s 14:15 0:00 sh -c /bin/baadmin 683 0.0 0.9 6820 4428 pts/1 S< 14:15 0:00 /bin/bash admin 688 0.0 0.6 8648 3176 pts/1 R<+ 14:16 0:00 ps auux admin@i-0113c5af4b6af66cd:~$ which
kihei/i-0113c5af4b6af66cd 00:33
by SadServersdrwxr-xr-x 3 root root 4096 Sep 17 16:44 .. drwx------ 3 admin admin 4096 Sep 20 15:52 .ansible -rw------- 1 admin admin 57 Sep 20 15:58 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Sep 20 15:56 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 16:44 .ssh drwxr-xr-x 2 admin root 4096 Sep 24 23:20 agent -rwxrwx--- 1 root root 360 Sep 24 23:20 webserver.py admin@i-057a22a824cc9eb82:~$ pwd /home/admin admin@i-057a22a824cc9eb82:~$ curl localhost:5000 Unauthorizedadmin@i-057a22a824cc9eb82:~$ admin@i-057a22a824cc9eb82:~$ netstat