kihei/i-075ea5c6ffa92e64b
by SadServersMore by SadServers
file"] /var/log/cast/i-008b0220d06b61fa7:[297.457658, "o", "\b\b\b\b\b\b\b\b\b\b\b-name/var/log/cast/i-008b0220d06b61fa7:[301.266025, "o", "\b\b\b\b\b\b\b\b\b\b\b\b\b\/var/log -name newdatafile"] /var/log/cast/i-008b0220d06b61fa7:[339.22969, "o", "\b\b\b\b\b\b\b\b\b\b\b\b\b\btafile /var/log"] /var/log/cast/i-008b0220d06b61fa7:[339.527642, "o", "\b\b\b\b\b\b\b\b\b\b\b\b\b\file"] /var/log/cast/i-008b0220d06b61fa7:[340.82254, "o", "\b\b\b\b\b\b\b\b\b\b\b-name /var/log/cast/i-008b0220d06b61fa7:[347.397351, "o", "\b\b\b\b\b\b\b\b\b\b\b\b\b\atafile /var/log"] grep: /var/log/btmp: Permission denied grep: /var/log/private: Permission denied grep: /var/log/chrony: Permission denied admin@i-008b0220d06b61fa7:~$ /home/admin/kihei
kihei/i-008b0220d06b61fa7 06:01
by SadServersa.out agent webserver.py $ admin@i-072b43453825ba99a:~$ find / -perm -u=s -type f 2>/dev/null /usr/lib/openssh/ssh-keysign /usr/lib/dbus-1.0/dbus-daemon-launch-helper /usr/bin/chsh /usr/bin/umount /usr/bin/mount /usr/bin/passwd /usr/bin/newgrp /usr/bin/sudo /usr/bin/chfn /usr/bin/su /usr/bin/gpasswd admin@i-072b43453825ba99a:~$ ./a.out /usr/bin/su
paris/i-072b43453825ba99a 03:20
by SadServers/asn1.oidEncoder,encoding/asn1.encodergo.itab.encoding/asn1.stringEncoder,encodiitab.encoding/asn1.int64Encoder,encoding/asn1.encodergo.itab.encoding/asn1.setEnencodergo.itab.golang.org/x/text/internal/language.sortVariants,sort.Interfacego/text/internal/language.variantsSort,sort.Interfacego.itab.golang.org/x/text/intuage.Tag,golang.org/x/text/internal/language/compact.fullTaggo.itab.*encoding/gogobTypego.itab.*encoding/gob.arrayType,encoding/gob.gobTypego.itab.*encoding/gob.gobTypego.itab.*encoding/gob.CommonType,encoding/gob.gobType__errno_locationgaihabortpthread_cond_broadcastsigactionsetenvpthread_cond_waitmmapnanosleepfputcpttex_unlockmallocmunmapvfprintfunsetenvpthread_attr_destroysigismemberfwritestrerime.buildVersion.strruntime.modinfo.strtype.*runtime.textsectionmap^C admin@i-059172a6cbeaf621a:~/agent$ tail -300f sadagent.txt ^C admin@i-059172a6cbeaf621a:~/agent$ ls check.sh sadagent sadagent.txt admin@i-059172a6cbeaf621a:~/agent$