command-line-murders/i-0d1a106b582c44b54
by SadServersMore by SadServers
root 593 0.0 1.4 13488 6708 ? Ss 11:53 0:00 /lib/systemd/_chrony 597 0.0 0.7 10856 3636 ? S 11:53 0:00 /usr/sbin/chrroot 598 0.0 1.5 13348 7144 ? Ss 11:53 0:00 sshd: /usr/sbroot 599 0.0 0.3 2872 1684 tty1 Ss+ 11:53 0:00 /sbin/agetty root 600 0.0 0.4 4396 2100 ttyS0 Ss+ 11:53 0:00 /sbin/agetty _chrony 601 0.0 0.1 10724 548 ? S 11:53 0:00 /usr/sbin/chrroot 622 0.0 3.7 26612 17332 ? Ss 11:53 0:00 /usr/bin/pythroot 677 0.0 0.0 0 0 ? I 11:53 0:00 [kworker/1:4-admin 789 0.0 0.7 5920 3552 pts/0 S<s+ 11:57 0:00 bash -l admin 791 0.7 4.1 98188 19356 pts/0 R<l+ 11:57 0:00 /usr/bin/pythadmin 794 0.0 3.1 24456 14504 pts/0 S<+ 11:57 0:00 /usr/bin/pythadmin 795 0.0 0.1 2480 508 pts/1 S<s 11:57 0:00 sh -c /bin/baadmin 796 0.0 0.9 6820 4532 pts/1 S< 11:57 0:00 /bin/bash admin 799 0.0 0.6 8648 3180 pts/1 R<+ 11:57 0:00 ps aux admin@i-0f090ab9a046ad6f3:~$ ps aux | gtr
kihei/i-0f090ab9a046ad6f3 00:16
by SadServersadmin@i-04f9b68ba2ba71eb9:~$ pwd /home/admin admin@i-04f9b68ba2ba71eb9:~$ admin@i-04f9b68ba2ba71eb9:~$ ls agent data datafile kihei admin@i-04f9b68ba2ba71eb9:~$ cd agent/ admin@i-04f9b68ba2ba71eb9:~/agent$ ls check.sh sadagent sadagent.txt admin@i-04f9b68ba2ba71eb9:~/agent$ cat c
kihei/i-04f9b68ba2ba71eb9 00:18
by SadServersfind: ‘./var/cache/apparmor/c08a2770.0’: Permission denied find: ‘./var/spool/rsyslog’: Permission denied find: ‘./var/spool/cron/crontabs’: Permission denied find: ‘./var/tmp/systemd-private-648cc96b50ab42589914a79776d72300-chrony.serviceed find: ‘./var/tmp/systemd-private-648cc96b50ab42589914a79776d72300-systemd-logindion denied find: ‘./var/log/private’: Permission denied find: ‘./var/log/chrony’: Permission denied find: ‘./var/lib/private’: Permission denied find: ‘./var/lib/apt/lists/partial’: Permission denied find: ‘./var/lib/chrony’: Permission denied admin@i-08c7e6569481c6e82:/$ admin@i-08c7e6569481c6e82:/$ admin@i-08c7e6569481c6e82:/$ cd /usr/share
paris/i-08c7e6569481c6e82 08:40
by SadServers#1698484587 cat .bash admin@i-0f6c30f8d04ab9891:~$ cd .config/ admin@i-0f6c30f8d04ab9891:~/.config$ ls asciinema admin@i-0f6c30f8d04ab9891:~/.config$ cd asciinema/ admin@i-0f6c30f8d04ab9891:~/.config/asciinema$ ls install-id admin@i-0f6c30f8d04ab9891:~/.config/asciinema$ cat install-id 0e2d35c4-a944-417f-bd3a-677c2f875b37admin@i-0f6c30f8d04ab9891:~/.config/asciinema$ cd .. admin@i-0f6c30f8d04ab9891:~/.config$ cd .. admin@i-0f6c30f8d04ab9891:~$ ls agent webserver.py admin@i-0f6c30f8d04ab9891:~$