command-line-murders/i-038602785d3f41a4a
by SadServersMore by SadServers
root 590 0.0 0.9 220796 4244 ? Ssl 14:15 0:00 /usr/sbin/rsyroot 594 0.1 1.1 13488 5416 ? Ss 14:15 0:00 /lib/systemd/_chrony 595 0.0 0.7 10856 3724 ? S 14:15 0:00 /usr/sbin/chr_chrony 600 0.0 0.1 10724 556 ? S 14:15 0:00 /usr/sbin/chrroot 601 0.2 0.3 2872 1740 tty1 Ss+ 14:15 0:00 /sbin/agetty root 603 0.0 0.4 4396 2144 ttyS0 Ss+ 14:15 0:00 /sbin/agetty root 604 0.0 1.5 13348 7020 ? Ss 14:15 0:00 sshd: /usr/sbroot 620 0.1 3.7 26612 17336 ? Ss 14:15 0:00 /usr/bin/pythadmin 675 0.0 0.7 5920 3632 pts/0 S<s+ 14:15 0:00 bash -l admin 678 0.4 4.1 98188 19388 pts/0 R<l+ 14:15 0:00 /usr/bin/pythadmin 681 0.0 3.0 24456 14432 pts/0 R<+ 14:15 0:00 /usr/bin/pythadmin 682 0.0 0.1 2480 508 pts/1 S<s 14:15 0:00 sh -c /bin/baadmin 683 0.0 0.9 6820 4428 pts/1 S< 14:15 0:00 /bin/bash admin 688 0.0 0.6 8648 3176 pts/1 R<+ 14:16 0:00 ps auux admin@i-0113c5af4b6af66cd:~$ which
kihei/i-0113c5af4b6af66cd 00:33
by SadServerspgrades/unattended-upgrade-shutdown -- root 620 0.0 0.0 0 0 ? I 21:48 0:00 [kworker/0:3-root 685 0.0 0.0 0 0 ? I 21:48 0:00 [kworker/0:4-admin 687 0.0 0.9 6740 4416 pts/0 S<s+ 21:49 0:00 bash -l admin 691 0.2 4.1 98188 19244 pts/0 D<l+ 21:49 0:00 /usr/bin/pyth-t paris/i-036f8423c1405f693 -q -i 2 / admin 694 0.0 3.0 24456 14396 pts/0 R<+ 21:49 0:00 /usr/bin/pyth-t paris/i-036f8423c1405f693 -q -i 2 / admin 695 0.0 0.1 2480 508 pts/1 S<s 21:49 0:00 sh -c /bin/baadmin 696 0.0 0.9 6820 4588 pts/1 S< 21:49 0:00 /bin/bash root 714 0.0 0.0 0 0 ? I 21:49 0:00 [kworker/1:3-root 716 0.0 0.0 0 0 ? I 21:49 0:00 [kworker/1:4-root 776 0.0 0.0 0 0 ? R 21:50 0:00 [kworker/u4:4admin 777 0.0 0.6 8648 3216 pts/1 R<+ 21:51 0:00 ps aux admin@i-036f8423c1405f693:~$
paris/i-036f8423c1405f693 02:01
by SadServersfind: ‘/var/cache/ldconfig’: Permission denied find: ‘/var/cache/apt/archives/partial’: Permission denied find: ‘/var/cache/apparmor/c08a2770.0’: Permission denied find: ‘/var/spool/rsyslog’: Permission denied find: ‘/var/spool/cron/crontabs’: Permission denied find: ‘/var/tmp/systemd-private-6311f1e23e8b46ab844ee53d9ed1279a-systemd-logind.on denied find: ‘/var/tmp/systemd-private-6311f1e23e8b46ab844ee53d9ed1279a-chrony.service-d find: ‘/var/log/private’: Permission denied find: ‘/var/log/chrony’: Permission denied find: ‘/var/lib/private’: Permission denied find: ‘/var/lib/apt/lists/partial’: Permission denied find: ‘/var/lib/chrony’: Permission denied admin@i-066a44d1b6845fe58:~$
kihei/i-066a44d1b6845fe58 01:35
by SadServersadmin@i-05ac26ae064999ace:~$ curl -vv^Cocalhost:5000 admin@i-05ac26ae064999ace:~$ ls -la total 44 drwxr-xr-x 6 admin admin 4096 Sep 24 2023 . drwxr-xr-x 3 root root 4096 Sep 17 2023 .. drwx------ 3 admin admin 4096 Sep 20 2023 .ansible -rw------- 1 admin admin 607 Mar 11 09:34 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 4 admin admin 4096 Mar 11 09:31 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 2023 .ssh drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-05ac26ae064999ace:~$