command-line-murders/i-0825fc5345815be7b
by SadServersMore by SadServers
=5,direct,pipe_ino=9613) hugetlbfs on /dev/hugepages type hugetlbfs (rw,relatime,pagesize=2M) mqueue on /dev/mqueue type mqueue (rw,nosuid,nodev,noexec,relatime) debugfs on /sys/kernel/debug type debugfs (rw,nosuid,nodev,noexec,relatime) tracefs on /sys/kernel/tracing type tracefs (rw,nosuid,nodev,noexec,relatime) fusectl on /sys/fs/fuse/connections type fusectl (rw,nosuid,nodev,noexec,relatimconfigfs on /sys/kernel/config type configfs (rw,nosuid,nodev,noexec,relatime) /dev/nvme0n1p15 on /boot/efi type vfat (rw,relatime,fmask=0022,dmask=0022,codepaortname=mixed,utf8,errors=remount-ro) binfmt_misc on /proc/sys/fs/binfmt_misc type binfmt_misc (rw,nosuid,nodev,noexecadmin@i-002fcecc6e43c1be2:~$ ps aux | grep webserver root 579 0.0 5.9 33040 27944 ? Ss 13:14 0:00 /usr/bin/pyth.py admin 935 0.0 0.1 5264 704 pts/1 S<+ 13:21 0:00 grep webserveadmin@i-002fcecc6e43c1be2:~$
paris/i-002fcecc6e43c1be2 03:03
by SadServerss/screencasts --limit-upload 5M root 678 0.0 0.0 0 0 ? I 20:30 0:00 [kworker/1:3-admin 681 0.0 0.7 5920 3700 pts/0 S<s+ 20:30 0:00 bash -l admin 683 0.4 4.1 98188 19416 pts/0 R<l+ 20:30 0:00 /usr/bin/pythc -t kihei/i-0625ea1d1c7254d20 -q -i 2 /var/log/cast/i-0625ea1d1c7254d20 admin 686 0.0 3.0 24456 14364 pts/0 S<+ 20:30 0:00 /usr/bin/pythc -t kihei/i-0625ea1d1c7254d20 -q -i 2 /var/log/cast/i-0625ea1d1c7254d20 admin 687 0.0 0.1 2480 576 pts/1 S<s 20:30 0:00 sh -c /bin/baadmin 688 0.0 0.9 6820 4616 pts/1 S< 20:30 0:00 /bin/bash admin 692 0.0 0.6 8648 3152 pts/1 R<+ 20:31 0:00 ps aux admin@i-0625ea1d1c7254d20:~$ iotop bash: iotop: command not found admin@i-0625ea1d1c7254d20:~$ uptime 20:32:05 up 2 min, 0 users, load average: 0.00, 0.00, 0.00 admin@i-0625ea1d1c7254d20:~$ vmsta
kihei/i-0625ea1d1c7254d20 01:11
by SadServersadmin@i-0e2c9c64a6cc5b706:~$ ls agent webserver.py admin@i-0e2c9c64a6cc5b706:~$ ls agent/ check.sh sadagent sadagent.txt admin@i-0e2c9c64a6cc5b706:~$ ls agent/sadagent agent/sadagent admin@i-0e2c9c64a6cc5b706:~$ file agent/sadagent agent/sadagent: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, Go BuildID=H6A8cVluPFUvaNojVwMi/C5t-5rNiA5GJLWeSm5Qz/KXfivG_lDFnrqPGrWEJo/K_OQEFevUZEPr4lPEnoe, not stripped admin@i-0e2c9c64a6cc5b706:~$ ./agent/check.sh md5sum: /home/admin/mysolution: No such file or directory NOadmin@i-0e2c9c64a6cc5b706:~$ ./agent/
paris/i-0e2c9c64a6cc5b706 01:06
by SadServers559 ? S<sl 0:00 /home/admin/agent/sadagent 562 ? Ss 0:00 /usr/sbin/cron -f 563 ? Ss 0:00 /usr/bin/dbus-daemon --system --address=systemd: -- 575 ? Ss 0:00 /usr/bin/python3 /home/admin/webserver.py 576 ? Ssl 0:00 /usr/sbin/rsyslogd -n -iNONE 582 ? Ss 0:00 /lib/systemd/systemd-logind 584 ? Ss 0:00 sshd: /usr/sbin/sshd -D [listener] 0 of 10-100 star 585 tty1 Ss+ 0:00 /sbin/agetty -o -p -- \u --noclear tty1 linux 586 ttyS0 Ss+ 0:00 /sbin/agetty -o -p -- \u --keep-baud 115200,57600,3 588 ? S 0:00 /usr/sbin/chronyd -F 1 589 ? S 0:00 \_ /usr/sbin/chronyd -F 1 606 ? Ss 0:00 /usr/bin/python3 /usr/share/unattended-upgrades/unaadmin@i-04f25c68fa11fb6a2:~$ curl -A "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5it/537.36 (KHTML, like Gecko) Chrome/W.X.Y.Z Mobile Safari/537.36 (compatible; G.google.com/bot.html)"