command-line-murders/i-0825fc5345815be7b
by SadServersMore by SadServers
drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-010d84eaab4d0fc03:~$ cp /home/admin/webserver.py /tmp/ cp: cannot open '/home/admin/webserver.py' for reading: Permission denied admin@i-010d84eaab4d0fc03:~$ admin@i-010d84eaab4d0fc03:~$ ls -la /home/admin/agent/ total 11144 drwxr-xr-x 2 admin root 4096 Sep 24 2023 . drwxr-xr-x 6 admin admin 4096 Sep 24 2023 .. -rwxr-xr-x 1 admin admin 230 Sep 24 2023 check.sh -rwxr-xr-x 1 admin root 11397096 Sep 20 2023 sadagent -rw-r--r-- 1 admin admin 0 Sep 20 2023 sadagent.txt admin@i-010d84eaab4d0fc03:~$ ls -la /home/admin/agent/sadagent -rwxr-xr-x 1 admin root 11397096 Sep 20 2023 /home/admin/agent/sadagent admin@i-010d84eaab4d0fc03:~$
paris/i-010d84eaab4d0fc03 02:29
by SadServers1 134 2 26 4 54 573 594 63 729 bus driver 10 14 20 27 462 55 574 596 64 73 cgroups dynamic_debug11 15 212 28 49 557 579 597 680 762 cmdline execdomains 114 16 22 29 5 558 58 6 684 78 consoles fb 115 17 23 3 50 56 582 60 687 8 cpuinfo filesystems 12 18 235 30 51 561 583 61 688 9 crypto fs 13 19 24 347 52 563 584 618 689 acpi devices interrupts 133 195 25 389 53 57 59 62 7 buddyinfo diskstats iomem admin@i-0c5c0bccbc8341a7b:~$ ls /proc/^C admin@i-0c5c0bccbc8341a7b:~$ ^C admin@i-0c5c0bccbc8341a7b:~$ ^C admin@i-0c5c0bccbc8341a7b:~$ ^C admin@i-0c5c0bccbc8341a7b:~$ ^C admin@i-0c5c0bccbc8341a7b:~$ ^C admin@i-0c5c0bccbc8341a7b:~$ ps -aux | grep p
paris/i-0c5c0bccbc8341a7b 01:47
by SadServers[sudo] password for admin: ^Csudo: 1 incorrect password attempt admin@i-09b7dc79be18d538a:~$ ^C admin@i-09b7dc79be18d538a:~$ netstat -an --tcp --program (Not all processes could be identified, non-owned process info will not be shown, you would have to be root to see it all.) Active Internet connections (servers and established) Proto Recv-Q Send-Q Local Address Foreign Address State tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN tcp 0 0 127.0.0.1:5000 0.0.0.0:* LISTEN tcp6 0 0 :::6767 :::* LISTEN tcp6 0 0 :::8080 :::* LISTEN tcp6 0 0 :::22 :::* LISTEN tcp6 0 249 172.31.37.243:8080 172.31.16.109:41784 ESTABLISHED admin@i-09b7dc79be18d538a:~$