command-line-murders/i-0825fc5345815be7b
by SadServersMore by SadServers
-rw------- 1 admin admin 269 Jan 2 11:38 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Sep 20 2023 .config drwxr-xr-x 3 admin admin 4096 Jan 2 11:37 .local -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 2023 .ssh -rw-r--r-- 1 admin admin 1024 Jan 2 11:37 .webserver.py.swp drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-0f995f369ab3b4d0d:~$ ls .config/ asciinema admin@i-0f995f369ab3b4d0d:~$ less .webserver.py.swp ".webserver.py.swp" may be a binary file. See it anyway? admin@i-0f995f369ab3b4d0d:~$ cat .bashr
paris/i-0f995f369ab3b4d0d 01:44
by SadServerstcp 0 0 127.0.0.1:5000 0.0.0.0:* LISTEN tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN tcp 0 0 172.31.46.95:36554 172.31.18.4:9000 TIME_WAIT tcp 0 0 172.31.46.95:36542 172.31.18.4:9000 TIME_WAIT tcp 0 0 172.31.46.95:36528 172.31.18.4:9000 TIME_WAIT tcp 0 0 172.31.46.95:36558 172.31.18.4:9000 TIME_WAIT tcp6 0 0 :::6767 :::* LISTEN tcp6 0 0 :::8080 :::* LISTEN tcp6 0 0 :::22 :::* LISTEN tcp6 0 0 172.31.46.95:8080 172.31.16.109:59882 ESTABLISHED udp 0 0 127.0.0.1:323 0.0.0.0:* udp 0 0 0.0.0.0:68 0.0.0.0:* udp6 0 0 fe80::8cf:dff:fe7d::546 :::* udp6 0 0 ::1:323 :::* admin@i-02f99f045f22e8777:~$ lso
paris/i-02f99f045f22e8777 01:59
by SadServersasciinema 1021 admin mem REG 259,1 149520 15088 /usr/lib/x86_64-linux-gnasciinema 1021 admin mem REG 259,1 14536 132274 /usr/lib/python3.9/lib-dx86_64-linux-gnu.so asciinema 1021 admin mem REG 259,1 177928 13 /usr/lib/x86_64-linux-gnasciinema 1021 admin DEL REG 0,23 2 /dev/shm/Ovvy0c asciinema 1021 admin 0u CHR 136,0 0t0 3 /dev/pts/0 asciinema 1021 admin 1u CHR 136,0 0t0 3 /dev/pts/0 asciinema 1021 admin 2u CHR 136,0 0t0 3 /dev/pts/0 asciinema 1021 admin 3r FIFO 0,11 0t0 12195 pipe asciinema 1021 admin 4w FIFO 0,11 0t0 12195 pipe asciinema 1021 admin 5r CHR 1,3 0t0 4 /dev/null asciinema 1021 admin 6w FIFO 0,11 0t0 12196 pipe asciinema 1021 admin 7r FIFO 0,11 0t0 12197 pipe asciinema 1021 admin 8w REG 259,1 9550 264863 /var/log/cast/i-09d7e7d9admin@i-09d7e7d93e5a6dcdb:~$ less /var/log/cast/i-09d7e7d93e5a6dcdb