command-line-murders/i-07539d5a34215db5b
by SadServersMore by SadServers
unix 3 [ ] STREAM CONNECTED 11453 unix 3 [ ] STREAM CONNECTED 10664 unix 2 [ ] DGRAM 11425 unix 3 [ ] STREAM CONNECTED 10681 unix 3 [ ] SEQPACKET CONNECTED 11434 unix 3 [ ] STREAM CONNECTED 11349 /run/systemd/journal/unix 3 [ ] STREAM CONNECTED 11478 /run/systemd/journal/unix 2 [ ] DGRAM 10394 admin@i-0b15957f6074fd500:~$ netstat -tuln | grep LISTEN tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN tcp 0 0 127.0.0.1:5000 0.0.0.0:* LISTEN tcp6 0 0 :::22 :::* LISTEN tcp6 0 0 :::6767 :::* LISTEN tcp6 0 0 :::8080 :::* LISTEN admin@i-0b15957f6074fd500:~$ curl 127.0.0.1:
paris/i-0b15957f6074fd500 01:37
by SadServersif [[ "$actual_checksum" == "$expected_checksum" ]]; then echo -n "OK" else echo -n "NO" fiadmin@i-053e95096bbd62d08:~/agent$ file sadagent sadagent: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linke-linux-x86-64.so.2, Go BuildID=H6A8cVluPFUvaNojVwMi/C5t-5rNiA5GJLWeSm5Qz/KXfivG_EPr4lPEnoe, not stripped admin@i-053e95096bbd62d08:~/agent$ cd .. admin@i-053e95096bbd62d08:~$ ls agent webserver.py admin@i-053e95096bbd62d08:~$ cat webserver.py cat: webserver.py: Permission denied admin@i-053e95096bbd62d08:~$ ls
paris/i-053e95096bbd62d08 02:03
by SadServersroot 574 0.0 0.3 2872 1672 tty1 Ss+ 10:17 0:00 /sbin/agetty root 575 0.0 0.4 4396 2040 ttyS0 Ss+ 10:17 0:00 /sbin/agetty _chrony 577 0.0 0.7 10852 3668 ? S 10:17 0:00 /usr/sbin/chr_chrony 578 0.0 0.1 10724 556 ? S 10:17 0:00 /usr/sbin/chrroot 579 0.0 1.5 13352 7084 ? Ss 10:17 0:00 sshd: /usr/sbroot 583 0.0 3.7 26612 17396 ? Ss 10:17 0:00 /usr/bin/pythroot 662 0.0 0.0 0 0 ? I 10:17 0:00 [kworker/1:4-admin 664 0.0 0.9 6740 4464 pts/0 S<s+ 10:17 0:00 bash -l admin 668 0.1 4.1 98320 19236 pts/0 D<l+ 10:17 0:00 /usr/bin/pythadmin 671 0.0 3.1 24456 14924 pts/0 R<+ 10:17 0:00 /usr/bin/pythadmin 672 0.0 0.1 2480 568 pts/1 S<s 10:17 0:00 sh -c /bin/baadmin 673 0.0 1.0 6952 4792 pts/1 S< 10:17 0:00 /bin/bash root 717 0.0 0.0 0 0 ? R 10:18 0:00 [kworker/u4:4admin 762 0.0 0.6 8648 3212 pts/1 R<+ 10:19 0:00 ps aux admin@i-0cace07c960fab3ec:/etc$ ps aux