command-line-murders/i-098174ee7e11a20ae
by SadServersMore by SadServers
ty1 Ss+ 20:00 0:00 /sbin/agetty -o -p -- \u --noclear tty1 linux root 593 0.0 0.4 4396 2028 ttyS0 Ss+ 20:00 0:00 /sbin/agetty -o -p -- \u --keep-baud 115200,57 _chrony 595 0.0 0.7 10852 3716 ? S 20:00 0:00 /usr/sbin/chronyd -F 1 _chrony 596 0.0 0.1 10724 552 ? S 20:00 0:00 \_ /usr/sbin/chronyd -F 1 root 611 0.0 3.7 26612 17296 ? Ss 20:00 0:00 /usr/bin/python3 /usr/share/unattended-upgrade admin@i-020b6c81f12d03fba:~$ ca
paris/i-020b6c81f12d03fba 04:05
by SadServers-V, --version print version admin@i-0c5198ac56f7a1469:~$ strace -e open ./ .ansible/ .config/ .ssh/ agent/ data/ kihei admin@i-0c5198ac56f7a1469:~$ strace -e open ./kihei --- SIGURG {si_signo=SIGURG, si_code=SI_TKILL, si_pid=1049, si_uid=1000} --- --- SIGCHLD {si_signo=SIGCHLD, si_code=CLD_EXITED, si_pid=1053, si_uid=1000, si__stime=0} --- panic: exit status 1 goroutine 1 [running]: main.main() ./main.go:64 +0x47d +++ exited with 2 +++ admin@i-0c5198ac56f7a1469:~$ strace ./kihei | less admin@i-0c5198ac56f7a1469:~$
i-0c5198ac56f7a1469 03:45
by SadServersadmin@i-07ee6b558ede8f810:~$ file /home/admin/kihei /home/admin/kihei: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), staticalolUanvRPB7DWhc7e4I/nM83nW4qxDvf9asNaf7E/5u1Qa6jnFvq2KL4kV5G1/6IwNz7tVbey9uC58oKsadmin@i-07ee6b558ede8f810:~$ lsof /home/admin/kihei admin@i-07ee6b558ede8f810:~$ ls -l /home/admin/kihei -rwxr-xr-x 1 admin root 2207109 Sep 17 2023 /home/admin/kihei admin@i-07ee6b558ede8f810:~$ man strace
kihei/i-07ee6b558ede8f810 00:59
by SadServers-rw-r--r-- 1 admin admin 3526 Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4096 Sep 20 2023 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4096 Sep 17 2023 .ssh drwxr-xr-x 2 admin root 4096 Sep 24 2023 agent -rwxrwx--- 1 root root 360 Sep 24 2023 webserver.py admin@i-08e8c3662820c3288:~$ curl -D- -H "User-Agent: admin" http://127.0.0.1:50HTTP/1.1 200 OK Server: Werkzeug/2.3.7 Python/3.9.2 Date: Sat, 12 Apr 2025 09:51:27 GMT Content-Type: text/html; charset=utf-8 Content-Length: 35 Connection: close Welcome! Password is FDZPmh5AX3oiJtadmin@i-08e8c3662820c3288:~$