command-line-murders/i-05e369bd7e35b4d65
by SadServersMore by SadServers
20K /var/log/debug 16K /var/log/dpkg.log 8.0K /var/log/faillog 33M /var/log/journal 176K /var/log/kern.log 8.0K /var/log/lastlog 180K /var/log/messages 4.0K /var/log/minio.log 4.0K /var/log/private 8.0K /var/log/runit 316K /var/log/syslog 8.0K /var/log/unattended-upgrades 20K /var/log/user.log 52K /var/log/wtmp admin@i-00c7c0914e0cfbd6f:~$
kihei/i-00c7c0914e0cfbd6f 00:57
by SadServers559 ? S<sl 0:00 /home/admin/agent/sadagent 562 ? Ss 0:00 /usr/sbin/cron -f 563 ? Ss 0:00 /usr/bin/dbus-daemon --system --address=systemd: -- 575 ? Ss 0:00 /usr/bin/python3 /home/admin/webserver.py 576 ? Ssl 0:00 /usr/sbin/rsyslogd -n -iNONE 582 ? Ss 0:00 /lib/systemd/systemd-logind 584 ? Ss 0:00 sshd: /usr/sbin/sshd -D [listener] 0 of 10-100 star 585 tty1 Ss+ 0:00 /sbin/agetty -o -p -- \u --noclear tty1 linux 586 ttyS0 Ss+ 0:00 /sbin/agetty -o -p -- \u --keep-baud 115200,57600,3 588 ? S 0:00 /usr/sbin/chronyd -F 1 589 ? S 0:00 \_ /usr/sbin/chronyd -F 1 606 ? Ss 0:00 /usr/bin/python3 /usr/share/unattended-upgrades/unaadmin@i-04f25c68fa11fb6a2:~$ curl -A "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5it/537.36 (KHTML, like Gecko) Chrome/W.X.Y.Z Mobile Safari/537.36 (compatible; G.google.com/bot.html)"
paris/i-04f25c68fa11fb6a2 00:29
by SadServers[46][protocol][@hostname|hostaddr][:service|port] where: 46 specifies the IP version, IPv4 or IPv6 that applies to the following address. '6' may be be specified only if the UNIX dialect supports IPv6. If neither '4' nor '6' is specified, the following address applies to all IP versions. protocol is a protocol name - TCP, UDP hostname is an Internet host name. Unless a specific IP version is specified, open network files associated with host names of all versions will be selected. Manual page lsof(8) line 380 (press h for help or q to quit)