command-line-murders/i-0bf744948ac460d40
by SadServersMore by SadServers
pgrades/unattended-upgrade-shutdown -- root 620 0.0 0.0 0 0 ? I 21:48 0:00 [kworker/0:3-root 685 0.0 0.0 0 0 ? I 21:48 0:00 [kworker/0:4-admin 687 0.0 0.9 6740 4416 pts/0 S<s+ 21:49 0:00 bash -l admin 691 0.2 4.1 98188 19244 pts/0 D<l+ 21:49 0:00 /usr/bin/pyth-t paris/i-036f8423c1405f693 -q -i 2 / admin 694 0.0 3.0 24456 14396 pts/0 R<+ 21:49 0:00 /usr/bin/pyth-t paris/i-036f8423c1405f693 -q -i 2 / admin 695 0.0 0.1 2480 508 pts/1 S<s 21:49 0:00 sh -c /bin/baadmin 696 0.0 0.9 6820 4588 pts/1 S< 21:49 0:00 /bin/bash root 714 0.0 0.0 0 0 ? I 21:49 0:00 [kworker/1:3-root 716 0.0 0.0 0 0 ? I 21:49 0:00 [kworker/1:4-root 776 0.0 0.0 0 0 ? R 21:50 0:00 [kworker/u4:4admin 777 0.0 0.6 8648 3216 pts/1 R<+ 21:51 0:00 ps aux admin@i-036f8423c1405f693:~$
paris/i-036f8423c1405f693 02:01
by SadServersdrwxr-xr-x 7 admin admin 4.0K Nov 27 15:00 . drwxr-xr-x 3 root root 4.0K Sep 17 16:44 .. drwx------ 3 admin admin 4.0K Sep 17 17:15 .ansible -rw------- 1 admin admin 43 Nov 27 15:00 .bash_history -rw-r--r-- 1 admin admin 220 Aug 4 2021 .bash_logout -rw-r--r-- 1 admin admin 3.5K Aug 4 2021 .bashrc drwxr-xr-x 3 admin admin 4.0K Nov 27 14:59 .config -rw-r--r-- 1 admin admin 807 Aug 4 2021 .profile drwx------ 2 admin admin 4.0K Sep 17 16:44 .ssh drwxr-xr-x 2 admin root 4.0K Sep 17 17:28 agent drwxr-xr-x 2 admin root 4.0K Sep 17 17:28 data -rw-r--r-- 1 root root 5.0G Sep 17 17:28 datafile -rwxr-xr-x 1 admin root 2.2M Sep 17 17:28 kihei admin@i-0070c8708b4a35386:~$ sudo head -c 10 datafile admin@i-0070c8708b4a35386:~$
kihei/i-0070c8708b4a35386 01:05
by SadServersstemd: --nofork --nopidfile --systemd-activation --syslog-only root 573 0.2 5.9 33040 27900 ? Ss 21:18 0:00 /usr/bin/pythroot 575 0.0 0.9 220796 4340 ? Ssl 21:18 0:00 /usr/sbin/rsyroot 586 0.0 1.4 13492 6676 ? Ss 21:18 0:00 /lib/systemd/root 591 0.0 0.3 2872 1728 tty1 Ss+ 21:18 0:00 /sbin/agetty nux root 592 0.0 0.4 4396 2096 ttyS0 Ss+ 21:18 0:00 /sbin/agetty 0,57600,38400,9600 ttyS0 vt220 root 593 0.0 1.5 13352 7292 ? Ss 21:18 0:00 sshd: /usr/sb-100 startups _chrony 595 0.0 0.7 10852 3664 ? S 21:18 0:00 /usr/sbin/chr_chrony 596 0.0 0.1 10724 548 ? S 21:18 0:00 \_ /usr/sbinroot 610 0.0 3.7 26612 17412 ? Ss 21:18 0:00 /usr/bin/pythrades/unattended-upgrade-shutdown --wait-for-signal admin@i-0f11b62e125014253:~$ curl 127
paris/i-0f11b62e125014253 02:50
by SadServersadmin@i-08bead324c6bc394c:~$ admin@i-08bead324c6bc394c:~$ admin@i-08bead324c6bc394c:~$ netstat -tnlp (Not all processes could be identified, non-owned process info will not be shown, you would have to be root to see it all.) Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State tcp 0 0 127.0.0.1:5000 0.0.0.0:* LISTEN tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN tcp6 0 0 :::6767 :::* LISTEN tcp6 0 0 :::8080 :::* LISTEN tcp6 0 0 :::22 :::* LISTEN admin@i-08bead324c6bc394c:~$ admin@i-08bead324c6bc394c:~$ admin@i-08bead324c6bc394c:~$