kihei/i-0ee7dc3aa4135ee9a
by SadServersMore by SadServers
-rw-r--r-- 1 root root 0 Feb 10 16:15 setgroups -r--r--r-- 1 root root 0 Feb 10 16:15 smaps -r--r--r-- 1 root root 0 Feb 10 16:15 smaps_rollup -r-------- 1 root root 0 Feb 10 16:15 stack -r--r--r-- 1 root root 0 Feb 10 16:10 stat -r--r--r-- 1 root root 0 Feb 10 16:15 statm -r--r--r-- 1 root root 0 Feb 10 16:10 status -r-------- 1 root root 0 Feb 10 16:15 syscall dr-xr-xr-x 3 root root 0 Feb 10 16:13 task -rw-r--r-- 1 root root 0 Feb 10 16:15 timens_offsets -r--r--r-- 1 root root 0 Feb 10 16:15 timers -rw-rw-rw- 1 root root 0 Feb 10 16:15 timerslack_ns -rw-r--r-- 1 root root 0 Feb 10 16:15 uid_map -r--r--r-- 1 root root 0 Feb 10 16:15 wchan admin@i-09ee8de58a0c22547:/proc/579$
paris/i-09ee8de58a0c22547 06:11
by SadServersSep 24 23:20:40 i-03be7122de01cf0bf sudo: pam_unix(sudo:session): session openedSep 24 23:20:40 i-03be7122de01cf0bf sudo: pam_unix(sudo:session): session closedSep 24 23:20:51 i-03be7122de01cf0bf systemd-logind[573]: Power key pressed. Sep 24 23:20:51 i-03be7122de01cf0bf systemd-logind[573]: Powering Off... Sep 24 23:20:52 i-03be7122de01cf0bf systemd-logind[573]: System is powering downSep 24 23:20:52 i-03be7122de01cf0bf sshd[636]: pam_unix(sshd:session): session cSep 24 23:20:52 i-03be7122de01cf0bf sshd[636]: pam_systemd(sshd:session): FailedNov 27 20:53:34 i-09484828e711b692d passwd[546]: password for 'admin' changed byNov 27 20:53:34 i-09484828e711b692d systemd-logind[578]: Watching system buttonsNov 27 20:53:34 i-09484828e711b692d systemd-logind[578]: Watching system buttonsNov 27 20:53:34 i-09484828e711b692d systemd-logind[578]: Watching system buttonsNov 27 20:53:34 i-09484828e711b692d systemd-logind[578]: New seat seat0. Nov 27 20:53:34 i-09484828e711b692d sshd[586]: Server listening on 0.0.0.0 port Nov 27 20:53:34 i-09484828e711b692d sshd[586]: Server listening on :: port 22.
paris/i-09484828e711b692d 05:17
by SadServers559 ? S<sl 0:00 /home/admin/agent/sadagent 562 ? Ss 0:00 /usr/sbin/cron -f 563 ? Ss 0:00 /usr/bin/dbus-daemon --system --address=systemd: -- 575 ? Ss 0:00 /usr/bin/python3 /home/admin/webserver.py 576 ? Ssl 0:00 /usr/sbin/rsyslogd -n -iNONE 582 ? Ss 0:00 /lib/systemd/systemd-logind 584 ? Ss 0:00 sshd: /usr/sbin/sshd -D [listener] 0 of 10-100 star 585 tty1 Ss+ 0:00 /sbin/agetty -o -p -- \u --noclear tty1 linux 586 ttyS0 Ss+ 0:00 /sbin/agetty -o -p -- \u --keep-baud 115200,57600,3 588 ? S 0:00 /usr/sbin/chronyd -F 1 589 ? S 0:00 \_ /usr/sbin/chronyd -F 1 606 ? Ss 0:00 /usr/bin/python3 /usr/share/unattended-upgrades/unaadmin@i-04f25c68fa11fb6a2:~$ curl -A "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5it/537.36 (KHTML, like Gecko) Chrome/W.X.Y.Z Mobile Safari/537.36 (compatible; G.google.com/bot.html)"