command-line-murders/i-035f5d158a8f9d6df
by SadServersMore by SadServers
drwx------ 5 root root 4096 Nov 1 12:56 . drwxr-xr-x 18 root root 4096 Nov 1 12:54 .. -rw-r--r-- 1 root root 571 Apr 10 2021 .bashrc drwxr-xr-x 3 root root 4096 Nov 1 12:56 .config drwx------ 5 root root 4096 Nov 1 12:56 .mc -rw-r--r-- 1 root root 161 Jul 9 2019 .profile drwx------ 2 root root 4096 Sep 17 16:44 .ssh --wxrw--wT 1 root root 984 Sep 17 17:16 mc.sh root@i-065b0b4396750e734:~# cat .config/ cat: .config/: Is a directory root@i-065b0b4396750e734:~# cd .config/ root@i-065b0b4396750e734:~/.config# ls asciinema root@i-065b0b4396750e734:~/.config# cat asciinema/install-id a8958cd1-8249-4f60-9b73-4859fccd1f47root@i-065b0b4396750e734:~/.config#
kihei/i-065b0b4396750e734 02:07
by SadServerstcp ESTAB 0 0 [::ffff:172.31. [::ffff:172.31.16.109]:49770 timer:(keepalive,3.216ms,0) admin@i-0bce630416db45b25:~$ admin@i-0bce630416db45b25:~$ admin@i-0bce630416db45b25:~$ admin@i-0bce630416db45b25:~$ lsof -i:5000 admin@i-0bce630416db45b25:~$ admin@i-0bce630416db45b25:~$ lsof -i COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME gotty 558 admin 6u IPv6 10895 0t0 TCP *:http-alt (LISTEN) gotty 558 admin 7u IPv6 12340 0t0 TCP ip-172-31-40-35.us-east-2.co>ip-172-31-16-109.us-east-2.compute.internal:49770 (ESTABLISHED) sadagent 559 admin 7u IPv6 1958 0t0 TCP *:6767 (LISTEN) admin@i-0bce630416db45b25:~$ admin@i-0bce630416db45b25:~$
paris/i-0bce630416db45b25 03:00
by SadServers5.1G . admin@i-0d1a853573aef78d6:~$ du -sh 5.1G . admin@i-0d1a853573aef78d6:~$ du -h 11M ./agent 4.0K ./.ansible/tmp 8.0K ./.ansible 4.0K ./data 8.0K ./.config/asciinema 12K ./.config 8.0K ./.ssh 5.1G . admin@i-0d1a853573aef78d6:~$ pwd /home/admin admin@i-0d1a853573aef78d6:~$