command-line-murders/i-025b6a06f09fc937e
by SadServersMore by SadServers
drwx------ 5 root root 4096 Jan 25 19:49 root drwxr-xr-x 22 root root 620 Jan 25 19:49 run lrwxrwxrwx 1 root root 8 Sep 28 2021 sbin -> usr/sbin drwxr-xr-x 2 root root 4096 Sep 28 2021 srv dr-xr-xr-x 13 root root 0 Jan 25 19:48 sys drwxrwxrwt 9 root root 4096 Jan 25 19:49 tmp drwxr-xr-x 14 root root 4096 Sep 28 2021 usr drwxr-xr-x 11 root root 4096 Sep 28 2021 var admin@i-0f29e47a857c873d8:/$ ls opt admin@i-0f29e47a857c873d8:/$ ls run agetty.reload cloud-init dbus initramfs network sshblkid credentials dhclient.ens5.pid lock screen sshchrony crond.pid dhclient6.ens5.pid log sendsigs.omit.d sudchrony-dhcp crond.reboot initctl mount shm sysadmin@i-0f29e47a857c873d8:/$ cd run
paris/i-0f29e47a857c873d8 03:51
by SadServers114 root 0 -20 0 0 0 I 0.0 0.0 0:00.00 ena admin@i-0aba8159a1a1cc7e9:~$ ps PID TTY TIME CMD 695 pts/1 00:00:00 sh 696 pts/1 00:00:00 bash 881 pts/1 00:00:00 ps admin@i-0aba8159a1a1cc7e9:~$ lsof -Ua COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME gotty 563 admin 1u unix 0x000000000e846a83 0t0 10471 type=STREAM gotty 563 admin 2u unix 0x000000000e846a83 0t0 10471 type=STREAM sadagent 564 admin 1u unix 0x00000000cc53c95b 0t0 10477 type=STREAM sadagent 564 admin 2u unix 0x00000000cc53c95b 0t0 10477 type=STREAM admin@i-0aba8159a1a1cc7e9:~$
paris/i-0aba8159a1a1cc7e9 05:20
by SadServersLISTEN 0 4096 *:8080 *:* users:(("gotty",pid=559,fd=6)) LISTEN 0 128 [::]:22 [::]:* admin@i-063fac77df199e9d3:~$ lsof -i :5000 admin@i-063fac77df199e9d3:~$ lsof -i:5000 admin@i-063fac77df199e9d3:~$ lsof -i :8080 COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME gotty 559 admin 6u IPv6 11594 0t0 TCP *:http-alt (LISTEN) gotty 559 admin 7u IPv6 11877 0t0 TCP ip-172-31-39-158.us-east-2.compute.internal:http-alt->ip-172-31-16-109.us-east-2.compute.internal:40662 (ESTABLISHED) admin@i-063fac77df199e9d3:~$ lsof -i :5000 admin@i-063fac77df199e9d3:~$