|
Dec 2, 02:01:18
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 2, 02:01:17
2 weeks ago
|
default-host
|
Ssh Login
|
64.176.212.158
|
66.135.25.80
|
root
|
No details
|
Warning
|
|
|
Dec 2, 02:01:17
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 2, 02:01:05
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTFILE="${HOME}/.bash_history_$(date +%Y%...
|
Critical
|
|
|
Dec 2, 02:01:05
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
docker exec azuracast mariadb -u azuracast -p2aKzj...
|
Info
|
|
|
Dec 2, 02:01:04
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTSIZE=50000
|
Info
|
|
|
Dec 2, 02:01:04
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTFILESIZE=50000
|
Info
|
|
|
Dec 2, 02:01:04
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTCONTROL=""
|
Info
|
|
|
Dec 2, 02:01:04
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 2, 02:01:03
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTCONTROL=
|
Info
|
|
|
Dec 2, 02:01:03
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 2, 02:01:03
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 2, 02:01:02
2 weeks ago
|
default-host
|
Ssh Login
|
64.176.212.158
|
66.135.25.80
|
root
|
No details
|
Warning
|
|
|
Dec 2, 02:01:02
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTSIZE=10000
|
Info
|
|
|
Dec 2, 02:01:02
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTFILESIZE=10000
|
Info
|
|
|
Dec 2, 02:01:01
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 2, 02:00:51
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
echo "=== CHECK FOR SUSPICIOUS SCRIPTS ==="
|
Info
|
|
|
Dec 2, 02:00:51
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
find /root -name "*.sh" -o -name "*.php" -o -name...
|
Critical
|
|
|
Dec 2, 02:00:51
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
head -20
|
Info
|
|
|
Dec 2, 02:00:50
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
echo "=== DOCKER CRONTABS ==="
|
Info
|
|
|
Dec 2, 02:00:50
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
docker exec azuracast crontab -l 2> /dev/null
|
Info
|
|
|
Dec 2, 02:00:50
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
echo "No docker crontab"
|
Info
|
|
|
Dec 2, 02:00:50
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
echo ""
|
Info
|
|
|
Dec 2, 02:00:49
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
echo "=== SYSTEM CRONTABS ==="
|
Info
|
|
|
Dec 2, 02:00:49
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
ls -la /etc/cron.d/
|
Info
|
|
|
Dec 2, 02:00:49
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
echo ""
|
Info
|
|
|
Dec 2, 02:00:48
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
echo "=== ROOT CRONTAB ==="
|
Info
|
|
|
Dec 2, 02:00:48
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
crontab -l 2> /dev/null
|
Info
|
|
|
Dec 2, 02:00:48
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
echo ""
|
Info
|
|
|
Dec 2, 02:00:47
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTFILESIZE=50000
|
Info
|
|
|
Dec 2, 02:00:47
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTCONTROL=""
|
Info
|
|
|
Dec 2, 02:00:47
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 2, 02:00:47
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTFILE="${HOME}/.bash_history_$(date +%Y%...
|
Critical
|
|
|
Dec 2, 02:00:46
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTCONTROL=
|
Info
|
|
|
Dec 2, 02:00:46
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 2, 02:00:46
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 2, 02:00:46
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTSIZE=50000
|
Info
|
|
|
Dec 2, 02:00:45
2 weeks ago
|
default-host
|
Ssh Login
|
64.176.212.158
|
66.135.25.80
|
root
|
No details
|
Warning
|
|
|
Dec 2, 02:00:45
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 2, 02:00:45
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTSIZE=10000
|
Info
|
|
|
Dec 2, 02:00:45
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTFILESIZE=10000
|
Info
|
|
|
Dec 2, 02:00:27
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
docker exec azuracast cat /var/azuracast/www/backe...
|
Info
|
|
|
Dec 2, 02:00:26
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTFILESIZE=50000
|
Info
|
|
|
Dec 2, 02:00:26
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTCONTROL=""
|
Info
|
|
|
Dec 2, 02:00:26
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 2, 02:00:26
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTFILE="${HOME}/.bash_history_$(date +%Y%...
|
Critical
|
|
|
Dec 2, 02:00:25
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTCONTROL=
|
Info
|
|
|
Dec 2, 02:00:25
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 2, 02:00:25
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 2, 02:00:25
2 weeks ago
|
default-host
|
Command
|
64.176.212.158
|
66.135.25.80
|
root
|
export HISTSIZE=50000
|
Info
|
|