|
Dec 2, 02:16:06
3 months ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
session_800
|
No details
|
Info
|
|
|
Dec 2, 02:16:05
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 2, 02:16:05
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTFILE="${HOME}/.bash_history_$(date +%Y%...
|
Critical
|
|
|
Dec 2, 02:16:05
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
docker exec azuracast mariadb -u azuracast -pREffK...
|
Info
|
|
|
Dec 2, 02:16:04
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTSIZE=50000
|
Info
|
|
|
Dec 2, 02:16:04
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTFILESIZE=50000
|
Info
|
|
|
Dec 2, 02:16:04
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTCONTROL=""
|
Info
|
|
|
Dec 2, 02:16:03
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 2, 02:16:03
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 2, 02:16:02
3 months ago
|
default-host
|
Ssh Login
|
140.82.46.49
|
66.135.25.80
|
root
|
No details
|
Warning
|
|
|
Dec 2, 02:16:02
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTSIZE=10000
|
Info
|
|
|
Dec 2, 02:16:02
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTFILESIZE=10000
|
Info
|
|
|
Dec 2, 02:16:02
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTCONTROL=
|
Info
|
|
|
Dec 2, 02:16:01
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 2, 02:15:53
3 months ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 2, 02:15:53
3 months ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
session_798
|
No details
|
Info
|
|
|
Dec 2, 02:15:53
3 months ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 2, 02:15:52
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
echo "=== AZURACAST AUDIT LOG - RECENT ENTRIES ===...
|
Info
|
|
|
Dec 2, 02:15:52
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
docker exec azuracast mariadb -u azuracast -pREffK...
|
Info
|
|
|
Dec 2, 02:15:51
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTCONTROL=""
|
Info
|
|
|
Dec 2, 02:15:51
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 2, 02:15:51
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTFILE="${HOME}/.bash_history_$(date +%Y%...
|
Critical
|
|
|
Dec 2, 02:15:50
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 2, 02:15:50
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 2, 02:15:50
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTSIZE=50000
|
Info
|
|
|
Dec 2, 02:15:50
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTFILESIZE=50000
|
Info
|
|
|
Dec 2, 02:15:49
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTSIZE=10000
|
Info
|
|
|
Dec 2, 02:15:49
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTFILESIZE=10000
|
Info
|
|
|
Dec 2, 02:15:49
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTCONTROL=
|
Info
|
|
|
Dec 2, 02:15:48
3 months ago
|
default-host
|
Ssh Login
|
140.82.46.49
|
66.135.25.80
|
root
|
No details
|
Warning
|
|
|
Dec 2, 02:15:48
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 2, 02:15:37
3 months ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 2, 02:15:37
3 months ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 2, 02:15:37
3 months ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
session_796
|
No details
|
Info
|
|
|
Dec 2, 02:15:36
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
echo "=== CHECK DOCKER VOLUMES ==="
|
Info
|
|
|
Dec 2, 02:15:36
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
docker volume ls
|
Info
|
|
|
Dec 2, 02:15:35
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
ls -la /tmp/*.sql /tmp/*.php /tmp/*.py 2> /dev/nul...
|
Info
|
|
|
Dec 2, 02:15:35
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
echo "None found"
|
Info
|
|
|
Dec 2, 02:15:35
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
echo ""
|
Info
|
|
|
Dec 2, 02:15:34
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
echo ""
|
Info
|
|
|
Dec 2, 02:15:34
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
echo "=== CHECK /tmp FOR SUSPICIOUS FILES ==="
|
Info
|
|
|
Dec 2, 02:15:33
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
echo "=== CHECK FOR ANY DATABASE EVENTS ==="
|
Info
|
|
|
Dec 2, 02:15:33
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
docker exec azuracast mariadb -u azuracast -pREffK...
|
Critical
|
|
|
Dec 2, 02:15:32
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
echo "=== CHECK FOR LISTENER TABLE TRIGGERS ==="
|
Info
|
|
|
Dec 2, 02:15:32
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
docker exec azuracast mariadb -u azuracast -pREffK...
|
Critical
|
|
|
Dec 2, 02:15:32
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
echo ""
|
Info
|
|
|
Dec 2, 02:15:31
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
echo ""
|
Info
|
|
|
Dec 2, 02:15:30
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
echo "=== CHECK FOR ANY CUSTOM SCRIPTS OUTSIDE AZU...
|
Info
|
|
|
Dec 2, 02:15:30
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
find /var -name "*.php" -not -path "*/azuracast/*"...
|
Info
|
|
|
Dec 2, 02:15:30
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
head -20
|
Info
|
|