|
Dec 1, 23:44:58
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 1, 23:44:58
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 1, 23:44:57
3 weeks ago
|
default-host
|
Ssh Login
|
140.82.46.49
|
66.135.25.80
|
root
|
No details
|
Warning
|
|
|
Dec 1, 23:44:57
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 1, 23:44:57
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTSIZE=10000
|
Info
|
|
|
Dec 1, 23:44:57
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTFILESIZE=10000
|
Info
|
|
|
Dec 1, 23:44:47
3 weeks ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 1, 23:44:47
3 weeks ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 1, 23:44:47
3 weeks ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
session_726
|
No details
|
Info
|
|
|
Dec 1, 23:44:46
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTFILE="${HOME}/.bash_history_$(date +%Y%...
|
Critical
|
|
|
Dec 1, 23:44:46
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
echo '=== COMPROMISED: Reports/Analytics Controlle...
|
Info
|
|
|
Dec 1, 23:44:46
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
docker exec azuracast find /var/azuracast/www/back...
|
Info
|
|
|
Dec 1, 23:44:45
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTFILESIZE=50000
|
Info
|
|
|
Dec 1, 23:44:45
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTCONTROL=""
|
Info
|
|
|
Dec 1, 23:44:45
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 1, 23:44:44
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTCONTROL=
|
Info
|
|
|
Dec 1, 23:44:44
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 1, 23:44:44
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 1, 23:44:44
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTSIZE=50000
|
Info
|
|
|
Dec 1, 23:44:43
3 weeks ago
|
default-host
|
Ssh Login
|
140.82.46.49
|
66.135.25.80
|
root
|
No details
|
Warning
|
|
|
Dec 1, 23:44:43
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 1, 23:44:43
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTSIZE=10000
|
Info
|
|
|
Dec 1, 23:44:43
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTFILESIZE=10000
|
Info
|
|
|
Dec 1, 23:44:33
3 weeks ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 1, 23:44:33
3 weeks ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 1, 23:44:33
3 weeks ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
session_724
|
No details
|
Info
|
|
|
Dec 1, 23:44:32
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
xargs grep -l -i 'listener.*report\|report.*listen...
|
Info
|
|
|
Dec 1, 23:44:32
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
head -20
|
Info
|
|
|
Dec 1, 23:44:31
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 1, 23:44:31
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTFILE="${HOME}/.bash_history_$(date +%Y%...
|
Critical
|
|
|
Dec 1, 23:44:31
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
echo '=== COMPROMISED: Listener Report Files ==='
|
Info
|
|
|
Dec 1, 23:44:31
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
docker exec azuracast find /var/azuracast/www -nam...
|
Info
|
|
|
Dec 1, 23:44:30
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTFILESIZE=50000
|
Info
|
|
|
Dec 1, 23:44:30
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTCONTROL=""
|
Info
|
|
|
Dec 1, 23:44:29
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 1, 23:44:29
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 1, 23:44:29
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTSIZE=50000
|
Info
|
|
|
Dec 1, 23:44:28
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTSIZE=10000
|
Info
|
|
|
Dec 1, 23:44:28
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTFILESIZE=10000
|
Info
|
|
|
Dec 1, 23:44:28
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTCONTROL=
|
Info
|
|
|
Dec 1, 23:44:27
3 weeks ago
|
default-host
|
Ssh Login
|
140.82.46.49
|
66.135.25.80
|
root
|
No details
|
Warning
|
|
|
Dec 1, 23:44:27
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 1, 23:39:05
3 weeks ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 1, 23:39:05
3 weeks ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 1, 23:39:05
3 weeks ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
session_723
|
No details
|
Info
|
|
|
Dec 1, 23:39:04
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
docker exec azuracast php /var/azuracast/www/bin/c...
|
Info
|
|
|
Dec 1, 23:39:04
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
head -30
|
Info
|
|
|
Dec 1, 23:39:03
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTFILE="${HOME}/.bash_history_$(date +%Y%...
|
Critical
|
|
|
Dec 1, 23:39:03
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
echo '=== COMPROMISED: Station Webhooks ==='
|
Info
|
|
|
Dec 1, 23:39:02
3 weeks ago
|
default-host
|
Command
|
140.82.46.49
|
66.135.25.80
|
root
|
export HISTCONTROL=""
|
Info
|
|