|
Dec 1, 23:26:02
3 months ago
|
default-host
|
Azuracast Web User Login
|
64.176.194.149
|
173.63.205.69
|
N/A
|
No details
|
Info
|
|
|
Dec 1, 23:25:01
3 months ago
|
default-host
|
Azuracast Web User Login
|
64.176.194.149
|
173.63.205.69
|
N/A
|
No details
|
Info
|
|
|
Dec 1, 23:24:02
3 months ago
|
default-host
|
Azuracast Web User Login
|
64.176.194.149
|
173.63.205.69
|
N/A
|
No details
|
Info
|
|
|
Dec 1, 23:23:30
3 months ago
|
default-host
|
Ssh Logout
|
64.176.194.149
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 1, 23:23:30
3 months ago
|
default-host
|
Ssh Logout
|
64.176.194.149
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 1, 23:23:30
3 months ago
|
default-host
|
Ssh Logout
|
64.176.194.149
|
N/A
|
session_757
|
No details
|
Info
|
|
|
Dec 1, 23:23:29
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
grep -E 'listener|radio|stream|curl|wget'
|
Critical
|
|
|
Dec 1, 23:23:29
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
grep -v grep
|
Info
|
|
|
Dec 1, 23:23:29
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
head -20
|
Info
|
|
|
Dec 1, 23:23:28
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 1, 23:23:28
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTFILE="${HOME}/.bash_history_$(date +%Y%...
|
Critical
|
|
|
Dec 1, 23:23:28
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
echo '=== CHECKING RUNNING PROCESSES FOR LISTENER...
|
Info
|
|
|
Dec 1, 23:23:28
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
ps aux
|
Info
|
|
|
Dec 1, 23:23:27
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTSIZE=50000
|
Info
|
|
|
Dec 1, 23:23:27
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTFILESIZE=50000
|
Info
|
|
|
Dec 1, 23:23:27
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTCONTROL=""
|
Info
|
|
|
Dec 1, 23:23:26
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTCONTROL=
|
Info
|
|
|
Dec 1, 23:23:26
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 1, 23:23:26
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 1, 23:23:25
3 months ago
|
default-host
|
Ssh Login
|
64.176.194.149
|
66.135.25.80
|
root
|
No details
|
Warning
|
|
|
Dec 1, 23:23:25
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 1, 23:23:25
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTSIZE=10000
|
Info
|
|
|
Dec 1, 23:23:25
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTFILESIZE=10000
|
Info
|
|
|
Dec 1, 23:23:24
3 months ago
|
default-host
|
Ssh Logout
|
64.176.194.149
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 1, 23:23:24
3 months ago
|
default-host
|
Ssh Logout
|
64.176.194.149
|
N/A
|
session_755
|
No details
|
Info
|
|
|
Dec 1, 23:23:24
3 months ago
|
default-host
|
Ssh Logout
|
64.176.194.149
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 1, 23:23:15
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
xargs grep -l -E 'requests.get.*radio|urllib.*radi...
|
Info
|
|
|
Dec 1, 23:23:15
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
head -10
|
Info
|
|
|
Dec 1, 23:23:14
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 1, 23:23:14
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTFILE="${HOME}/.bash_history_$(date +%Y%...
|
Critical
|
|
|
Dec 1, 23:23:14
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
echo '=== LOOKING FOR LISTENER BOT/MANIPULATION SC...
|
Info
|
|
|
Dec 1, 23:23:14
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
find / -name '*.py' -newer /etc/passwd 2> /dev/nul...
|
Info
|
|
|
Dec 1, 23:23:13
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 1, 23:23:13
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTSIZE=50000
|
Info
|
|
|
Dec 1, 23:23:13
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTFILESIZE=50000
|
Info
|
|
|
Dec 1, 23:23:13
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTCONTROL=""
|
Info
|
|
|
Dec 1, 23:23:12
3 months ago
|
default-host
|
Ssh Login
|
64.176.194.149
|
66.135.25.80
|
root
|
No details
|
Warning
|
|
|
Dec 1, 23:23:12
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 1, 23:23:12
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTSIZE=10000
|
Info
|
|
|
Dec 1, 23:23:12
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTFILESIZE=10000
|
Info
|
|
|
Dec 1, 23:23:12
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTCONTROL=
|
Info
|
|
|
Dec 1, 23:23:12
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 1, 23:23:02
3 months ago
|
default-host
|
Azuracast Web User Login
|
64.176.194.149
|
173.63.205.69
|
N/A
|
No details
|
Info
|
|
|
Dec 1, 23:22:50
3 months ago
|
default-host
|
Ssh Logout
|
64.176.194.149
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 1, 23:22:50
3 months ago
|
default-host
|
Ssh Logout
|
64.176.194.149
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 1, 23:22:50
3 months ago
|
default-host
|
Ssh Logout
|
64.176.194.149
|
N/A
|
session_753
|
No details
|
Info
|
|
|
Dec 1, 23:22:49
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
echo '=== DOCKER CRONS ==='
|
Info
|
|
|
Dec 1, 23:22:49
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
docker exec azuracast crontab -l 2> /dev/null
|
Info
|
|
|
Dec 1, 23:22:48
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 1, 23:22:48
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTFILE="${HOME}/.bash_history_$(date +%Y%...
|
Critical
|
|