|
Dec 1, 23:22:48
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
echo '=== SYSTEM CRONS ==='
|
Info
|
|
|
Dec 1, 23:22:48
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
cat /etc/cron.d/* 2> /dev/null
|
Info
|
|
|
Dec 1, 23:22:48
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
echo
|
Info
|
|
|
Dec 1, 23:22:47
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 1, 23:22:47
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 1, 23:22:47
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTSIZE=50000
|
Info
|
|
|
Dec 1, 23:22:47
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTFILESIZE=50000
|
Info
|
|
|
Dec 1, 23:22:47
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTCONTROL=""
|
Info
|
|
|
Dec 1, 23:22:46
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTFILESIZE=10000
|
Info
|
|
|
Dec 1, 23:22:46
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTCONTROL=
|
Info
|
|
|
Dec 1, 23:22:45
3 months ago
|
default-host
|
Ssh Login
|
64.176.194.149
|
66.135.25.80
|
root
|
No details
|
Warning
|
|
|
Dec 1, 23:22:45
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 1, 23:22:45
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTSIZE=10000
|
Info
|
|
|
Dec 1, 23:22:23
3 months ago
|
default-host
|
Ssh Logout
|
64.176.194.149
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 1, 23:22:23
3 months ago
|
default-host
|
Ssh Logout
|
64.176.194.149
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 1, 23:22:23
3 months ago
|
default-host
|
Ssh Logout
|
64.176.194.149
|
N/A
|
session_752
|
No details
|
Info
|
|
|
Dec 1, 23:22:22
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
echo '=== CHECKING FOR SCRIPTS THAT GENERATE FAKE...
|
Info
|
|
|
Dec 1, 23:22:22
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
find /root /opt /var/www /home -name '*.py' -o -na...
|
Critical
|
|
|
Dec 1, 23:22:22
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
xargs grep -l 'listener\|curl.*radio\|wget.*radio'...
|
Critical
|
|
|
Dec 1, 23:22:22
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
head -20
|
Info
|
|
|
Dec 1, 23:22:21
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTFILESIZE=50000
|
Info
|
|
|
Dec 1, 23:22:21
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTCONTROL=""
|
Info
|
|
|
Dec 1, 23:22:21
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 1, 23:22:21
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTFILE="${HOME}/.bash_history_$(date +%Y%...
|
Critical
|
|
|
Dec 1, 23:22:20
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTCONTROL=
|
Info
|
|
|
Dec 1, 23:22:20
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 1, 23:22:20
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 1, 23:22:20
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTSIZE=50000
|
Info
|
|
|
Dec 1, 23:22:19
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 1, 23:22:19
3 months ago
|
default-host
|
Ssh Login
|
64.176.194.149
|
66.135.25.80
|
root
|
No details
|
Warning
|
|
|
Dec 1, 23:22:19
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTSIZE=10000
|
Info
|
|
|
Dec 1, 23:22:19
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTFILESIZE=10000
|
Info
|
|
|
Dec 1, 23:22:18
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
crontab -l 2> /dev/null
|
Info
|
|
|
Dec 1, 23:22:18
3 months ago
|
default-host
|
Ssh Logout
|
64.176.194.149
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 1, 23:22:18
3 months ago
|
default-host
|
Ssh Logout
|
64.176.194.149
|
N/A
|
session_750
|
No details
|
Info
|
|
|
Dec 1, 23:22:18
3 months ago
|
default-host
|
Ssh Logout
|
64.176.194.149
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 1, 23:22:17
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTCONTROL=""
|
Info
|
|
|
Dec 1, 23:22:17
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 1, 23:22:17
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTFILE="${HOME}/.bash_history_$(date +%Y%...
|
Critical
|
|
|
Dec 1, 23:22:17
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
echo '=== CHECKING FOR SCHEDULED LISTENER MANIPULA...
|
Info
|
|
|
Dec 1, 23:22:16
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 1, 23:22:16
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTSIZE=50000
|
Info
|
|
|
Dec 1, 23:22:16
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTFILESIZE=50000
|
Info
|
|
|
Dec 1, 23:22:15
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTFILESIZE=10000
|
Info
|
|
|
Dec 1, 23:22:15
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTCONTROL=
|
Info
|
|
|
Dec 1, 23:22:15
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 1, 23:22:14
3 months ago
|
default-host
|
Ssh Login
|
64.176.194.149
|
66.135.25.80
|
root
|
No details
|
Warning
|
|
|
Dec 1, 23:22:14
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 1, 23:22:14
3 months ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTSIZE=10000
|
Info
|
|
|
Dec 1, 23:22:02
3 months ago
|
default-host
|
Azuracast Web User Login
|
64.176.194.149
|
173.63.205.69
|
N/A
|
No details
|
Info
|
|