|
Dec 7, 23:22:44
2 days ago
|
default-host
|
Ssh Login
|
64.176.212.158
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 7, 23:22:21
2 days ago
|
default-host
|
Ssh Login
|
104.238.132.126
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 7, 22:22:43
2 days ago
|
default-host
|
Ssh Login
|
64.176.212.158
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 7, 22:22:20
2 days ago
|
default-host
|
Ssh Login
|
104.238.132.126
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 7, 21:22:42
2 days ago
|
default-host
|
Ssh Login
|
64.176.212.158
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 7, 21:22:20
2 days ago
|
default-host
|
Ssh Login
|
104.238.132.126
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 7, 20:42:11
2 days ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
session_1201
|
No details
|
Info
|
|
|
Dec 7, 20:42:11
2 days ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 7, 20:42:11
2 days ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 7, 20:39:38
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
pwd -P >| /tmp/claude-df5d-cwd
|
Info
|
|
|
Dec 7, 20:39:38
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
sort -rn
|
Info
|
|
|
Dec 7, 20:39:37
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
uniq -c
|
Info
|
|
|
Dec 7, 20:39:37
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
sort
|
Info
|
|
|
Dec 7, 20:39:36
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
grep -v '^shopt '
|
Critical
|
|
|
Dec 7, 20:39:36
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
grep -v '^export '
|
Info
|
|
|
Dec 7, 20:39:36
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
jq -r .command 2> /dev/null
|
Info
|
|
|
Dec 7, 20:39:35
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
grep 66.135.25.80
|
Info
|
|
|
Dec 7, 20:39:35
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
grep '"event_type": "command"'
|
Info
|
|
|
Dec 7, 20:39:34
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
grep 2025-12-02T05 /var/log/grutu/collected_logs.j...
|
Info
|
|
|
Dec 7, 20:39:34
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
eval "grep 2025-12-02T05 /var/log/grutu/collected_...
|
Critical
|
|
|
Dec 7, 20:39:33
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTFILE="${HOME}/.bash_history_$(date +%Y%...
|
Critical
|
|
|
Dec 7, 20:39:33
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 7, 20:39:32
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTCONTROL=""
|
Info
|
|
|
Dec 7, 20:39:32
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTFILESIZE=50000
|
Info
|
|
|
Dec 7, 20:39:32
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTSIZE=50000
|
Info
|
|
|
Dec 7, 20:39:31
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 7, 20:39:31
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 7, 20:39:31
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTCONTROL=
|
Info
|
|
|
Dec 7, 20:39:30
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTFILESIZE=10000
|
Info
|
|
|
Dec 7, 20:39:30
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTSIZE=10000
|
Info
|
|
|
Dec 7, 20:39:29
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 7, 20:39:29
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
source /etc/profile.d/honeypot.sh 2> /dev/null
|
Critical
|
|
|
Dec 7, 20:39:29
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
true
|
Info
|
|
|
Dec 7, 20:39:28
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
mesg n 2> /dev/null
|
Info
|
|
|
Dec 7, 20:39:28
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTFILE="${HOME}/.bash_history_$(date +%Y%...
|
Critical
|
|
|
Dec 7, 20:39:27
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 7, 20:39:26
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTCONTROL=""
|
Info
|
|
|
Dec 7, 20:39:26
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTFILESIZE=50000
|
Info
|
|
|
Dec 7, 20:39:26
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTSIZE=50000
|
Info
|
|
|
Dec 7, 20:39:25
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 7, 20:39:25
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 7, 20:39:24
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTCONTROL=
|
Info
|
|
|
Dec 7, 20:39:24
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTFILESIZE=10000
|
Info
|
|
|
Dec 7, 20:39:23
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTSIZE=10000
|
Info
|
|
|
Dec 7, 20:39:23
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 7, 20:39:22
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
. ~/.bashrc
|
Critical
|
|
|
Dec 7, 20:39:22
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
[ -f ~/.bashrc ]
|
Critical
|
|
|
Dec 7, 20:39:21
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
[ "$BASH" ]
|
Critical
|
|
|
Dec 7, 20:39:21
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
unset i
|
Info
|
|
|
Dec 7, 20:39:21
2 days ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTFILE="${HOME}/.bash_history_$(date +%Y%...
|
Critical
|
|