|
Dec 1, 22:37:44
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
ps aux
|
Info
|
|
|
Dec 1, 22:37:40
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
grep -v "/azuracast/"
|
Info
|
|
|
Dec 1, 22:37:40
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
head -20
|
Info
|
|
|
Dec 1, 22:37:39
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
echo ""
|
Info
|
|
|
Dec 1, 22:37:39
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
echo "--- Recently modified Python files (30 days)...
|
Info
|
|
|
Dec 1, 22:37:39
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
find / -name "*.py" -mtime -30 2> /dev/null
|
Info
|
|
|
Dec 1, 22:37:26
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
find / -type d -name ".*" -exec find {} -name "*.p...
|
Info
|
|
|
Dec 1, 22:37:26
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
head -20
|
Info
|
|
|
Dec 1, 22:37:25
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
find /opt -name "*.py" \! -path "*/azuracast/*" 2>...
|
Info
|
|
|
Dec 1, 22:37:25
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
head -20
|
Info
|
|
|
Dec 1, 22:37:25
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
echo ""
|
Info
|
|
|
Dec 1, 22:37:25
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
echo "--- Hidden directories with Python ---"
|
Critical
|
|
|
Dec 1, 22:37:24
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
echo ""
|
Info
|
|
|
Dec 1, 22:37:24
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
echo "--- Python files in unusual locations ---"
|
Info
|
|
|
Dec 1, 22:37:24
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
find /tmp /var/tmp /dev/shm /root /home -name "*.p...
|
Critical
|
|
|
Dec 1, 22:37:23
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTCONTROL=""
|
Info
|
|
|
Dec 1, 22:37:23
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 1, 22:37:23
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTFILE="${HOME}/.bash_history_$(date +%Y%...
|
Critical
|
|
|
Dec 1, 22:37:23
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
echo "=== AZURA5 SCAN ==="
|
Info
|
|
|
Dec 1, 22:37:22
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 1, 22:37:22
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 1, 22:37:22
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTSIZE=50000
|
Info
|
|
|
Dec 1, 22:37:22
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTFILESIZE=50000
|
Info
|
|
|
Dec 1, 22:37:21
3 weeks ago
|
default-host
|
Ssh Login
|
64.176.194.149
|
66.135.25.80
|
root
|
No details
|
Warning
|
|
|
Dec 1, 22:37:21
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 1, 22:37:21
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTSIZE=10000
|
Info
|
|
|
Dec 1, 22:37:21
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTFILESIZE=10000
|
Info
|
|
|
Dec 1, 22:37:21
3 weeks ago
|
default-host
|
Command
|
64.176.194.149
|
66.135.25.80
|
root
|
export HISTCONTROL=
|
Info
|
|
|
Dec 1, 22:37:20
3 weeks ago
|
default-host
|
Ssh Logout
|
104.238.132.126
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 1, 22:37:20
3 weeks ago
|
default-host
|
Ssh Logout
|
104.238.132.126
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 1, 22:37:20
3 weeks ago
|
default-host
|
Ssh Logout
|
104.238.132.126
|
N/A
|
session_852
|
No details
|
Info
|
|
|
Dec 1, 22:37:19
3 weeks ago
|
default-host
|
Command
|
104.238.132.126
|
66.135.25.80
|
root
|
grep -i python
|
Info
|
|
|
Dec 1, 22:37:19
3 weeks ago
|
default-host
|
Command
|
104.238.132.126
|
66.135.25.80
|
root
|
grep -v grep
|
Info
|
|
|
Dec 1, 22:37:18
3 weeks ago
|
default-host
|
Command
|
104.238.132.126
|
66.135.25.80
|
root
|
echo ""
|
Info
|
|
|
Dec 1, 22:37:18
3 weeks ago
|
default-host
|
Command
|
104.238.132.126
|
66.135.25.80
|
root
|
echo "--- Python processes running ---"
|
Info
|
|
|
Dec 1, 22:37:18
3 weeks ago
|
default-host
|
Command
|
104.238.132.126
|
66.135.25.80
|
root
|
ps aux
|
Info
|
|
|
Dec 1, 22:37:09
3 weeks ago
|
default-host
|
Command
|
104.238.132.126
|
66.135.25.80
|
root
|
grep -v "/azuracast/"
|
Info
|
|
|
Dec 1, 22:37:09
3 weeks ago
|
default-host
|
Command
|
104.238.132.126
|
66.135.25.80
|
root
|
head -20
|
Info
|
|
|
Dec 1, 22:37:08
3 weeks ago
|
default-host
|
Command
|
104.238.132.126
|
66.135.25.80
|
root
|
echo ""
|
Info
|
|
|
Dec 1, 22:37:08
3 weeks ago
|
default-host
|
Command
|
104.238.132.126
|
66.135.25.80
|
root
|
echo "--- Recently modified Python files (30 days)...
|
Info
|
|
|
Dec 1, 22:37:08
3 weeks ago
|
default-host
|
Command
|
104.238.132.126
|
66.135.25.80
|
root
|
find / -name "*.py" -mtime -30 2> /dev/null
|
Info
|
|
|
Dec 1, 22:36:52
3 weeks ago
|
default-host
|
Command
|
104.238.132.126
|
66.135.25.80
|
root
|
echo ""
|
Info
|
|
|
Dec 1, 22:36:52
3 weeks ago
|
default-host
|
Command
|
104.238.132.126
|
66.135.25.80
|
root
|
echo "--- Hidden directories with Python ---"
|
Critical
|
|
|
Dec 1, 22:36:52
3 weeks ago
|
default-host
|
Command
|
104.238.132.126
|
66.135.25.80
|
root
|
find / -type d -name ".*" -exec find {} -name "*.p...
|
Info
|
|
|
Dec 1, 22:36:52
3 weeks ago
|
default-host
|
Command
|
104.238.132.126
|
66.135.25.80
|
root
|
head -20
|
Info
|
|
|
Dec 1, 22:36:51
3 weeks ago
|
default-host
|
Command
|
104.238.132.126
|
66.135.25.80
|
root
|
find /opt -name "*.py" \! -path "*/azuracast/*" 2>...
|
Info
|
|
|
Dec 1, 22:36:51
3 weeks ago
|
default-host
|
Command
|
104.238.132.126
|
66.135.25.80
|
root
|
head -20
|
Info
|
|
|
Dec 1, 22:36:50
3 weeks ago
|
default-host
|
Command
|
104.238.132.126
|
66.135.25.80
|
root
|
echo ""
|
Info
|
|
|
Dec 1, 22:36:50
3 weeks ago
|
default-host
|
Command
|
104.238.132.126
|
66.135.25.80
|
root
|
echo "--- Python files in unusual locations ---"
|
Info
|
|
|
Dec 1, 22:36:50
3 weeks ago
|
default-host
|
Command
|
104.238.132.126
|
66.135.25.80
|
root
|
find /tmp /var/tmp /dev/shm /root /home -name "*.p...
|
Critical
|
|