|
Dec 8, 11:17:49
3 months ago
|
default-host
|
Ssh Login
|
104.238.132.126
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 8, 10:17:54
3 months ago
|
default-host
|
Ssh Login
|
64.176.212.158
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 8, 10:17:41
3 months ago
|
default-host
|
Ssh Login
|
104.238.132.126
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 8, 09:19:45
3 months ago
|
default-host
|
Ssh Login
|
64.176.212.158
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 8, 09:18:57
3 months ago
|
default-host
|
Ssh Login
|
104.238.132.126
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 8, 07:20:11
3 months ago
|
default-host
|
Ssh Login
|
104.238.132.126
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 8, 07:18:23
3 months ago
|
default-host
|
Ssh Login
|
64.176.212.158
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 8, 06:19:21
3 months ago
|
default-host
|
Ssh Login
|
104.238.132.126
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 8, 06:17:59
3 months ago
|
default-host
|
Ssh Login
|
64.176.212.158
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 8, 05:20:08
3 months ago
|
default-host
|
Ssh Login
|
104.238.132.126
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 8, 05:18:22
3 months ago
|
default-host
|
Ssh Login
|
64.176.212.158
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 8, 04:20:07
3 months ago
|
default-host
|
Ssh Login
|
104.238.132.126
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 8, 04:18:22
3 months ago
|
default-host
|
Ssh Login
|
64.176.212.158
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 8, 03:20:06
3 months ago
|
default-host
|
Ssh Login
|
104.238.132.126
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 8, 03:18:22
3 months ago
|
default-host
|
Ssh Login
|
64.176.212.158
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 8, 02:20:04
3 months ago
|
default-host
|
Ssh Login
|
104.238.132.126
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 8, 02:18:22
3 months ago
|
default-host
|
Ssh Login
|
64.176.212.158
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 8, 01:23:35
3 months ago
|
default-host
|
Ssh Login
|
104.238.132.126
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 8, 01:18:31
3 months ago
|
default-host
|
Ssh Login
|
64.176.212.158
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 7, 23:22:44
3 months ago
|
default-host
|
Ssh Login
|
64.176.212.158
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 7, 23:22:21
3 months ago
|
default-host
|
Ssh Login
|
104.238.132.126
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 7, 22:22:43
3 months ago
|
default-host
|
Ssh Login
|
64.176.212.158
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 7, 22:22:20
3 months ago
|
default-host
|
Ssh Login
|
104.238.132.126
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 7, 21:22:42
3 months ago
|
default-host
|
Ssh Login
|
64.176.212.158
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 7, 21:22:20
3 months ago
|
default-host
|
Ssh Login
|
104.238.132.126
|
N/A
|
N/A
|
No details
|
Warning
|
|
|
Dec 7, 20:42:11
3 months ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 7, 20:42:11
3 months ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
root
|
No details
|
Info
|
|
|
Dec 7, 20:42:11
3 months ago
|
default-host
|
Ssh Logout
|
140.82.46.49
|
N/A
|
session_1201
|
No details
|
Info
|
|
|
Dec 7, 20:39:38
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
sort -rn
|
Info
|
|
|
Dec 7, 20:39:38
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
pwd -P >| /tmp/claude-df5d-cwd
|
Info
|
|
|
Dec 7, 20:39:37
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
sort
|
Info
|
|
|
Dec 7, 20:39:37
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
uniq -c
|
Info
|
|
|
Dec 7, 20:39:36
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
jq -r .command 2> /dev/null
|
Info
|
|
|
Dec 7, 20:39:36
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
grep -v '^export '
|
Info
|
|
|
Dec 7, 20:39:36
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
grep -v '^shopt '
|
Critical
|
|
|
Dec 7, 20:39:35
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
grep '"event_type": "command"'
|
Info
|
|
|
Dec 7, 20:39:35
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
grep 66.135.25.80
|
Info
|
|
|
Dec 7, 20:39:34
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
eval "grep 2025-12-02T05 /var/log/grutu/collected_...
|
Critical
|
|
|
Dec 7, 20:39:34
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
grep 2025-12-02T05 /var/log/grutu/collected_logs.j...
|
Info
|
|
|
Dec 7, 20:39:33
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 7, 20:39:33
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTFILE="${HOME}/.bash_history_$(date +%Y%...
|
Critical
|
|
|
Dec 7, 20:39:32
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTSIZE=50000
|
Info
|
|
|
Dec 7, 20:39:32
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTFILESIZE=50000
|
Info
|
|
|
Dec 7, 20:39:32
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTCONTROL=""
|
Info
|
|
|
Dec 7, 20:39:31
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTCONTROL=
|
Info
|
|
|
Dec 7, 20:39:31
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
shopt -s histappend
|
Critical
|
|
|
Dec 7, 20:39:31
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTTIMEFORMAT="%Y-%m-%d %H:%M:%S "
|
Critical
|
|
|
Dec 7, 20:39:30
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTSIZE=10000
|
Info
|
|
|
Dec 7, 20:39:30
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
export HISTFILESIZE=10000
|
Info
|
|
|
Dec 7, 20:39:29
3 months ago
|
default-host
|
Command
|
140.82.46.49
|
209.6.216.95
|
root
|
true
|
Info
|
|