PSPY


A root cronjob process was discovered

┌──(kali㉿kali)-[~/archive/htb/labs/editorial]
└─$ scp /home/kali/Tools/pspy/pspy64 dev@$IP:/dev/shm/pspy64
dev@10.10.11.20's password: dev080217_devAPI!@
pspy64                           100% 3032KB   2.1MB/s   00:01    

Delivery complete

dev@editorial:/dev/shm$ ./pspy64 
pspy - version: v1.2.1 - Commit SHA: f9e6a1590a4312b9faa093d8dc84e19567977a6d
 
 
     ██▓███    ██████  ██▓███ ▓██   ██▓
    ▓██░  ██▒▒██ ▓██░  ██▒▒██  ██▒
    ▓██░ ██▓▒░ ▓██▄   ▓██░ ██▓▒ ▒██ ██░
    ▒██▄█▓▒   ██▒▒██▄█▓▒ ▐██▓░
    ▒██▒  ░▒██████▒▒▒██▒ ██▒▓░
    ▒▓▒░  ░▒ ▒▓▒ ░▒▓▒░  ██▒▒▒ 
    ░▒ ░▒ ░░▒     ▓██ ░▒░ 
    ░░  ░░ ░░  
     
     
 
Config: Printing events (colored=true): processes=true | file-system-events=false ||| Scanning for processes every 100ms and on inotify events ||| Watching directories: [/usr /tmp /etc /home /var /opt] (recursive) | [] (non-recursive)
Draining file system events due to startup...
done

Executing PSPY

One of the root cronjob is executing a script; /opt/internal_apps/environment_scripts/clear.sh It clears the file upload directory, /opt/apps/app_editorial/static/uploads/