What would you guess the going rate on the black market would be for an RCE on some error-log collection box that happens to be in use by Facebook? My guess is "less than $5000".
The only code they executed was "sleep(100)" If they started dumping env variables/snooping around they would have done a lot more than $5000 worth of damage.