dslreports logo
site
 
    All Forums Hot Topics Gallery
spc

spacer




how-to block ads


Search Topic:
uniqs
76
share rss forum feed


anarchoi2

@distributel.net
reply to HELLFIRE

Re: intruder in my network

I uploaded the file here:
»www.2shared.com/file/xJjERHDA/CDKEYZIP.html

Microsoft Windows [version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. Tous droits réservés.

C:\Users\Anarchoi>nbtstat -S

ANARCHOI:
Adresse IP du noeud : [192.168.2.2] ID d'étendue : []

Aucune connexion

Hamachi:
Adresse IP du noeud : [25.162.23.89] ID d'étendue : []

Aucune connexion

C:\Users\Anarchoi>



NetFixer
From my cold dead hands
Premium
join:2004-06-24
The Boro
Reviews:
·Cingular Wireless
·Comcast Business..
·Vonage
·Comcast

1 recommendation

A .pbk file is just a text file, not an executable, so it is unlikely that anybody's malware scanner will tell you anything. The "pbk" file extension is an acronym for "phonebook", and the file contains text parameter entries used by Windows for making dialup and VPN connections.

FWIW, here is the relevant information for the "Ukraine" entries in the file you uploaded:

[EUROIP L2TP Ukraine]
Encoding=1
Type=2
AutoLogon=0
UseRasCredentials=1
LowDateTime=-1331370144
HighDateTime=29944263
DialParamsUID=172546
Guid=7106BE987679AF4B8258EFCCADA692A5
BaseProtocol=1
VpnStrategy=3
ExcludedProtocols=2
LcpExtensions=1
DataEncryption=8
SwCompression=1
NegotiateMultilinkAlways=1
SkipNwcWarning=0
SkipDownLevelDialog=0
SkipDoubleDialDialog=0
DialMode=1
OverridePref=15
RedialAttempts=99
RedialSeconds=30
IdleDisconnectSeconds=0
RedialOnLinkFailure=0
CallbackMode=0
CustomDialDll=
CustomDialFunc=
CustomRasDialDll=
ForceSecureCompartment=0
DisableIKENameEkuCheck=0
AuthenticateServer=0
ShareMsFilePrint=1
BindMsNetClient=1
SharedPhoneNumbers=0
GlobalDeviceSettings=0
PrerequisiteEntry=
PrerequisitePbk=
PreferredPort=VPN2-0
PreferredDevice=WAN Miniport (L2TP)
PreferredBps=0
PreferredHwFlow=1
PreferredProtocol=1
PreferredCompression=1
PreferredSpeaker=1
PreferredMdmProtocol=0
PreviewUserPw=1
PreviewDomain=0
PreviewPhoneNumber=0
ShowDialingProgress=1
ShowMonitorIconInTaskBar=1
CustomAuthKey=-1
AuthRestrictions=544
TypicalAuth=2
IpPrioritizeRemote=1
IpInterfaceMetric=0
fCachedDnsSuffix=0
IpHeaderCompression=0
IpAddress=0.0.0.0
IpDnsAddress=0.0.0.0
IpDns2Address=0.0.0.0
IpWinsAddress=0.0.0.0
IpWins2Address=0.0.0.0
IpAssign=1
IpNameAssign=1
IpDnsFlags=0
IpNBTFlags=1
TcpWindowSize=0
UseFlags=0
IpSecFlags=0
IpDnsSuffix=
IpCachedDnsSuffix=
Ipv6PrioritizeRemote=1
Ipv6InterfaceMetric=0
Ipv6NameAssign=1
Ipv6DnsAddress=::
Ipv6Dns2Address=::
Ipv6InterfaceId=0000000000000000
 
NETCOMPONENTS=
ms_server=1
ms_msclient=1
ms_psched=1
ms_nwsapagent=1
ms_nwclient=1
ms_pacer=1
cfosspeed=1
odysseyim4=1
vmware_bridge=1
 
MEDIA=rastapi
Port=VPN0-0
Device=WAN-miniport (L2TP)
 
DEVICE=vpn
PhoneNumber=ttu.15.usaip.eu
AreaCode=
CountryCode=98
CountryID=98
UseDialingRules=0
Comment=
LastSelectedPhone=0
PromoteAlternates=0
TryNextAlternateOnFail=1
 
[EUROIP PPTP Ukraine]
Encoding=1
Type=2
AutoLogon=0
UseRasCredentials=1
LowDateTime=-1542958000
HighDateTime=29944249
DialParamsUID=172546
Guid=7106BE987679AF4B8258EFCCADA692A5
BaseProtocol=1
VpnStrategy=1
ExcludedProtocols=2
LcpExtensions=1
DataEncryption=8
SwCompression=1
NegotiateMultilinkAlways=1
SkipNwcWarning=0
SkipDownLevelDialog=0
SkipDoubleDialDialog=0
DialMode=1
OverridePref=15
RedialAttempts=99
RedialSeconds=30
IdleDisconnectSeconds=0
RedialOnLinkFailure=0
CallbackMode=0
CustomDialDll=
CustomDialFunc=
CustomRasDialDll=
ForceSecureCompartment=0
DisableIKENameEkuCheck=0
AuthenticateServer=0
ShareMsFilePrint=1
BindMsNetClient=1
SharedPhoneNumbers=0
GlobalDeviceSettings=0
PrerequisiteEntry=
PrerequisitePbk=
PreferredPort=VPN2-0
PreferredDevice=WAN Miniport (L2TP)
PreferredBps=0
PreferredHwFlow=1
PreferredProtocol=1
PreferredCompression=1
PreferredSpeaker=1
PreferredMdmProtocol=0
PreviewUserPw=1
PreviewDomain=0
PreviewPhoneNumber=0
ShowDialingProgress=1
ShowMonitorIconInTaskBar=1
CustomAuthKey=-1
AuthRestrictions=544
TypicalAuth=2
IpPrioritizeRemote=1
IpInterfaceMetric=0
fCachedDnsSuffix=0
IpHeaderCompression=0
IpAddress=0.0.0.0
IpDnsAddress=0.0.0.0
IpDns2Address=0.0.0.0
IpWinsAddress=0.0.0.0
IpWins2Address=0.0.0.0
IpAssign=1
IpNameAssign=1
IpDnsFlags=0
IpNBTFlags=1
TcpWindowSize=0
UseFlags=0
IpSecFlags=1
IpDnsSuffix=
IpCachedDnsSuffix=
Ipv6PrioritizeRemote=1
Ipv6InterfaceMetric=0
Ipv6NameAssign=1
Ipv6DnsAddress=::
Ipv6Dns2Address=::
Ipv6InterfaceId=0000000000000000
 
NETCOMPONENTS=
ms_server=1
ms_msclient=1
ms_psched=1
ms_nwsapagent=1
ms_nwclient=1
ms_pacer=1
cfosspeed=1
odysseyim4=1
vmware_bridge=1
 
MEDIA=rastapi
Port=VPN0-0
Device=WAN-miniport (L2TP)
 
DEVICE=vpn
PhoneNumber=ttu.15.usaip.eu
AreaCode=
CountryCode=98
CountryID=98
UseDialingRules=0
Comment=
LastSelectedPhone=0
PromoteAlternates=0
TryNextAlternateOnFail=1
 
[EUROIP SSTP Ukraine]
Encoding=1
PBVersion=1
Type=2
AutoLogon=0
UseRasCredentials=1
LowDateTime=463995664
HighDateTime=30143741
DialParamsUID=172546
Guid=7106BE987679AF4B8258EFCCADA692A5
VpnStrategy=5
ExcludedProtocols=2
LcpExtensions=1
DataEncryption=8
SwCompression=1
NegotiateMultilinkAlways=1
SkipDoubleDialDialog=0
DialMode=1
OverridePref=15
RedialAttempts=99
RedialSeconds=30
IdleDisconnectSeconds=0
RedialOnLinkFailure=0
CallbackMode=0
CustomDialDll=
CustomDialFunc=
CustomRasDialDll=
ForceSecureCompartment=0
DisableIKENameEkuCheck=0
AuthenticateServer=0
ShareMsFilePrint=1
BindMsNetClient=1
SharedPhoneNumbers=0
GlobalDeviceSettings=0
PrerequisiteEntry=
PrerequisitePbk=
PreferredPort=VPN0-0
PreferredDevice=WAN Miniport (SSTP)
PreferredBps=0
PreferredHwFlow=1
PreferredProtocol=1
PreferredCompression=1
PreferredSpeaker=1
PreferredMdmProtocol=0
PreviewUserPw=1
PreviewDomain=0
PreviewPhoneNumber=0
ShowDialingProgress=1
ShowMonitorIconInTaskBar=1
CustomAuthKey=0
AuthRestrictions=544
IpPrioritizeRemote=1
IpInterfaceMetric=0
IpHeaderCompression=0
IpAddress=0.0.0.0
IpDnsAddress=0.0.0.0
IpDns2Address=0.0.0.0
IpWinsAddress=0.0.0.0
IpWins2Address=0.0.0.0
IpAssign=1
IpNameAssign=1
IpDnsFlags=0
IpNBTFlags=1
TcpWindowSize=0
UseFlags=0
IpSecFlags=0
IpDnsSuffix=
Ipv6Assign=1
Ipv6Address=::
Ipv6PrefixLength=0
Ipv6PrioritizeRemote=1
Ipv6InterfaceMetric=0
Ipv6NameAssign=1
Ipv6DnsAddress=::
Ipv6Dns2Address=::
Ipv6Prefix=0000000000000000
Ipv6InterfaceId=0000000000000000
DisableClassBasedDefaultRoute=0
DisableMobility=0
NetworkOutageTime=0
ProvisionType=0
PreSharedKey=
 
NETCOMPONENTS=
ms_server=1
ms_msclient=1
ms_psched=1
ms_nwsapagent=1
ms_nwclient=1
ms_pacer=1
cfosspeed=1
odysseyim4=1
vmware_bridge=1
 
MEDIA=rastapi
Port=VPN0-0
Device=WAN Miniport (SSTP)
 
DEVICE=vpn
PhoneNumber=vpn15.usaip.eu
AreaCode=
CountryCode=98
CountryID=98
UseDialingRules=0
Comment=
FriendlyName=
LastSelectedPhone=0
PromoteAlternates=0
TryNextAlternateOnFail=1
 

There is no way of knowing if you were hacked while attached to that VPN server, or if what you have is something that came packaged with some game you downloaded. However, the safest thing to do would be to nuke the effected PCs from orbit, change all passwords to everything you use that uses a password, and carefully check your bank and credit card accounts for at least several months. DBAN is the ultimate malware removal tool.

--
We can never have enough of nature.
We need to witness our own limits transgressed, and some life pasturing freely where we never wander.


Lagz
Premium
join:2000-09-03
The Rock

1 recommendation

reply to anarchoi2

Hamachi is a VPN. So you didn't entirely delete all the VPN software



NetFixer
From my cold dead hands
Premium
join:2004-06-24
The Boro
Reviews:
·Cingular Wireless
·Comcast Business..
·Vonage
·Comcast

2 edits

1 recommendation

said by Lagz:

Hamachi is a VPN. So you didn't entirely delete all the VPN software

And the owner of the IP address used by that Himachi connection is somewhat interesting:


% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf
% Note: this output has been filtered.
%       To receive output for a database update, use the "-B" flag.
% Information related to '25.0.0.0 - 25.255.255.255'
inetnum:        25.0.0.0 - 25.255.255.255
netname:        UK-MOD-19850128
descr:          DINSA, Ministry of Defence
country:        GB
org:            ORG-DMoD1-RIPE
admin-c:        MN1891-RIPE
tech-c:         MN1891-RIPE
status:         ALLOCATED PA
mnt-by:         RIPE-NCC-HM-MNT
mnt-lower:      UK-MOD-MNT
mnt-domains:    UK-MOD-MNT
mnt-routes:     UK-MOD-MNT
source:         RIPE # Filtered
organisation:   ORG-DMoD1-RIPE
org-name:       DINSA, Ministry of Defence
org-type:       LIR
address:        Not Published
                Not Published Not Published
                United Kingdom
phone:          +44 (0)30 677 00816
admin-c:        MN1891-RIPE
mnt-ref:        UK-MOD-MNT
mnt-ref:        RIPE-NCC-HM-MNT
mnt-by:         RIPE-NCC-HM-MNT
source:         RIPE # Filtered
person:         Mathew Newton
address:        C4 Architecture
address:        UK Ministry of Defence
phone:          +44 (0)30 677 00816
abuse-mailbox:  hostmaster@mod.uk
nic-hdl:        MN1891-RIPE
source:         RIPE # Filtered
mnt-by:         UK-MOD-MNT
% Information related to '25.0.0.0/8AS5378'
route:          25.0.0.0/8
descr:          INS-MOD-NET
descr:          INSnet core/customer route
descr:          Address Space owned by MOD
descr:          see whois.arin.net
member-of:      RS-AS5378
origin:         AS5378
mnt-by:         AS5378-MNT
source:         RIPE # Filtered
% This query was served by the RIPE Database Query Service version 1.47.5 (WHOIS1)
 



My assumption was that connection was probably "work related", but...

EDIT:
OK, the Himachi/UK MoD mystery is solved:

»b.logme.in/2012/11/07/changes-to···er-19th/

The first change concerns the use of the 5.x.x.x address space. As you may or may not be aware, this address space has been allocated by IANA to RIPE NCC two years ago. RIPE NCC has been handing out these addresses to their customers, and having Hamachi active on your computer means that you’re not able to access a growing portion of the Internet. We’ve added IPv6 support to Hamachi a while back, and you can simply turn off the use of the 5/8 space, but we realize that IPv4 is still very important to most of you. Therefore we’ll be changing every Hamachi node’s address to the 25/8 space...

Why 25/8? Well, it rhymes a bit with 5/8, and furthermore, it’s a block that’s been allocated to a foreign government agency for private use for almost two decades. We have no Hamachi users from this address space, and it’s highly unlikely that the general public would need to access one of these IP addresses. However, our general recommendation is that if you can, please turn off IPv4 support in your Hamachi clients. The IPv6 space we’re using has been registered to LogMeIn, and most modern software should function perfectly without needing an IPv4 address.

So, it seems that LogMeIn/Himachi has simply hijacked the UK MoD's IPv4 address space. I can't believe that the UK MoD has not already nuked them.

OTOH, the phrase "plausible deniability" does come to mind, so maybe the UK MoD isn't really too upset about LogMeIn/Himachi spoofing their IP addresses.
--
We can never have enough of nature.
We need to witness our own limits transgressed, and some life pasturing freely where we never wander.


Lagz
Premium
join:2000-09-03
The Rock

2 recommendations

The 5.x.x.x address block was reserved at one time. The 5.x.x.x block was used by Hamachi to avoid collisions with private IP networks that might be in use on the client side. Hamachi was wrong to hijack the range, but if IANA has it reserved, then one might as well utilize it. I hope IANA doesn't decide to simply allocate the 10.x.x.x range at some point in the future.
--
When somebody tells you nothing is impossible, ask him to dribble a football.