Forensics 17. Notifying owners of other machines

Here the intruders' own packet sniffer records them logging into a purloined account at another site:

 -- TCP/IP LOG -- TM: Sun Oct 31 07:05:40 --
 PATH: foo(13664) => bar(telnet)
 STAT: Sun Oct 31 07:06:11, 82 pkts, 129 bytes [DATA LIMIT]
 DATA: (255)(253)^C(255)(251)^X(255)(251)^_(255)(251) (255)
     : VT100(255)(240)(255)(250)'
     : (255)(240)(255)(253)^A(255)(252)^Atotalnet
     : 49$a1K
     : cd /var/preserve/totalnet
     : chmod 770 rsh
     : ./rsh

WHOIS should list postal, phone and email contact details for each network connected to the Internet. Be aware that the intruder may be reading everyone's mail!