The attacker gained root access to the host at 209.165.200.235 from 209.165.201.17. By reviewing logs in Sguil and Wireshark, it was determined that the attacker copied the file "confidential.txt" from 209.165.200.235 to 192.168.0.11 using FTP with credentials of "analyst" and password "cyberops". The file contained confidential information about a security breach. It is recommended that the analyst password be changed on all systems to prevent further unauthorized access.