<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.pandasoftware.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Panda Software</title><link>http://blogs.pandasoftware.com/blogs/default.aspx</link><description>PandaLabs Blog- Up-to-the-minute information about viruses, spyware, spam</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 (Build: 60809.935)</generator><item><title>Greetings from Vienna</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/09/19/Greetings-from-Vienna.aspx</link><pubDate>Wed, 19 Sep 2007 12:10:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:249</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>0</slash:comments><description>&lt;P class=MsoNormal&gt;&lt;o:p&gt;Virus Bulletin 2007 is taking&amp;nbsp;place this week, at the Hilton Vienna Hotel. This event, which starts today and ends on Friday, offers a wide range of interesting conferences about typical issues in the security area, such as crimeware, spam, phishing and all kind of malware and antimalware techniques. The program can ve viewed &lt;A href="http://www.virusbtn.com/conference/vb2007/programme/index" target=blank&gt;here&lt;/A&gt;.&lt;/o:p&gt;&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=249" width="1" height="1"&gt;</description></item><item><title>PandaLabs Quarterly Report</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/08/31/PandaLabs-Quarterly-Report.aspx</link><pubDate>Fri, 31 Aug 2007 08:44:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:247</guid><dc:creator>Sergio Piñeiro</dc:creator><slash:comments>0</slash:comments><description>&lt;P&gt;Today we have published our Quarterly Report. The new Panda&amp;nbsp;required a new look,&amp;nbsp;so we have done our best to improve these reports. All the team hopes that you like them. Your comments are welcomed.&lt;/P&gt;
&lt;P&gt;Inside the report you can find plenty of information regarding what has happened in the last 3 months, Relevant issues, trends,&amp;nbsp;&amp;nbsp;and very interesting articles.&lt;/P&gt;
&lt;P&gt;Have you ever wondered how much does it cost to hire a Denial of Service&amp;nbsp;attack? Find it inside.&lt;/P&gt;
&lt;P&gt;Here you can find a link to the complete report. Enjoy it!&amp;nbsp;&lt;A href="http://www.pandasecurity.com/homeusers/downloads/register?Tipo=5&amp;amp;CodigoProducto=99&amp;amp;Idioma=2&amp;amp;TipoUsuario=11&amp;amp;Country=US&amp;amp;TipoLead=2&amp;amp;Ref=WW-EN-T2PLABS07"&gt;English&lt;/A&gt;&amp;nbsp;&lt;A href="http://www.pandasecurity.com/spain/homeusers/downloads/register?Tipo=5&amp;amp;CodigoProducto=99&amp;amp;Idioma=1&amp;amp;TipoUsuario=11&amp;amp;Country=ES&amp;amp;TipoLead=2&amp;amp;Ref=WW-ES-T2PLABS07"&gt;Spanish&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=247" width="1" height="1"&gt;</description></item><item><title>Has your credit card been stolen?</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/08/21/Has-your-credit-card-been-stolen_3F00_.aspx</link><pubDate>Tue, 21 Aug 2007 06:51:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:245</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>1</slash:comments><description>&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;In the last three months we have seen some activity regarding a bot C&amp;amp;C Server named Apophis. Here you can see a few screenshots:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;- Login:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/21/login.jpg"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;- Statistics:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Configuration:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/21/statistics.jpg" target=blank&gt;&lt;IMG style="WIDTH:319px;HEIGHT:110px;" height=109 src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/21/statistics.jpg" width=852&gt;&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&amp;nbsp;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/21/configurer.jpg" target=blank&gt;&lt;IMG style="WIDTH:243px;HEIGHT:171px;" height=190 src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/21/configurer.jpg" width=459&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;- Settings:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Templates:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/21/settings.jpg" target=blank&gt;&lt;IMG style="WIDTH:239px;HEIGHT:205px;" height=541 src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/21/settings.jpg" width=433&gt;&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/21/templates.jpg" target=blank&gt;&lt;IMG style="WIDTH:240px;HEIGHT:203px;" height=213 src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/21/templates.jpg" width=339&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;- And a few more:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/21/routine.jpg" target=blank&gt;&lt;IMG style="WIDTH:236px;HEIGHT:182px;" height=490 src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/21/routine.jpg" width=379&gt;&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/21/ip2location.jpg" target=blank&gt;&lt;IMG style="WIDTH:252px;HEIGHT:183px;" height=422 src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/21/ip2location.jpg" width=524&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;Today we have gained access to a new Apophis C&amp;amp;C Server. Looking at the files stored in the Server, we have found an encrypted file that seemed to have valuable information. We have decrypted it, it is an excel file that has information about 1,435 people. It includes: &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;- Full name&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;- Address (Street, City, State, Zip, Country)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;- Phone&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;- E-mail&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;- CC number&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;- cvv&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;- CC exp. date&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;- Bank info&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;This is the number of affected users per country:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;
&lt;TABLE class=MsoNormalTable style="MARGIN:auto 4.8pt;WIDTH:94pt;BORDER-COLLAPSE:collapse;mso-table-lspace:7.05pt;mso-table-rspace:7.05pt;mso-table-anchor-vertical:paragraph;mso-table-anchor-horizontal:page;mso-table-left:135.55pt;mso-table-top:4.95pt;mso-padding-alt:0cm 3.5pt 0cm 3.5pt;" cellSpacing=0 cellPadding=0 align=left&gt;

&lt;TR style="HEIGHT:12pt;mso-yfti-irow:0;mso-yfti-firstrow:yes;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:windowtext 1pt solid;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-alt:solid windowtext 1.0pt;mso-border-right-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Users&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:windowtext 1pt solid;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;B&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Country&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:1;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;994&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;USA&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:2;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;64&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Italy&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:3;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;53&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Netherlands&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:4;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;48&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Israel&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:5;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;47&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Belgium&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:6;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;43&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Sweden&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:7;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;38&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Norway&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:8;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;32&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;United Kingdom&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:9;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;21&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Canada&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:10;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;15&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Spain&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:11;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;14&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Grecia&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:12;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;14&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Switzerland&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:13;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;13&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;France&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:14;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;12&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Germany&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:15;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;7&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Austria&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:16;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;5&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;China&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:17;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;3&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Bulgaria&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:18;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;3&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Croacia&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:19;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;3&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Polland&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:20;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;1&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Estonia&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:21;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;1&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Iceland&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:22;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;1&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Latvia&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:23;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;1&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Lithuania&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:24;mso-height-source:userset;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;1&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Russia&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="HEIGHT:12pt;mso-yfti-irow:25;mso-height-source:userset;mso-yfti-lastrow:yes;"&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:windowtext 1pt solid;WIDTH:30pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;mso-border-right-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext 1.0pt;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:right;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;" align=right&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;1&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-RIGHT:windowtext 1pt solid;PADDING-RIGHT:3.5pt;BORDER-TOP:#ece9d8;PADDING-LEFT:3.5pt;PADDING-BOTTOM:0cm;BORDER-LEFT:#ece9d8;WIDTH:64pt;PADDING-TOP:0cm;BORDER-BOTTOM:windowtext 1pt solid;HEIGHT:12pt;BACKGROUND-COLOR:transparent;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-element:frame;mso-element-frame-hspace:7.05pt;mso-element-wrap:around;mso-element-anchor-vertical:paragraph;mso-element-anchor-horizontal:page;mso-element-left:135.6pt;mso-element-top:4.95pt;mso-height-rule:exactly;"&gt;&lt;SPAN style="FONT-SIZE:8pt;COLOR:black;FONT-FAMILY:Arial;"&gt;Ukraine&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TABLE&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;SPAN style="mso-tab-count:1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face="Times New Roman" size=3&gt;It has all the information in all fields but the phone and e-mail addresses, these ones are stored for 994 users. All of them are from 3 countries: USA, UK and Canada. Scary. We are contacting the different banks in order to avoid major problems for the users.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face="Times New Roman" size=3&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face="Times New Roman" size=3&gt;Thanks to Vicente for all the research.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=245" width="1" height="1"&gt;</description></item><item><title>Easy money: affiliate programs</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/08/14/Easy-money_3A00_-affiliate-programs.aspx</link><pubDate>Tue, 14 Aug 2007 11:29:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:243</guid><dc:creator>Vicente Martinez</dc:creator><slash:comments>0</slash:comments><description>&lt;P&gt;Today we’re going to describe one of the ways the cybercriminals use to earn some easy money. There are many marketing companies that promote web traffic to different Web pages, software installations, etc. They use what they call&amp;nbsp; 'affiliate programs', paying money for every software installed or traffic generated. This web traffic is very assorted: activex, rogue-antispywares, bundles, banners, fakecodecs, iframes, etc.&lt;/P&gt;
&lt;P&gt;They usually pay depending on the country you obtain the download. Normally USA&amp;nbsp; and Europe are the best paid countries and other countries as China or Russia are the worst paid.&lt;/P&gt;
&lt;P&gt;Here we can see some examples obtained from these pages:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT:0px;"&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;&lt;EM&gt;We will pay you for installs coming from 16 countries as exposed here :&lt;BR&gt;$0.40 for USA, Canada &lt;BR&gt;$0.20 for United Kingdom, France, Germany, Italy, Spain, Belgium, Luxembourg, Monaco&lt;BR&gt;$0.05 for Austria, Denmark, Finland, Sweden, Norway, The Netherlands&lt;BR&gt;$0.01 for China, Korea, Japan&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Although some of these marketing enterprises can be well-intentioned, other have been specifically created by &amp;amp; for cybercriminals to earn money. Here we can see a gif file that was being used by one of these companies in order to advertise itself in an underground malware forum:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/14/iframecash.gif"&gt;&lt;/P&gt;
&lt;P&gt;A short time ago, analyzing&amp;nbsp; a &lt;A href="http://research.pandasoftware.com/blogs/research/archive/2007/03/29/eCrime-2007-Congress.aspx"&gt;Trj/Sinowal&lt;/A&gt; variant (a banking Trojan) to discover where it was sending the information to, we found one of these websites. We found out that this site had 4 different kits to install malware through exploits in the same server the page was hosted in:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/14/iframe911.jpg"&gt;&lt;/P&gt;
&lt;P&gt;There was an &lt;A href="http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/07/26/Ice_2800_Pack_2900_-for-the-summer.aspx"&gt;IcePack&lt;/A&gt;, a Traffic Pro, a Prime Exploit System, and a very basic kit that only used two exploits and had no name. These kits were downloading two Trojans: Trj/Galapoper and Trj/Sinowal. This is not the first time we see something similar. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The web sites where they promote themselves use to be very eye-catching, here you can see some examples: &lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/14/fantasticdollars.jpg" target=blank&gt;&lt;IMG style="WIDTH:616px;HEIGHT:572px;" height=700 src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/14/fantasticdollars.jpg" width=608&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/14/iframebiz.jpg" target=blank&gt;&lt;IMG style="WIDTH:603px;HEIGHT:460px;" height=636 src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/14/iframebiz.jpg" width=874&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/14/loadscc.jpg" target=blank&gt;&lt;IMG style="WIDTH:521px;HEIGHT:556px;" height=716 src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/08/14/loadscc.jpg" width=645&gt;&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=243" width="1" height="1"&gt;</description></item><item><title>JavaScript de-obfuscation with Rhino</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/08/06/JavaScript-de_2D00_obfuscation-with-Rhino.aspx</link><pubDate>Mon, 06 Aug 2007 07:00:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:241</guid><dc:creator>Ismael Briones</dc:creator><slash:comments>1</slash:comments><description>&lt;P&gt;&lt;FONT face="Courier New"&gt;Last Friday,&amp;nbsp;I received a URL which used several exploits to spread malware. As always,&amp;nbsp;I started to investigate it. As you may know, these sites&amp;nbsp;use javascript to exploit web browser, ActiveX or third party vulnerabilities, and of course JS obfuscation is used most of the time.&lt;/FONT&gt;&lt;/P&gt;&lt;FONT face="Courier New"&gt;&lt;/FONT&gt;&lt;FONT face="Courier New"&gt;&lt;/FONT&gt;
&lt;P&gt;&lt;FONT face="Courier New"&gt;I don't like using web browsers to de-obfuscate these codes, basically because these js are dangerous and&amp;nbsp;I want to avoid an&amp;nbsp;infection. I know that some &lt;A href="http://isc.sans.org/diary.html?storyid=3219"&gt;researchers&lt;/A&gt; use debugging techniques to de-obfuscate these js codes, but&amp;nbsp;I really think there are safer, faster and&amp;nbsp;more automated methods to do the same job.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Courier New"&gt;I prefer to use &lt;A href="http://www.mozilla.org/rhino/"&gt;Rhino&lt;/A&gt; to accomplish these tasks. &lt;B&gt;Rhino&lt;/B&gt; is "&lt;B&gt;&lt;I&gt;an open-source implementation of JavaScript written entirely in Java&lt;/I&gt;&lt;/B&gt;". With this js engine and a Linux system I'm able to de-obfuscate these codes, without using any web browser. &lt;/FONT&gt;&lt;FONT face="Courier New"&gt;&lt;/FONT&gt;&lt;FONT face="Courier New"&gt;I recommend you the CanWest presentation &lt;A href="http://cansecwest.com/slides07/csw07-nazario.pdf"&gt;Reverse Engineering Malicious Javascript&lt;/A&gt; (&lt;/FONT&gt;Jose Nazario, Ph. D. &lt;I&gt;Arbor)&lt;/I&gt;&lt;FONT face="Courier New"&gt;.&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Courier New"&gt;I'm going to show the process with an example (the same js code&amp;nbsp;I received on Friday). &lt;BR&gt;This is a special case, because it uses a trick to avoid the modification of the code: &lt;/FONT&gt;&lt;FONT face="Courier New"&gt;&lt;B&gt;&lt;I&gt;arguments.callee.toString()&lt;/I&gt;&lt;/B&gt; (This call returns the code of the funcion where it's called). Any modification of the code will affect the final result and therefore avoid an automated de-obfuscation of the code.&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Courier New"&gt;The js code has two functions: &lt;B&gt;&lt;I&gt;bodipyri(ii)&lt;/I&gt;&lt;/B&gt; and &lt;I&gt;&lt;B&gt;cynolapy(a1,b1)&lt;/B&gt;&lt;/I&gt;. The Function's names are dinamically generated every time the page is loaded. Analyzing the second function,&amp;nbsp;I saw there was a return with an eval call:&lt;BR&gt;&lt;BR&gt;&lt;I&gt;function cynolapy(a1,b1)&lt;BR&gt;{&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if(!b1){&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; return eval(bodipyri("ZG9jdW1lbnQud3JpdGUoY[DELETED]2csIiIpKSk7")); }&lt;/I&gt;&lt;BR&gt;&lt;BR&gt;[DELETED]&lt;BR&gt;}&lt;BR&gt;This function is first called only with an argument:&lt;BR&gt;&lt;BR&gt;&lt;I&gt;cynolapy('YSYsMTs5IHAkOGlvIid7ZDZ9IGo5cD4[DELETED]VrY2SVSXZnKzJakIk=');&lt;/I&gt;&lt;BR&gt;&lt;BR&gt;so the function &lt;/FONT&gt;&lt;FONT face="Courier New"&gt;&lt;I&gt;cynolapy&lt;/I&gt;&lt;/FONT&gt;&lt;FONT face="Courier New"&gt; returns the eval result.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Courier New"&gt;&lt;/FONT&gt;&lt;FONT face="Courier New"&gt;&lt;BR&gt;I deleted all the html code, changed the&amp;nbsp;eval call with a print, and executed rhino against the file. This was the result:&lt;BR&gt;&lt;BR&gt;&lt;I&gt;document.write(cynolapy(a1,arguments.callee.toString().replace(/\s/g,"")));&lt;/I&gt;&lt;BR&gt;&lt;BR&gt;The js code is recursively calling the same function but with a second argument. This new argument is the known &lt;/FONT&gt;&lt;FONT face="Courier New"&gt;&lt;B&gt;&lt;I&gt;arguments.callee.toString()&lt;/I&gt;&lt;/B&gt; trick used to avoid code modifications. Since&amp;nbsp;I had modified eval with print, I was&amp;nbsp;modifing the value of the second parameter and therefore changing the final result. That's bad and avoided an automated de-obfuscation of the code. This example has to be manually de-obfuscated. &lt;BR&gt;The &lt;B&gt;&lt;I&gt;arguments.callee.toString().replace(/\s/g,"")) &lt;/I&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;FONT face="Courier New"&gt;function returns the &lt;I&gt;cynolapy&lt;/I&gt; funct&lt;/FONT&gt;&lt;FONT face="Courier New"&gt;ion source code and then strips all white spaces.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="Courier New"&gt;&lt;BR&gt;Therefore, in order to&amp;nbsp;to get the real js code we have to call this function with this second argument. I got the original js code again (with the eval call), and added the following code at the end of the file:&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;FONT face="Courier New"&gt;&lt;I&gt;print cynolapy&lt;/I&gt;&lt;/FONT&gt;&lt;FONT face="Courier New"&gt;('YSYsMTs5IHAkNGlhIj97aDZ9[DELETED]24viw==','functiontumawyzu(a1,b1){if(!b1){returneval(cynolapy("ZG9[DELETED]returno;}');&lt;BR&gt;&lt;BR&gt;What I'm doing here is calling cynolapy function with the expected second parameter. After parsing this code with Rhino this is the resulting code:&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;DIV align=left&gt;&lt;FONT face="Courier New"&gt;&amp;lt;script&amp;gt;var ifr='&amp;lt;iframe width=2 height=2 style=display:none';var t='other';[DELETE](ifr+' src=http://[DELETED]/?u=0068&amp;amp;t='+t+'&amp;gt;&amp;lt;/iframe&amp;gt;');&amp;lt;/script&amp;gt;&lt;/FONT&gt;&lt;BR&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;FONT face="Courier New"&gt;&lt;BR&gt;This de-obfuscated code is loading an iframe with a new site. This site is used to exploit several vulnerabilities: ANI/ANR, Java/ByteVerify, ADODB.Stream,...&lt;BR&gt;&lt;BR&gt;PandaLabs is developing an automated engine to de-obfuscate js, but sometimes it's not possible and we need to do it manually.&lt;/FONT&gt;&lt;FONT face="Courier New"&gt;&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=241" width="1" height="1"&gt;</description></item><item><title>July spyware list</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/08/01/July-spyware-list.aspx</link><pubDate>Wed, 01 Aug 2007 11:50:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:239</guid><dc:creator>Vicente Martinez</dc:creator><slash:comments>1</slash:comments><description>&lt;P&gt;This month, the first positions of the list are very similar to last month’s.&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT:0px;"&gt;
&lt;P&gt;1.- Application/MyWebSearch&lt;/P&gt;
&lt;P&gt;2.- Adware/Lop&lt;/P&gt;
&lt;P&gt;3.- Adware/Gator&lt;/P&gt;
&lt;P&gt;4.- Adware/ActiveSearch&lt;/P&gt;
&lt;P&gt;5.- Spyware/Virtumonde&lt;/P&gt;
&lt;P&gt;6.- Adware/Savenow&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Adware/VideoActiveXObject goes up from the 10th to 7th position.&lt;/P&gt;
&lt;P&gt;It is the most active version of the known fakecodecs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Application/RealSpy goes up from the 17th to the 13th position.&lt;/P&gt;
&lt;P&gt;It is a commercial keylogger that logs the keystrokes typed by the user, monitors the websites visited, captures screenshots and records conversations of instant messaging programs such as MSN, ICQ, AOL and Yahoo.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Trj/Lineage.BZE goes up from the 34th to the 24th position. &lt;/P&gt;
&lt;P&gt;It is a Trojan that steals passwords from the MORPG Lineage.&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=239" width="1" height="1"&gt;</description></item><item><title>Ice(Pack) for the summer</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/07/26/Ice_2800_Pack_2900_-for-the-summer.aspx</link><pubDate>Thu, 26 Jul 2007 12:01:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:236</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>0</slash:comments><description>&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;It's summer, about 29ºC - 84ºF&amp;nbsp;in Bilbao, a sunny and beautiful day. Good time for an ice-cream. But today we'll change the menu and we'll have an IcePack instead. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/26/IcePack1.JPG"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;IcePack Platinum is the name of a new "Kit for installing malware through exploits". Regarding the exploits it uses, nothing new can be added, it is very similar to &lt;A href="http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/05/11/MPack-uncovered_2100_.aspx" target=blank&gt;Mpack&lt;/A&gt;, which takes advantage of the last exploits that have appeared. This way, they have more chances to infect the users that are not patched with the last updates:&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;- MS06-014 Internet Explorer 6 - MS06-006 Firefox 1.5 &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;- MS06-006 Opera 7 &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;- WVF Overflow&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;- QuickTime Overflow&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;- WinZip Overflow&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;- VML Overflow&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&amp;nbsp;&amp;nbsp;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/26/IcePack2.JPG" target=blank&gt;&lt;IMG style="WIDTH:447px;HEIGHT:280px;" height=461 src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/26/IcePack2.JPG" width=845&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/18/parser2.JPG" target=blank&gt;&lt;/A&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;Here you have an image of the ftp checker:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/26/IcePack3.JPG" target=blank&gt;&lt;IMG style="WIDTH:457px;HEIGHT:205px;" height=230 src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/26/IcePack3.JPG" width=781&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;IcePack is programmed by other group (IDT Group) different from Mpack creators (Dream Coders Team) . The price of this tool is also lower than the Mpack and can be purchased for $400 .&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=236" width="1" height="1"&gt;</description></item><item><title>XRumer</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/07/24/XRumer.aspx</link><pubDate>Tue, 24 Jul 2007 06:26:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:234</guid><dc:creator>Vicente Martinez</dc:creator><slash:comments>3</slash:comments><description>&lt;P&gt;As we commented in &lt;A href="http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/01/24/PHP-forums-can-also-host-malware-.aspx" target=blank&gt;Spam in PHP forums&lt;/A&gt;&amp;nbsp;and in &lt;A href="http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/02/02/Spam-in-PHP-forums-_2800_II_2900_.aspx" target=blank&gt;Spam in PHP forums (II)&lt;/A&gt;, it has become more and more usual to see websites (forums, blogs, wikis, guestbooks, etc...) that contain advertising comments or links that direct to sites that infect with malware.&lt;/P&gt;
&lt;P&gt;We are going to talk about a program that allows this type of comments to be created: the XRumer.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/24/xrumer1.JPG"&gt;&lt;/P&gt;
&lt;P&gt;It is sold for $450, and for $50 more you can have the Hrefer, which includes more functions.&lt;/P&gt;
&lt;P&gt;This application, with regard to the web section, is more powerful than &lt;A href="http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/05/08/Zunker.aspx" target=blank&gt;Zunker&lt;/A&gt;,&amp;nbsp;as&amp;nbsp;this&amp;nbsp;is only able to post in phpBB and VBulleting.&lt;/P&gt;
&lt;P&gt;Xrumer allows to post in phpBB and PHP-Nuke (with any modification), yaBB, VBulletin, Invision Power Board, IconBoard, UltimateBB, exBB, and phorum.org.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Basically, it follows the process below: &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; It looks for websites where comments can be inserted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; It registers itself as a user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; It posts the message.&lt;/P&gt;
&lt;P&gt;This type of websites usually include human verification codes, in order to make automatic registration more difficult for this kind of robots or they use filters in order to block IP addresses that carry out suspicious operations.&lt;/P&gt;
&lt;P&gt;That’s why, this program is able to recognize the texts in the following type of images: &lt;/P&gt;
&lt;P&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/24/xrumer2.JPG"&gt;&lt;/P&gt;
&lt;P&gt;It also allows to connect to a list of proxies&amp;nbsp;in order to use different IP addresses.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/24/xrumer.swf" target=blank&gt;Here&lt;/A&gt; you have a video where the working of the program is shown.&lt;/P&gt;
&lt;P&gt;According to the comments of its creators, it is able to post 1100 links in only 15 minutes.&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=234" width="1" height="1"&gt;</description></item><item><title>More about Mpack (II)</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/07/20/More-about-Mpack-II.aspx</link><pubDate>Fri, 20 Jul 2007 06:35:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:228</guid><dc:creator>Vicente Martinez</dc:creator><slash:comments>0</slash:comments><description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Today I have come across a server hosting an Mpack that has 292 different websites with iframes that make reference to it.&lt;BR&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/20/Mpack.JPG" target=blank&gt;&lt;IMG style="WIDTH:579px;HEIGHT:299px;" height=447 src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/20/Mpack.JPG" width=799&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Most of the infected users are Italian, as in the case we explained a month ago. You can check the information by following this link: &lt;A href="http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/06/19/More-about-Mpack.aspx"&gt;http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/06/19/More-about-Mpack.aspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;But, the most curious thing is that after analyzing the range of the IP addresses, we have seen that the websites are hosted in the same Italian provider as in the other case.&lt;/P&gt;
&lt;P&gt;The version of this Mpack is 0.91. However, the latest version we have found is 0.94.&lt;BR&gt;&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=228" width="1" height="1"&gt;</description></item><item><title>PINCH, THE TROJAN CREATOR</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/07/18/PINCH_2C00_-THE-TROJAN-CREATOR.aspx</link><pubDate>Wed, 18 Jul 2007 08:41:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:227</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>1</slash:comments><description>&lt;P&gt;Some time ago, we talked to you about malware prices, HTTP botnets, etc. Today I will show you the level Trojan creators have reached and the way in which some of them launch their creation ‘builders’, authentic centers for designing and creating totally customizable Trojans. And this is where Pinch comes in.&lt;/P&gt;
&lt;P&gt;It is a tool for creating Trojans which allows: defining the actions for the Trojan to take, packing the executable file to make its detection more difficult, disabling specific ‘annoying’ services such as those of antiviruses…&lt;/P&gt;
&lt;P&gt;Among the tools for creating viruses, Trojans, etc. this might be the most commonly used, distributed and sold, given its ease of use due to a very intuitive interface. This allows malicious attackers to have an executable ready to infect, steal, spread, etc. in a few minutes. Consequently, it causes victims serious problems without them even realizing, until it is too late and they have to face the financial consequences.&lt;/P&gt;
&lt;P&gt;First, attackers must choose the ‘return’ mode of the data the Trojan obtains. More specifically, whether the data should be sent via SMTP, HTTP or simply be left on a system file to recover it later through a backdoor opened on the victim’s computer by the Trojan.&lt;/P&gt;
&lt;P&gt;If SMTP is chosen, the following parameters must be specified:&lt;BR&gt;+ SMTP server and port to use.&lt;BR&gt;+ ‘From’ and ‘To’ fields of email to send.&lt;BR&gt;+ Subject&lt;BR&gt;+ Interval between data sending&lt;/P&gt;
&lt;P&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/18/PinchSMTP.JPG"&gt;&lt;/P&gt;
&lt;P&gt;If HTTP is chosen, the name of the server with mail3.php must be specified. Mail3.php loads the information onto the server.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/18/PinchHTTP.JPG"&gt;&lt;/P&gt;
&lt;P&gt;If the FILE method is chosen, the name of the file created with the information and its path must be specified. &lt;/P&gt;
&lt;P&gt;There are several tabs in the middle of the screen where the parameters below can be specified:&lt;/P&gt;
&lt;P&gt;PWD: The type of password to be stolen can be indicated: from mail programs to passwords stored on browsers, including system information. The report can also be encrypted.&lt;/P&gt;
&lt;P&gt;RUN: The way the Trojan will run on the target computer, the location it will be copied to (if necessary), its name, etc. are indicated.&lt;BR&gt;&amp;nbsp;If Autorun is selected, there are several options to choose from:&lt;/P&gt;
&lt;P&gt;+ Standard: It copies the executable file onto the selected directory and includes it in the registry to carry out the autorun.&lt;BR&gt;+ DLL RUN: It copies the Trojan to the directory, creates a .dll and includes a reference in the Windows Registry for it to run automatically.&lt;BR&gt;+ UNDELETE: It compiles the Trojan and changes it to different formats (exe, dll), it compiles a .dll again with one of the conversions, etc.&lt;BR&gt;+ SERVICE: It copies the Trojan to the directory, and creates a reference in the Windows Registry so it runs automatically. The name of the service can be specified.&lt;/P&gt;
&lt;P&gt;It can also be set to act on a specific date and time, delete itself, and run when it detects a network connection or after a reboot. It can also be compiled to change the firewall settings in Windows and allow the Trojan to act.&lt;/P&gt;
&lt;P&gt;SPY: The following parameters are specified in this section: lets Trojans act as keyloggers, takes screenshots of the victim’s desktop, captures IE data, looks for certain files on the target system, etc.&lt;/P&gt;
&lt;P&gt;NET: Allows the victim’s PC to be turned into a Proxy, specifying ports, etc. It also acts as a downloader; by specifying the address of the executable file, victims download the .exe file and run it. The last option allows connecting to a php script, allowing parameter specification, etc.&lt;/P&gt;
&lt;P&gt;BD: Or backdoor. Allows ports to be specified and logs to be opened on victims’ computers.&lt;/P&gt;
&lt;P&gt;ETC: Allows the Trojan to be hidden using typical joiner methods.&lt;/P&gt;
&lt;P&gt;KILL: It allows the selected services or processes to be killed. It allows most antivirus services to be selected by default.&lt;/P&gt;
&lt;P&gt;IE: Allows attackers to add sites to the IE Trusted Sites and the favorites section.&lt;/P&gt;
&lt;P&gt;WORM: Allows worm characteristics to be determined for the Trojan so it distributes itself.&lt;/P&gt;
&lt;P&gt;IRC-BOT: Allows victims’ computers to be added to an IRC bot network, specifying the server, channel, port and password.&lt;/P&gt;
&lt;P&gt;It also allows the Trojan to be encrypted using RC4, packing it using FSG, UPX or MEW.&lt;/P&gt;
&lt;P&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/18/Pinchfilebck.JPG"&gt;&amp;nbsp; &lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/18/PinchFileKill.JPG"&gt;&lt;/P&gt;
&lt;P&gt;Once all the Trojan’s characteristics are specified, it must be compiled to obtain the .exe file. &lt;/P&gt;
&lt;P&gt;The version I have used for this post is version 2.60 since the builder in this version is very complete. Later versions are available, but they are disabled builders which do not allow all the Trojan’s characteristics to be specified from a single builder. The author has ‘diversified’ them, has created a specific builder for SMTP, and has removed several options which are now included in the final Trojan by default. Bearing in mind builder prices, this process to make their ‘creations’ more profitable is not surprising. Here you have a screenshot of the latest version:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/18/Pinch3.JPG"&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The parser: The pinch is accompanied by a parser program which is capable of reading and decrypting the logs left by the Trojan. The parser lets you search the logs and truth be said, it is easy to use and allows easy visualization of different log data obtained by the Trojan:&lt;/P&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/18/parser2.JPG" target=blank&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/18/parsersmall.JPG"&gt;&lt;/A&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=227" width="1" height="1"&gt;</description></item><item><title>A new case of RansomWare !!!</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/07/17/A-new-case-of-RansomWare-_210021002100_.aspx</link><pubDate>Tue, 17 Jul 2007 06:45:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:224</guid><dc:creator>Vicente Martinez</dc:creator><slash:comments>1</slash:comments><description>&lt;P&gt;We have detected a new case of RansomWare.&lt;/P&gt;
&lt;P&gt;Once the malware infects users and encrypts their files, several “read_me.txt” files are created in the infected system, which warn users that their data files have been encrypted and that they won’t be able to access them unless they pay a ransom of $300.&lt;/P&gt;
&lt;P align=center&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/17/Sinowal1.JPG"&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;The email addresses indicated in the message may vary:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT:0px;"&gt;
&lt;P&gt;&lt;A href="mailto:kiloglamour@gmail.com"&gt;kiloglamour@gmail.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="mailto:tristanniglam@gmail.com"&gt;tristanniglam@gmail.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="mailto:oxyglamour@gmail.com"&gt;oxyglamour@gmail.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="mailto:glamourepalace@gmail.com"&gt;glamourepalace@gmail.com&lt;/A&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;The “personal code” may also vary depending on the random value that is used to encrypt the data.&lt;/P&gt;
&lt;P&gt;The encrypted files usually begin with the text “GLAMOUR”:&lt;/P&gt;
&lt;P align=center&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/17/Sinowal2.JPG"&gt;&lt;/P&gt;
&lt;P&gt;We have managed to access the data of the infected systems and there are 1,108 infected computers. &lt;/P&gt;
&lt;P&gt;Besides, in 111 of those machines the port 6838 is open so that the machines act as socket servers.&lt;/P&gt;
&lt;P&gt;The “construction kit” of Trj/Sinowal has been used to create this Trojan.&lt;/P&gt;
&lt;P&gt;We have already mentioned this malware family in the eCrime 2007&lt;/P&gt;
&lt;P&gt;&lt;A href="http://research.pandasoftware.com/blogs/research/archive/2007/03/29/eCrime-2007-Congress.aspx"&gt;http://research.pandasoftware.com/blogs/research/archive/2007/03/29/eCrime-2007-Congress.aspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;According to SecureWorks, this “construction kit” is sold for around $1,000.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.computerworlduk.com/management/security/cybercrime/news/index.cfm?RSS&amp;amp;NewsId=3740"&gt;http://www.computerworlduk.com/management/security/cybercrime/news/index.cfm?RSS&amp;amp;NewsId=3740&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This variant has been detected as Trj/Sinowal.FY in the signature file. &lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=224" width="1" height="1"&gt;</description></item><item><title>Spammers: PDF rules!</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/07/11/Spammers_3A00_-PDF-rules_2100_.aspx</link><pubDate>Wed, 11 Jul 2007 12:18:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:222</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>0</slash:comments><description>&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;FONT face=Verdana&gt;A few weeks ago a spam attack &lt;A href="http://antivirus.about.com/b/a/257884.htm" target=blank&gt;was launched&lt;/A&gt; – as it happens everyday. But that time there was something new. It was a pump and dump stock scam, using a PDF attachment. And what’s more, the PDF looked in a very professional way, so many people could be fooled. You can download the PDF clicking on the image below:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;o:p&gt;&lt;FONT face=Verdana&gt;&lt;/FONT&gt;&lt;/o:p&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;o:p&gt;&lt;FONT face=Verdana&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/11/all_report.pdf" target=blank&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/11/germanspampdf.PNG"&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face=Verdana&gt;It must have been successful somehow, as the number of&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;these PDF scams are increasing a lot. We must say that most of them are made in a really poor way, just take a look at the following screenshots:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;o:p&gt;&lt;FONT face=Verdana&gt;&lt;/FONT&gt;&lt;/o:p&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;o:p&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/11/poorpdfspambig.PNG" target=blank&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/11/poorpdfspamsmall.PNG"&gt;&lt;/A&gt;&amp;nbsp;&amp;nbsp; &lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/11/poorpdfspambig2.PNG" target=blank&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/11/poorpdfspamsmall2.PNG"&gt;&lt;/A&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;o:p&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/11/poorpdfspambig3.PNG" target=blank&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/11/poorpdfspamsmall3.PNG"&gt;&lt;/A&gt;&amp;nbsp;&amp;nbsp; &lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/11/poorpdfspambig4.PNG" target=blank&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/11/poorpdfspamsmall4.PNG"&gt;&lt;/A&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face=Verdana&gt;But you can find some which look better:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;o:p&gt;&lt;FONT face=Verdana&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;o:p&gt;&lt;FONT face=Verdana&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/11/spampdfbig5.PNG" target=blank&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/11/spampdfsmall5.PNG"&gt;&lt;/A&gt;&amp;nbsp;&amp;nbsp; &lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/11/spampdfbig1.PNG" target=blank&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/11/spampdfsmall1.PNG"&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;o:p&gt;&lt;FONT face=Verdana&gt;&lt;/FONT&gt;&lt;/o:p&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;o:p&gt;&lt;FONT face=Verdana&gt;&lt;/FONT&gt;&lt;/o:p&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face=Verdana&gt;As you can see most of the times they are just copy-pasting the body of the&amp;nbsp;"old" spam messages into the PDF file. But today, I have found one that has caught my eye. The first thing is the Subject (Off the record), which, on its own, makes anyone’s curiosity arouse. If the message is opened, there is a PDF attached, whose name is the name and surname of the user’s mail account! When it is opened, we discover that we will be given $500 if we reactivate an online casino account, finally it was not so exciting:&lt;/P&gt;&lt;/FONT&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;o:p&gt;&lt;FONT face=Verdana&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;"&gt;&lt;FONT face=Verdana&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/11/casinoscam.PNG"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;o:p&gt;&lt;FONT face=Verdana&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=222" width="1" height="1"&gt;</description></item><item><title>Guidded shopping</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/07/10/Guidded-shopping.aspx</link><pubDate>Tue, 10 Jul 2007 07:58:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:221</guid><dc:creator>pmontoya</dc:creator><slash:comments>1</slash:comments><description>&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;Last&amp;nbsp;week we have heard about an online shop that sells Iphones. This matter wouldn’t be unusual except for the fact that it is the classic case of phishing. Basically, you access the web thinking you are buying in an Apple’s official shop but, in fact, it’s not. No matter how many Iphones you purchase and pay, you won’t receive any.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;I’ve gone a little bit further in order to see how the swindle has been carried out and I’ve been really surprised by the discovery.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;They have plenty of resources in order to make you visit their website instead of the official one. We have never seen before a deployment in resources and organization like this.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;We’ve already known about the existence of banker Trojans that send all the information they obtain to a server. But in addition, they turn your computer into a bot that is completely controlled by a central server, from which each bot and the stolen information can be managed… Well, I have come across a variation of this framework, which is totally focused on the Iphone swindle.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;When a PC is infected by the Trojan, it automatically turns into a bot of the server in question. The first time you connect to the Internet, the Trojan will send several requests to the server, in order to receive some instructions that will be carried out by the Trojan in your computer.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;The server sends several data in such a way that when you visit certain websites, you are redirected to other ones without being aware. Up to the moment this can seem normal, but what surprises me most is that as well as being redirected, it is able to display popups and banners, and it can even modify the results offered by the most usual Internet search engines, such as Google, when certain searches are made.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;When an infected PC visits &lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;"&gt;&lt;A href="http://www.iphone.com/"&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;www.iphone.com&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt; &lt;SPAN&gt;in order to purchase an Iphone, the user will be actually buying it in their website instead of in the official one.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;As you can see, they are able to carry out all kind of operations from the control panel, in order to guide us to their Iphone online shop.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/10/Dibujo6.JPG" target=blank&gt;&lt;IMG style="WIDTH:206px;HEIGHT:114px;" height=735 src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/10/Dibujo6.jpg" width=570&gt;&lt;/A&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;Currently, this bot server controls 7519 bots, a number not to be sneezed at.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;From the section “COMMANDS ADMIN”, all kind of commands can be sent to the bots, from downloading new executables to restarting the PC.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/10/Dibujo2.JPG" target=blank&gt;&lt;IMG style="WIDTH:209px;HEIGHT:140px;" height=699 src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/10/Dibujo2.jpg" width=554&gt;&lt;/A&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;In “REDIRECTS ADMIN”, the redirection is specified. In order to do so, it is indicated the website the user thinks that they will be visiting and the website that they will be really visiting. As you can see, almost all the redirections belong to Apple websites. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/10/Dibujo3.JPG" target=blank&gt;&lt;IMG style="WIDTH:211px;HEIGHT:144px;" height=796 src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/10/Dibujo3.JPG" width=409&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;In “SEARCH REDIR”, it is indicated the URLs that will be displayed when the bot makes a search with an Internet search engine, and the words that triggers the redirecting as well. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;In “INJECTS ADMIN”, the “injects” are specified, that is, when a bot visits a URL that has been specified, the bot will inject code into the URL, in such a way that, for example, it can modify the links of the website. As you can see, all the injections make reference to Apple’s websites, and they inject code so that when a link of the website is followed, you will be redirected to their “online shop”.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/10/Dibujo4.JPG" target=blank&gt;&lt;IMG style="WIDTH:215px;HEIGHT:138px;" height=491 src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/10/Dibujo4.JPG" width=460&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;In “POPUPS ADMIN” and “BANNERS ADMIN”, the banners and popups that will be displayed in the bot browser are specified. They always make reference to their online shop of Iphones sale.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/10/Dibujo5.JPG" target=blank&gt;&lt;IMG style="WIDTH:212px;HEIGHT:63px;" height=258 src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/07/10/Dibujo5.JPG" width=212&gt;&lt;/A&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;We have never seen before a botnet that is specifically dedicated to “guide” its bots when their owners want to buy an Iphone. We can come to the conclusion that it is a very important business for them, above all for the determination with which they have developed it.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;It is interesting to see how the most used tools in the world of Trojans and botnets are being used in the world of phishing. This proves that thousands of computer crimes are being committed, and the worst thing of all is that many people all over the world have been victims of these swindles.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;This server is currently working and at the moment it is still sending commands to its bots so that the PCs are redirected to their illegal web.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="FONT-SIZE:10pt;FONT-FAMILY:Tahoma;mso-ansi-language:EN-GB;"&gt;The most interesting thing of all is that not only they can use this management device for one shop, but in a future they can also use it for other shops that offer brand-new and outstanding products, such as the case of the Apple’s Iphones. In fact, the shop is offline right now but I’m sure that they will use their Botnet&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;again with other “Online shops”.&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=221" width="1" height="1"&gt;</description></item><item><title>June spyware list</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/07/04/June-spyware-list.aspx</link><pubDate>Wed, 04 Jul 2007 12:06:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:219</guid><dc:creator>Vicente Martinez</dc:creator><slash:comments>1</slash:comments><description>&lt;P class=MsoNormal&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" align=justify&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;This month, Application/MyWebSearch joins the list in the first position, with only 36 detections less than Adware/Lop, which goes down to the second position.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" align=justify&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;" align=justify&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;1.- Application/MyWebSearch&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;" align=justify&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;2.- Adware/Lop&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;" align=justify&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;3.- Adware/Gator&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;" align=justify&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;4.- Dialer.XD&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;" align=justify&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;5.- Spyware/Virtumonde&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;" align=justify&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;6.- Application/SystemDoctor2006&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" align=justify&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" align=justify&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;Application/SystemDoctor2006 goes up from the 11th to the 6th position. It is a fake error-repairing program that is usually installed by Adware/SystemDoctor. There are also many websites or advertisements that simulate an analysis of the machine so that users install the program. Then, they are requested to purchase, for a modest price, a program to remove them.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" align=justify&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" align=justify&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;Adware/Navipromo goes up from the 21st to 19th position. It is an adware that promotes dialers and uses rootkit techniques in order to go unnoticed. It usually comes with other programs such as MailSkinner, WebMediaplayer&amp;nbsp; or InternetGameBox .&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" align=justify&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;" align=justify&gt;&lt;SPAN style="FONT-SIZE:10pt;COLOR:black;FONT-FAMILY:Tahoma;"&gt;Trj/Torpig, which is a banker Trojan, keeps the 37th position as in the previous month. The families belonging to Trj/Torpig and Trj/Sinowal are very similar. We explained the techniques used by Trj/Sinowal in the eCrime Congress. You can take a look at the paper &lt;A title=http://research.pandasoftware.com/blogs/research/archive/2007/03/29/eCrime-2007-Congress.aspx href="http://research.pandasoftware.com/blogs/research/archive/2007/03/29/eCrime-2007-Congress.aspx" target=_blank&gt;here&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=219" width="1" height="1"&gt;</description></item><item><title>NanoScan for Vista</title><link>http://blogs.pandasoftware.com/blogs/nanoscan/archive/2007/06/29/NanoScan-for-Vista.aspx</link><pubDate>Fri, 29 Jun 2007 11:56:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:214</guid><dc:creator>jmtapiola</dc:creator><slash:comments>0</slash:comments><description>&lt;p class="MsoNormal"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;Finally, we have published the final 
version of NanoScan compatible with Windows Vista. Although the new operating 
system has new security features, users with Vista installed also need a double check of the PC. 
&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;You don’t need to go to a special 
site neither change something at your computer: just come to &lt;a title="http://www.nanoscan.com/" href="http://www.nanoscan.com/"&gt;www.nanoscan.com&lt;/a&gt;, run the detection routine 
and that’s all, the application will recognise if you have Vista and runs exactly in the same way as if you have XP 
or any other operating system.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;Of course, it is also able to detect 
any active virus, spyware or other threat on your PC. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;font face="Arial" size="2"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;Cool! Isn’t it? There are not so 
many on-line antivirus compatible with Vista. 
So, enjoy it!!! &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=214" width="1" height="1"&gt;</description></item><item><title>A profitable use for stolen credit cards</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/06/27/How-to-use-stolen-credit-cards.aspx</link><pubDate>Wed, 27 Jun 2007 11:11:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:210</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>1</slash:comments><description>&lt;P&gt;We have often talked about the freedom with which certain cyber-crooks circulate around the Internet, but I must admit that even I am surprised sometimes… &lt;/P&gt;
&lt;P&gt;The theft of credit card details and trading of this information is the order of the day. How is this information being used? We could make assumptions, carry out research or try to infiltrate some of these groups, but…why bother if they talk about it all so openly on their websites?&lt;/P&gt;
&lt;P&gt;This is what appears on one of these websites:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/06/27/sale20.PNG"&gt;&lt;/P&gt;
&lt;P&gt;As usual, everything is in perfect Russian. Basically, they are selling laptops, PDAs, cell phones, etc. for 20% of their real value. How is this possible? Well, if you visit their section "Answers to frequently asked questions-F.A.Q.", the first question is: How can you offer such good prices? Pay attention to the answer:&lt;/P&gt;
&lt;P&gt;"&lt;EM&gt;It’s very simple. We buy these products in Western countries with stolen credit cards. You don’t run any risk when purchasing these products."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;It couldn’t be any clearer. They even have a section for partners, where you are given the code you must include on your website and you get 25% of the money that comes from your website.&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=210" width="1" height="1"&gt;</description></item><item><title>The first virus scan for personalized homepages</title><link>http://blogs.pandasoftware.com/blogs/nanoscan/archive/2007/06/22/The-first-virus-scan-for-personalized-homepages.aspx</link><pubDate>Fri, 22 Jun 2007 08:34:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:209</guid><dc:creator>admin</dc:creator><slash:comments>0</slash:comments><description>&lt;P&gt;Do you use personalized homepages as &lt;A href="http://www.netvibes.com/"&gt;&lt;FONT color=#08388e&gt;NetVibes&lt;/FONT&gt;&lt;/A&gt;, &lt;A href="http://www.google.com/ig"&gt;&lt;FONT color=#08388e&gt;iGoogle&lt;/FONT&gt;&lt;/A&gt; or &lt;A href="http://www.pageflakes.com/"&gt;&lt;FONT color=#08388e&gt;PageFlakes&lt;/FONT&gt;&lt;/A&gt;? If so, I think I have good news for you: from now on you'll be able to scan your PC for active viruses, spyware, Trojans, etc. right from your homepage. Yes, we've just launched the new NanoScan module for personalized homepages. You can add the module from your homepage's module directory. Once you added it you'll be able to NanoScan your PC as many times as you want without leaving your homepage.&lt;BR&gt;&lt;BR&gt;These are some of the pages that are offering the NanoScan module: &lt;A href="http://www.netvibes.com/"&gt;&lt;FONT color=#08388e&gt;NetVibes&lt;/FONT&gt;&lt;/A&gt;, &lt;A href="http://www.google.com/ig"&gt;&lt;FONT color=#08388e&gt;iGoogle&lt;/FONT&gt;&lt;/A&gt;, &lt;A href="http://www.pageflakes.com/"&gt;&lt;FONT color=#08388e&gt;PageFlakes&lt;/FONT&gt;&lt;/A&gt;, &lt;A href="http://www.protopage.com/"&gt;&lt;FONT color=#08388e&gt;ProtoPage&lt;/FONT&gt;&lt;/A&gt;, &lt;A href="http://www.widgipedia.com/"&gt;&lt;FONT color=#08388e&gt;Widgipedia&lt;/FONT&gt;&lt;/A&gt;... and more to come. &lt;BR&gt;&lt;BR&gt;Here's a screenshot from my desktop computer:&lt;BR&gt;&lt;BR&gt;&lt;A href="http://blogs.pandasoftware.com/photos/nanoscan/picture164.aspx" target=_blank&gt;&lt;/A&gt;&lt;IMG src="http://blogs.pandasoftware.com/photos/nanoscan/images/201/original.aspx" border=0&gt;&lt;BR&gt;&lt;BR&gt;&lt;I&gt;Note: as you can see in the screenshot NanoScan for Netvibes is really tiny (screen-wise). So, how do we call this new "Nano" NanoScan? :)&lt;/I&gt;&lt;BR&gt;&lt;BR&gt;Hope you like it!&lt;BR&gt;&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=209" width="1" height="1"&gt;</description></item><item><title>NanoScan now compatible with Firefox</title><link>http://blogs.pandasoftware.com/blogs/nanoscan/archive/2007/06/22/NanoScan-now-compatible-with-Firefox.aspx</link><pubDate>Fri, 22 Jun 2007 08:29:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:208</guid><dc:creator>admin</dc:creator><slash:comments>0</slash:comments><description>&lt;P&gt;Good news for Firefox users: NanoScan is now compatible with this excellent browser. &lt;/P&gt;
&lt;P&gt;&lt;FONT size=2&gt;To get the best results, we have opted to develop a plugin, and avoid Java, ActiveX controls and so on. This way, we have achieved complete compatibility and smooth operation of NanoScan with Firefox. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2&gt;By the way, Neil Rubenking, from the online magazine &lt;B&gt;AppScout&lt;/B&gt;&lt;/FONT&gt;&lt;FONT size=2&gt;, &lt;A href="http://www.appscout.com/2007/05/firefox_gets_nanoscan_support.php"&gt;&lt;FONT color=#08388e&gt;has already echoed this&lt;/FONT&gt;&lt;/A&gt; and seems happy with the new feature. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2&gt;Installing the plugin has been made as simple as possible. And, we have prepared a series of screens to guide you through the process. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2&gt;In any event, it is the same solution, capable of detecting almost 900,000 viruses (as of today, tomorrow it will be more), using our collective intelligence approach. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2&gt;If you are a Firefox user, we encourage you to try NanoScan. Also, if you have any comments, questions or problems, don't hesitate to contact us.&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=208" width="1" height="1"&gt;</description></item><item><title>Dream System</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/06/20/Dream-System_210021002100_.aspx</link><pubDate>Wed, 20 Jun 2007 15:04:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:196</guid><dc:creator>Vicente Martinez</dc:creator><slash:comments>1</slash:comments><description>&lt;P&gt;“Dream System” is a bot that allows hackers to use infected machines as socket servers and to run any type of files in them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It launches two types of DDOS attacks: &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP flood.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The bot consists of:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A server component, called “Dream Bot builder”, which contains the configuration interface and allows servers to be generated. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/06/19/DreamSystem.JPG"&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/2007/06/19/DreamSystem.JPG"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;And a client component, which allows the bot to be managed from a web interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The bot version 1.3 is sold for $750, including free updates for new versions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This bot is known as “Dream System” or “Dream sockets”. It seems too much coincidence that the name of the program is very similar to “Dream Downloader” of the &lt;A href="http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/05/11/MPack-uncovered_2100_.aspx"&gt;Mpack&lt;/A&gt;, which was programmed by DreamCoders Team. So, it is likely to be another software developed by this team.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is detected in the signature file as part of the Bck/DreamSocks family.&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=196" width="1" height="1"&gt;</description></item><item><title>MPack: how to infect thousands of websites</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/06/20/MPack-_13203E00_-Tools-to-_1820_infect_1920_-websites.aspx</link><pubDate>Wed, 20 Jun 2007 12:04:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:195</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>1</slash:comments><description>&lt;P&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;We've been&amp;nbsp;wondering for a few months now how&amp;nbsp;malware mafias&amp;nbsp;can&amp;nbsp;hack so many web sites automatically to be&amp;nbsp;exploited by MPack. Yesterday a few theories came to light, such as hinting that all the hacked servers all belong to the same virtual hosting server or the use of a ‘IFRAME Manager tool’. We're familiar with this tool since about 4 months. It's real name is ‘&lt;/SPAN&gt;&lt;I style="mso-bidi-font-style:normal;"&gt;&lt;SPAN style="mso-ansi-language:EN-GB;mso-bidi-font-weight:bold;mso-bidi-font-size:36.0pt;"&gt;FTP-Toolz pack&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;’ and it is being sold for $25.&amp;nbsp;Here you can see a capture from a Russian forum where it was advertised for sale:&lt;/SPAN&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/06/20/ftptoolzbig.PNG" target=blank&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/06/20/ftptoolzsmall.PNG"&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;And the tool itself:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/06/20/ftptoolz1big.PNG" target=blank&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/06/20/ftptoolz1small.PNG"&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/06/20/ftptoolz2big.PNG" target=blank&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/06/20/ftptoolz2small.PNG"&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;When we found MPack at the end of last year we also found also a similar tool named ‘&lt;EM&gt;&lt;STRONG&gt;RooT [iFrame]&lt;/STRONG&gt;&lt;/EM&gt;’ in one of the hacked servers. &lt;SPAN style="mso-ansi-language:EN-GB;"&gt;There is a funny thing about this one; if you buy it through the Russian version of the hacker’s website, it is just $25. In case you go to the English version of this hacker’s site, the price doubles, it’s $50. Finally we found yet another one named &lt;/SPAN&gt;&lt;A name=_Toc163451837&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;&lt;EM&gt;&lt;STRONG&gt;FTPCheckIframe&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;, this time only in Russian and for&amp;nbsp;$25.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;&lt;/SPAN&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;A href="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/06/20/rootiframebig.PNG" target=blank&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/06/20/rootiframesmall.PNG"&gt;&lt;/A&gt;&lt;/P&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;Even though we are still wondering how they gain access to those servers, it seems that they make use of tools such as the ones mentioned and feed them a list of usernames and passwords, probably stolen by the same Trojans and keyloggers they have previously gathered or purchased. But… how to work with all that mess? I mean, they can have hundreds of thousands of ftp addresses with usernames and passwords, but they don’t know which ones are working, which ones have write access, etc. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;"&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;Then we&amp;nbsp;run into yet&amp;nbsp;another tool, this time a &lt;STRONG&gt;&lt;EM&gt;PHP script that &lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;&lt;STRONG&gt;&lt;EM&gt;validates ftp accounts&lt;/EM&gt;&lt;/STRONG&gt;. The hacker loads the stolen account lists in a file called &lt;I style="mso-bidi-font-style:normal;"&gt;acc.txt&lt;/I&gt;, and by means of the script (ftp_check.php) he gets dumped the valid ones into a file called &lt;I style="mso-bidi-font-style:normal;"&gt;valid.txt&lt;/I&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;mso-layout-grid-align:none;"&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN:0cm 0cm 0pt;TEXT-ALIGN:justify;mso-layout-grid-align:none;"&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;So he can use that information with any of the previous programs: &lt;/SPAN&gt;&lt;SPAN style="mso-ansi-language:EN-GB;mso-bidi-font-weight:bold;mso-bidi-font-size:36.0pt;"&gt;FTP-Toolz pack&lt;/SPAN&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;, &lt;/SPAN&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt;RooT [iFrame] or&lt;/SPAN&gt;&lt;SPAN style="mso-ansi-language:EN-GB;"&gt; FTPCheckIframe and automatically infect hundreds of thousands of web pages with the MPack IFRAME.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=195" width="1" height="1"&gt;</description></item><item><title>More about Mpack</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/06/19/More-about-Mpack.aspx</link><pubDate>Tue, 19 Jun 2007 14:16:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:190</guid><dc:creator>Vicente Martinez</dc:creator><slash:comments>0</slash:comments><description>&lt;P&gt;In the last hours, many things have been said about the &lt;A href="http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/05/11/MPack-uncovered_2100_.aspx"&gt;MPack &lt;/A&gt;massive infection with more than 10.000 affected websites. For more information, visit the Websense site &lt;A href="http://www.websense.com/securitylabs/alerts/alert.php?AlertID=782"&gt;http://www.websense.com/securitylabs/alerts/alert.php?AlertID=782&lt;/A&gt;&amp;nbsp;.&lt;/P&gt;
&lt;P&gt;Although the data is astonishing, we are not very much surprised, as we carried out a small study about MPack, and in 2 months (April &amp;amp; May 2007) we discovered 41 different servers, and the statistics were frightening: more than 1 million users infected (1217741), and the iframe code was present in 366717 web pages.&lt;/P&gt;
&lt;P&gt;We don’t think that those 366717 websites had been hacked and infected manually one by one.&lt;/P&gt;
&lt;P&gt;Although we haven’t already found it, it seems that they are provided with a program that looks for vulnerable web servers, where it accesses the main file that loads the web page and adds an iframe reference to Mpack, so that the users who visit these websites are infected too.&lt;/P&gt;
&lt;P&gt;The version 0.90 of Mpack has recently come out. Among the last changes of this version, there are the following:&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The capability to infect only in certain countries. &lt;/P&gt;
&lt;P&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The stats.php has been replaced by the admin.php. Now not only a password is required but also a username. As a result, it is much safer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/06/19/admin.JPG"&gt;&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Update in the encryption module. This way, the exploits it uses are more difficult to detect. &lt;/P&gt;
&lt;P&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; And several small changes in the interface, bugs correction, etc.&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Its price has increased from $700 to $1000.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/06/19/Mpack.jpg"&gt;&lt;/P&gt;
&lt;P&gt;Up to the moment, we have located 4 active servers with this new version.&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=190" width="1" height="1"&gt;</description></item><item><title>Botnet controller via web</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/06/13/Botnet-controller-via-web.aspx</link><pubDate>Wed, 13 Jun 2007 09:00:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:183</guid><dc:creator>Vicente Martinez</dc:creator><slash:comments>1</slash:comments><description>&lt;P&gt;Today, when I was tracking the server to which a variant of Trj/LdPinch sends information, I have come across, among the files in the server, some .php files that are used to control a botnet via web.&lt;/P&gt;
&lt;P&gt;The image below would be the initial screen from which the infected systems can be viewed for geographical area:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs//2007/06/13/Botnet.JPG"&gt;&lt;/P&gt;
&lt;P&gt;And the option “Botnet controller” allows different actions to be carried out in the affected systems:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs//2007/06/13/Botnet2.JPG"&gt;&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=183" width="1" height="1"&gt;</description></item><item><title>Critical Bugs Discovered In Yahoo Messenger and Microsoft GDI+</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/06/08/Critical-Bugs-Discovered-In-Yahoo-Messenger-and-a-DoS-in-Microsoft-GDI_2B00_.aspx</link><pubDate>Fri, 08 Jun 2007 08:05:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:181</guid><dc:creator>Ismael Briones</dc:creator><slash:comments>0</slash:comments><description>Three new vulnerabilites have been make publicly this week. Two for Yahoo Messenger Webcam ActiveX and one for Microsoft GDI+&lt;BR&gt;&lt;BR&gt;&lt;B&gt;Yahoo! Messenger Webcam Upload ActiveX Control Buffer Overflow &lt;BR&gt;&lt;BR&gt;&lt;/B&gt;Security company eEye Digital Security has discovered two vulnerabilities for Yahoo's instant messenger client software that were reported to Yahoo. The bugs are critical because allow remote [code] execution. Yahoo gave them its highest security threat rating.&lt;BR&gt;The vulnerable control is part of the code for Webcam image upload and viewing (ywcupl.dll). Yahoo is working in a patch, nevertheless two publicly available exploits have been submited to Bugtraq and Full-Disclousre mailing lists. We think it willl be actively exploited by malware in a few days.&lt;BR&gt;The PoC's are inoffensive (execution of calc.exe) but it would be very easy to add&amp;nbsp; a more dangerous shellcodes.&lt;BR&gt;Yahoo! Messenger version 8.1.0.249, incorporating ywcupl.dll version 2.0.1.4&amp;nbsp;is vulnerable. This vulnerability is currently unpatched.&lt;BR&gt;&lt;BR&gt;&lt;B&gt;Microsoft GDI+ Integer division by zero flaw handling .ICO files&lt;BR&gt;&lt;/B&gt;&lt;BR&gt;CSIS Security group has found an "integer division by zero" flaw in GDI+ when parsing .ICO files. The vulnerability doesn't allow remote code execution but it allow to crash Windows Explorer and other components like "Windows Picture and Fax Viewer". The flaw was reported to Microsof and MSRC confirmed the vulnerability. It will be fixed in next Service Pack. The full advisory can be downloaded&amp;nbsp; at the following link: &lt;A href="http://www.csis.dk/dk/forside/GdiPlus.pdf"&gt;http://www.csis.dk/dk/forside/GdiPlus.pdf&lt;/A&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=181" width="1" height="1"&gt;</description></item><item><title>May spyware list</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/06/01/May-spyware-list.aspx</link><pubDate>Fri, 01 Jun 2007 11:38:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:180</guid><dc:creator>Vicente Martinez</dc:creator><slash:comments>0</slash:comments><description>&lt;P&gt;This month there have been changes in the first two positions. Adware/Lop occupies the first position and 47 detections below, the seconds position is occupied by Application/MyWebSearch. Meanwhile, Adware/Gator goes down to the third position of the ranking.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;1: Adware/Lop &lt;BR&gt;2: Application/MyWebSearch&lt;BR&gt;3: Adware/Gator&lt;BR&gt;4: Application/Winantivirus2006&lt;BR&gt;5: Spyware/Virtumonde&lt;BR&gt;6: Adware/SaveNow&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Adware/SpyLocked goes up from the 23rd to 17th position. This adware promotes the rogue antipysware called SpyLocked and is mainly distributed by the fakecodecs.&lt;/P&gt;
&lt;P&gt;Trj/Abwiz.A is in the 34th position, which is a Trojan that registers itself as a BHO and steals passwords from the computer. &lt;/P&gt;
&lt;P&gt;Exploit/LoadImage joins the ranking in the 44th position. It is a generic detection of an exploit we had already &lt;A href="http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/03/30/A-new-ANI-vulnerability-in-the-wild.aspx"&gt;mentioned&lt;/A&gt; that affects ANI files. Moreover, this exploit is one of the most used by&amp;nbsp;kits for installing malware using exploits, such as &lt;A href="http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/05/11/MPack-uncovered_2100_.aspx"&gt;Mpack&lt;/A&gt;.&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=180" width="1" height="1"&gt;</description></item><item><title>The Cimuz uninstaller</title><link>http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/05/30/The-Cimuz-uninstaller.aspx</link><pubDate>Wed, 30 May 2007 13:50:00 GMT</pubDate><guid isPermaLink="false">c957b16f-3e8b-473d-be13-e5160fbfb1ee:178</guid><dc:creator>Vicente Martinez</dc:creator><slash:comments>0</slash:comments><description>&lt;P&gt;Checking a server that installs a variant of Trj/Cimuz, I came across a link that pointed to remover.exe file:&lt;BR&gt;&amp;nbsp;&lt;IMG src="http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/05/30/Remover.JPG"&gt;&lt;/P&gt;
&lt;P&gt;After analyzing the code of the file, I noticed that it uninstalled the same variant of Trj/Cimuz that had been previously installed from that very same server.&lt;/P&gt;
&lt;P&gt;I suppose this is the way&amp;nbsp;the author&amp;nbsp;uses to make tests in order to check if the Trojan works properly and then, get easily disinfected&amp;nbsp;using the uninstaller.&lt;BR&gt;&lt;/P&gt;&lt;img src="http://blogs.pandasoftware.com/aggbug.aspx?PostID=178" width="1" height="1"&gt;</description></item></channel></rss>