Skip to content
UPLINK
Zeta-9 Security Incident Report

Zeta-9 Security Incident Report

BTLO-Project-Z-2025November 2025ConfidentialClosed
Incident ID
BTLO-Project-Z-2025
Date of Report
November 14, 2025
Prepared By
Warawut Manosong (Chicken0248)
Classification
Confidential
Executive Summary

During a CRISIS engagement, Warawut Manosong (as Chicken0248 agent) was deployed to investigate multiple security incidents across Zeta-9's infrastructure. The investigation revealed a full compromise of four critical assets, including:

  • The FortiGate network firewall
  • Hybrid cloud infrastructure (AWS and Azure)
  • The JUMPHOST workstation
  • The workstation of a key researcher

The first malicious activity was observed on September 16, 2025, targeting the FortiGate firewall to gain unauthorized access to the internal network. Subsequent actions by the adversary included:

  1. Exploitation of the Surveillance Storage Console to obtain JUMPHOST administrator credentials.
  2. Lateral movement to the JUMPHOST and exfiltration of AWS credentials.
  3. Unauthorized access and exfiltration of objects from hybrid cloud storage.
  4. Defacement of public-facing web assets hosted in Azure.
  5. Compromise of the researcher's workstation via a FileFix attack, leading to exfiltration of sensitive data, including the CURE: the final antidote against the ongoing zombie outbreak scenario.

This engagement demonstrates the high impact of coordinated attacks across on-premises and cloud environments, highlighting risks to both critical research and corporate operations.

Business & Stakeholder Impact

1. Strategic Impact: Confidentiality Breach

  • Corporate secrets and credentials were exposed. The adversary extracted local administrator credentials from surveillance video footage, AWS secret values from parameter store, and sensitive datasets from both AWS S3 and Azure Blob storage.
  • High-value intellectual property and internal R&D data stored in cloud repositories were accessed. This includes files belonging to ZETA-9's "Secret Division," implying possible loss of proprietary research materials.
  • Brand trust compromised. The defacement of the public Azure Web App resulted in reputational damage, as stakeholders and clients may have observed tampered content displaying adversary-controlled messaging.

2. Operational Impact: Service Disruption & Persistence

  • The adversary established persistent remote control via a Sliver C2 implant embedded into Dr. Frankenstein Code's PowerShell profile. This persistence mechanism could have allowed long-term access, unauthorized script execution, and continuous monitoring of internal operations.
  • Automation and backup workflows on compromised cloud accounts may have been disrupted due to deleted or modified configurations during the exfiltration phase.
  • Forensic indicators show data tampering and secure deletion (SDelete), suggesting permanent loss of original evidence and potential data corruption in the affected division.

3. Financial & Compliance Impact

  • Potential Regulatory Exposure: The unauthorized access to personal and research data likely violates data protection obligations (GDPR/PDPA equivalents), exposing Zeta-9 to regulatory fines and reporting requirements.
  • Incident Response and Recovery Costs: Containment, forensic imaging, cloud credential rotation, and rebuilding of affected environments will incur significant cost and downtime.
  • Reputational and Market Impact: Investor confidence and partner relations may be affected due to public disclosure of the defacement and data leaks.
Timeline
Date/Time (UTC)EventSource
2025-09-16 00:10:08First event observed of the adversary connecting to the firewallFortiGate Syslog
2025-09-16 00:17:36The adversary exploited CVE-2024-55591FortiGate Syslog
2025-09-16 00:18:12The adversary connected to the VPN as zeta_adm userFortiGate Syslog
2025-09-16 00:19:37The adversary enumerated hosts within the network range 192.168.86.0/24FortiGate Syslog
2025-09-24 01:08:58The adversary discovered the Surveillance Storage ConsoleArkime
2025-09-24 01:16:50The adversary exploited a SQL injection vulnerability on the Surveillance Storage Console webpageArkime
2025-09-24 01:17:33The adversary downloaded a video containing the local administrator credential of JUMPHOSTArkime
2025-09-24 10:38:31The adversary performed lateral movement to JUMPHOST with a WMI-based technique using custom malware for AWS credential exfiltrationMemory dump
2025-09-25 16:06:00First event on AWS by the adversaryAWS CloudTrail
2025-09-25 16:15:00The adversary retrieved the secret value from zeta9/windows/admin-passwordAWS CloudTrail
2025-09-25 16:27:00The adversary retrieved AWS objects from S3 storageAWS CloudTrail
2025-09-25 16:38:07First event on Azure Storage Blob by the adversaryStorageBlobLogs
2025-09-25 16:41:12The adversary retrieved objects from Azure Blob storageStorageBlobLogs
2025-09-25 16:50:00Azure Web App defacementAppServiceHTTPLogs
2025-09-27 11:17:33Dr. Frankenstein Code visited the defaced website, resulting in a FileFix attack and initial access to ZETA9-SECRETDIVMicrosoft Edge History
2025-09-27 11:23:09The adversary created a PowerShell profile for Dr. Frankenstein CodeUSN Journal
2025-09-27 11:30:52The adversary cloned the Sliver C2 implant from MEGAUSN Journal, MEGA
2025-09-27 11:34:18The adversary moved the Sliver C2 implant to C:\Users\Public\RunTimeBroker.exeUSN Journal
2025-09-27 11:35:08The adversary added the Sliver C2 implant as persistence in the PowerShell profile of Dr. Frankenstein CodeUSN Journal
2025-09-27 15:49:58The adversary embedded the exfiltration zip file into an image file and deleted the original files from ZETA9-SECRETDIV with SDeleteUSN Journal, Prefetch
2025-09-28 02:20:47The adversary removed all entries from the TypedPaths registry key of Dr. Frankenstein Code's user profile to clear tracksNTUSER.DAT
Scope & Evidence

Affected Systems & Devices

Hostname/Device NameIP AddressesOSRole
ProjectZ-fw38.68.134.215FortiOSFirewall
10.0.14.53 / 18.133.31.160LinuxSurveillance Storage Console
JUMPBOX192.168.1.148 / 192.168.86.2WindowsJumphost
zeta9-research-portal.azurewebsites.netN/ALinuxAzure Web App
ZETA9-SECRETDIV192.168.45.128Windows 10 ProDr. Frankenstein Code's workstation

Affected Users

UsernameCompromised FromDetails
zeta-admFortiGate (ProjectZ-fw)CVE-2024-55591 and added user to VPN group
ghostFortiGate (ProjectZ-fw)CVE-2024-55591
operator39Surveillance Storage ConsoleLocal Administrator on JUMPBOX, credentials exfiltrated from storage console
VictorVenomJumpboxIAMUser, credentials exfiltrated from Jumpbox
Dr.FrankensteinCodeZETA9-SECRETDIVVictim of FileFix attack
Dr.HelenaZETA9-SECRETDIVUser on the same host as Dr.FrankensteinCode

Files Exfiltrated

File Name / File PathSource
cam06_ai_monitor_securityincident.mp4Arkime
reports/threat-analysis-September-2025.jsonAWS S3 Bucket (zombie-killer-antivirus)
infrastructure/cloudformation/database-stack.txtAWS S3 Bucket (zeta9-cloudaws-ops)
secrets/api-keys/third-party-integrations.datAWS S3 Bucket (zeta9-cloudaws-ops)
backups/database-backup-sept-24.tar.gzAWS S3 Bucket (zeta9-cloudaws-ops)
Subject-Zombie15-Experiment.pdfAWS S3 Bucket (zombietesting)
/zeta9researchdata/quantum-research-secrets/contracts/military-qc-2025.txtAzure Storage Blob
/zeta9researchdata/quantum-research-secrets/research/quantum-nexus-status.txtAzure Storage Blob
/zeta9researchdata/quantum-research-secrets/secretLAB/SecretLANConnection.txtAzure Storage Blob
/zeta9researchdata/quantum-research-secrets/secretLAB/SecretLabInfo.txtAzure Storage Blob
/zeta9researchdata/quantum-research-secrets/secretLAB/SecretNetworkVPN.txtAzure Storage Blob
/zeta9researchdata/quantum-research-secrets/secretLAB/AntiZombieSolution.txtAzure Storage Blob
C:\Users\Dr.FrankensteinCode\Desktop\confidential.pngExfiltrated image file
C:\Users\Dr.FrankensteinCode\Desktop\CURE.txtExfiltrated image file
C:\Users\Dr.FrankensteinCode\Desktop\gunman.pngExfiltrated image file
C:\Users\Dr.FrankensteinCode\Desktop\Helena.txtExfiltrated image file
C:\Users\Dr.FrankensteinCode\Desktop\test.txtExfiltrated image file
C:\Users\Dr.FrankensteinCode\Desktop\outbreak.pngExfiltrated image file

Important File Deletion

File Name / File PathSource
C:\Users\Dr.FrankensteinCode\Desktop\confidential.pngUSN Journal
C:\Users\Dr.FrankensteinCode\Desktop\CURE.txtUSN Journal
C:\Users\Dr.FrankensteinCode\Desktop\gunman.pngUSN Journal
C:\Users\Dr.FrankensteinCode\Desktop\Helena.txtUSN Journal
C:\Users\Dr.FrankensteinCode\Desktop\test.txtUSN Journal
C:\Users\Dr.FrankensteinCode\Desktop\outbreak.pngUSN Journal

Evidence

EvidenceTypeDetails
FortiGate SyslogSyslog / LogIngested in Graylog
Arkime network logsNetwork TrafficIngested in Arkime
JUMPBOX-20250925-103855.rawMemory dumpJumpbox host
AWSCloudTrail.jsonCloudTrail (AWS)Ingested in Splunk
AppServiceHTTPLogs.jsonAppServiceHTTPLogs (Azure)Ingested in Splunk
StorageBlobLogs.jsonStorageBlobLogs (Azure)Ingested in Splunk
KAPE TriageTriage ImageTriage image from ZETA9-SECRETDIV
Findings
FINDING #1
FortiGate Firewall Compromised Leads to Internal Network Access from VPN
FortiGate compromise overview

On September 16, 2025, the adversary identified Zeta-9's FortiGate Firewall exposed to the internet via its public IP address. The attacker's originating IP was recorded as 38[.]68[.]134[.]103.

Shortly afterward, the firewall logs captured evidence of an unauthorized administrator login performed through the FortiGate JSON console interface (jsconsole), which corresponds to the authentication bypass vulnerability CVE-2024-55591.

Log entries showing the exploit

These events indicate that the attacker exploited the vulnerability to execute API calls locally via 127.0.0.1, bypassing normal authentication controls and logging in as the administrator account "ghost." Immediately after gaining administrative access, the attacker modified a user group (ZetaGroup) to include several new VPN accounts, establishing a persistent entry point into the internal network.

User group modification evidence

The adversary then leveraged these newly added credentials to initiate a VPN connection and access Zeta-9's internal environment without triggering perimeter authentication alerts. The adversary now had access to the internal network with an IP address of 10[.]1[.]1[.]10.

VPN connection evidence

Once inside, the adversary conducted network reconnaissance within the 192.168.86.0/24 subnet, scanning for SMB (445/TCP), RPC/DCOM (135/TCP), and LDAP (389/TCP) services: typical indicators of host and domain enumeration activity.

Network scan evidence

This reconnaissance revealed the presence of a JUMPHOST system, which subsequently became the next stage of the attacker's lateral movement.

FINDING #2
User Credential Retrieval from Storage Console via SQL Injection Attack
Surveillance Storage Console overview

Another activity was observed on September 24, 2025. The adversary with an IP address of 91[.]90[.]124[.]21 had interacted with the Surveillance Storage Console.

Adversary interaction evidence

The adversary attempted to conduct a SQL injection attack on the Surveillance Storage Console.

SQL injection attempt evidence

The adversary successfully exploited the SQL injection vulnerability on the Surveillance Storage Console and was able to download the storage object with an ID of 6.

Storage object download evidence

The user-agent showed that the threat actor used PowerShell to manually exploit the SQL injection vulnerability and download storage object ID 6, which is the cam06_ai_monitor_securityincident.mp4 video file.

Video file details

The credential of operator39 could be obtained within the video, which would be used for lateral movement to JUMPBOX.

FINDING #3
AWS Credential Stolen from JumpBox
JumpBox compromise overview

With the credential obtained from the Surveillance Storage Console, the adversary conducted a WMI-based lateral movement technique to inject a malicious DLL into the legitimate more.com process.

DLL injection evidence

The adversary deployed the custom malware (Deaddrop.dll) on this jumphost, which retrieved its configuration like the ChaCha20 key and nonce from the repository hosted on codeberg.org.

Malware configuration evidence

The custom malware exfiltrated data via dnshook[.]site by appending a subdomain with the BASE32-encoded ChaCha20-Poly1305 ciphertext.

DNS exfiltration evidence

The AWS credential was stolen and would be used to access the hybrid cloud environment.

FINDING #4
Cloud Storage Exfiltration and Website Defacement
AWS environment accessed by the threat actor
AWS environment accessed by the threat actor

Credentials exfiltrated from the jump box were used by the adversary to sign in to AWS as "VictorVenom." The activity was observed from 172[.]235[.]129[.]221 on September 25, 2025, in the AWS CloudTrail log.

Adversary obtained AWS Secret
Adversary obtained AWS Secret

After gaining access, the adversary invoked the GetSecretValue API to retrieve the secret zeta9/windows/admin-password, which likely contains Windows administrative credentials.

S3 bucket listing evidence

Subsequently, the adversary downloaded 5 objects from 3 different Amazon S3 buckets including a database backup, secret API key, threat analysis report, and the Zombie 15 experiment.

Azure Web App exploitation evidence

After that, the adversary activity was observed from the website hosted on Azure, which was restricted to administrator-level access only. The adversary used the cmd parameter to run system commands to request an OAuth access token from Azure Managed Identity using a secret that was possibly obtained from an AWS S3 object.

OAuth token request evidence

Using the acquired OAuth token, the adversary accessed the quantum-research-secrets Azure Blob Storage container and exfiltrated sensitive files including contracts, research, and confidential laboratory information.

Blob storage exfiltration evidence

The adversary was observed retrieving malicious content from hxxps[://]pastebin[.]com/raw/sBEs83q3, which was then used to overwrite /home/site/wwwroot/public/index.html. This action resulted in the defacement of the main index page of zeta9-research-portal.azurewebsites.net.

Defaced website hosting FileFix payload observed from Wayback Machine
Defaced website hosting FileFix payload observed from Wayback Machine

From the initial access to the AWS environment to website defacement, the adversary only took 44 minutes from 16:06:00 UTC to 16:50:00 UTC. This rapid attack sequence demonstrated sophisticated knowledge of both AWS and Azure environments, indicating a well-planned and executed intrusion.

FINDING #5
FileFix Leads to Researcher's Workstation Compromised and Critical Data Exfiltration
FileFix attack overview

On September 27, 2025, Dr. Frankenstein Code visited a compromised website that had been defaced by the adversary, which led to a FileFix attack being successfully deployed on this workstation.

FileFix payload delivery evidence

Upon executing the malicious PowerShell command from the defaced website, the command fetched another PowerShell script payload from hxxps[://]gist[.]githubusercontent[.]com/a1l4m/.../Microsoft[.]PowerShell[.]DataV4Adapter[.]ps1 and this script fetched the hex-encoded shellcode from hxxps[://]gist[.]githubusercontent[.]com/a1l4m/.../IamTheDanger[.]txt and executed it, which established a reverse shell connection to the adversary on 35[.]158[.]153[.]237 on port 34651.

Reverse shell connection evidence

The first command after establishing the reverse shell connection was observed from the adversary at 11:18:33 with the whoami command to determine the level of access on this workstation. Subsequently, we observed more activity from the adversary, which utilized rclone to transfer the Sliver C2 implant from MEGA drive.

Rclone transfer evidence

The Sliver C2 implant was originally named sapi.cpl as downloaded from MEGA drive.

Original filename evidence

The adversary then renamed it to RunTimeBroker.exe and moved it to C:\Users\Public.

File rename/move evidence

The adversary achieved persistence on this workstation by creating a PowerShell profile, as observed in the USN Journal.

PowerShell profile creation evidence

The Sliver C2 implant execution was observed several times after PowerShell execution. Afterward, KillTheCURE.exe and sdelete.exe were executed from the same folder at C:\Users\Dr.FrankensteinCode\AppData\Local\CureKiller\CureKiller around 15:49:58 ~ 15:49:59.

Prefetch/execution evidence

KillTheCURE.exe and sdelete.exe along with several DLLs were observed being extracted from the CUREKiller.zip file that was downloaded with the living-off-the-land binary certutil.exe, and the Exfiltration_data.zip was created after the execution of KillTheCURE.exe.

USN Journal extraction evidence

CUREKiller.zip was downloaded from GitHub. This attachment was likely uploaded within an issue, a pull request, or a comment on GitHub.

GitHub download evidence

The adversary used sdelete to permanently delete all original files that had already been copied to the user's temporary folder.

SDelete execution evidence

SDelete.exe execution was observed immediately after the execution of KillTheCURE.exe, which deleted 6 files on the desktop:

  • C:\Users\Dr.FrankensteinCode\Desktop\confidential.png
  • C:\Users\Dr.FrankensteinCode\Desktop\CURE.txt
  • C:\Users\Dr.FrankensteinCode\Desktop\gunman.png
  • C:\Users\Dr.FrankensteinCode\Desktop\Helena.txt
  • C:\Users\Dr.FrankensteinCode\Desktop\test.txt
  • C:\Users\Dr.FrankensteinCode\Desktop\outbreak.png
File deletion USN evidence

After finishing the deletion, an image file was created with the Exfiltration_data.zip embedded, which contained the 6 files stolen from this workstation.

Image embedding evidence
Zip contents evidence

KillTheCURE.exe was designed to search for .png and .txt files located in the Downloads and Desktop folders of the current user and copy them to the Temp folder, zip them to Exfiltrated_data.zip, embed the archive in BetterCallSaul.png, send the image to 36[.]157[.]123[.]216 with an HTTP POST request, and finally use sdelete.exe to completely remove the original files from the workstation.

The adversary also utilized rclone as a fallback, and we successfully obtained the image file from the MEGA drive of the adversary.

MEGA rclone evidence
Additional exfiltration evidence

After the exfiltration phase, the adversary cleared all tracks that could be traced back to them.

Track clearing evidence

Additionally, a Wing FTP Server exploitation script (CVE-2025-47812) was also found on the MEGA drive and on this workstation, which indicates that the adversary also attempted to exploit the Wing FTP Server running on this workstation.

Wing FTP exploit evidence

On September 28, 2025, the adversary cleared 5 different logs, and a netcat executable was also observed before the log clearing event.

Log clearing evidence

The registry key that contains the information indicating the FileFix attack was deleted at 2025-09-28 02:20:47.

Registry key deletion evidence

All of them were eventually deleted by the adversary at the end.

Indicators of Compromise (IOCs)
IP Addresses
38[.]68[.]134[.]103: IP used by the adversary to access FortiGate firewall
91[.]90[.]124[.]21: IP used by the adversary to attack the Storage Console
172[.]235[.]129[.]221: IP used by the adversary to attack hybrid cloud infrastructure (AWS + Azure)
35[.]158[.]153[.]237:34651: IP used by the adversary for the ClickFix attack
63[.]178[.]44[.]21:8838: IP used by the Sliver implant as persistence
36[.]157[.]123[.]216: IP used by KillTheCURE.exe payload to exfiltrate files
URLs & Domains
hxxps[://]pastebin[.]com/raw/sBEs83q3: Pastebin used to retrieve source code of the FileFix webpage
zeta9-research-portal.azurewebsites.net: Compromised Azure Web App
zeta9/windows/admin-password: Compromised AWS Secret
hxxps[://]gist[.]githubusercontent[.]com/a1l4m/.../Microsoft[.]PowerShell[.]DataV4Adapter[.]ps1: ClickFix payload stage 0
hxxps[://]gist[.]githubusercontent[.]com/a1l4m/.../IamTheDanger[.]txt: URL that hosted the shellcode
hxxps[://]github[.]com/user-attachments/files/22441452/CUREKiller[.]zip: GitHub link hosting the exfiltration binary
Accounts
aboallam480+2@gmail.com: MEGA account
00darksideofme00+2@gmail.com: MEGA account
File Hashes (SHA256)
2c327fdbaf65f8626f76858206a18a81790c5233917396e96f12d4cdea06fc7b: Sliver implant
e8fbec25db4f9d95b5e8f41cca51a4b32be8674a4dea7a45b6f7aeb22dbc38db: Netcat binary
cc84a7c2e28dddcab7143ef57429dbd9f45cb61cec86ac1d0134658d5d47170c: WingFTP CVE exploitation script
93997160b7091a043bc7cd8241f4e7d73ba0c6903337d2379e8b3d3cbb855885: CUREKiller.zip
367555ad82dbca5d7607b46720b569e5ee04aa01c3d31e32451238a9c580268a: KillTheCURE.exe
e1f7f9741f16c55c7d90e020812680673dfe3dcf87f43f722be8349aada213f2: sdelete.exe
Recommendations

Immediate Tactical Fixes

  • Contain all compromised devices
    • Isolate the researcher's workstation, JUMPHOST, and any affected servers from the network.
    • Disable persistence mechanisms (e.g., Sliver C2 implants, malicious PowerShell profiles).
  • Remove unauthorized accounts and VPN sessions
    • Delete or disable the "ghost" VPN user from the FortiGate firewall.
    • Rotate all exposed credentials, including local admin, cloud, and service accounts.
  • Patch and update critical infrastructure
    • Upgrade FortiOS to the latest secure version.
    • Ensure all servers, endpoints, and appliances have current security patches applied.
  • Verify and restore data integrity
    • Check cloud storage (AWS S3, Azure Blob) for unauthorized changes.
    • Restore deleted or tampered files from backups where possible.

Strategic Improvements

  • Adopt a Zero Trust security model
    • Implement least privilege access, micro-segmentation, and continuous authentication.
    • Ensure multi-factor authentication (MFA) is enforced for all privileged accounts.
  • Enhance monitoring and detection
    • Deploy or improve SIEM/XDR to monitor lateral movement, anomalous cloud access, and endpoint compromise.
    • Integrate real-time alerting for critical events across both on-premises and cloud environments.
  • Strengthen cloud security posture
    • Enforce IAM best practices: rotate keys, implement role-based access, and audit cloud accounts regularly.
    • Enable logging and versioning for all cloud storage objects to detect unauthorized access or deletions.
  • Incident response readiness
    • Maintain an updated playbook for advanced persistent threats targeting multi-cloud environments.
    • Conduct tabletop exercises simulating full compromise scenarios to improve team readiness.
Appendix

Splunk Queries

SPL (Splunk)
index=* "userIdentity.accessKeyId"=AKIA3EBEV4OQF3XCXJ5S | sort _time index=* "userIdentity.accessKeyId"=AKIA3EBEV4OQF3XCXJ5S eventName=GetObject | sort _time | table requestParameters.bucketName, requestParameters.key index=* "172.235.129.221" sourcetype=StorageBlobLogs | sort _time index=* "172.235.129.221" sourcetype=StorageBlobLogs | sort _time | table AuthenticationType, OperationName, ObjectKey

Rclone Configuration File

Rclone configuration file
Rclone configuration file

File Inside Adversary's MEGA Account

File inside the adversary's MEGA account
File inside the adversary's MEGA account

File Recovery

A Python script was used to recover files from the steganographic image created by the adversary:

Python
# extractor.py # Requires: Pillow (PIL) # Usage: python extractor.py hidden.png recovered.bin import sys from PIL import Image import zlib import struct def read_rgba_bytes(png_path): img = Image.open(png_path) img = img.convert("RGBA") data = img.tobytes() # row-major RGBA return data def extract(png_path, out_path): data = read_rgba_bytes(png_path) if len(data) < 16: raise ValueError("PNG too small or not containing embedded data.") header = data[:16] crc32_field, key_field_lo, orig_size = struct.unpack("<I Q I", header) key = struct.pack("<Q", key_field_lo)[:4] original_size = orig_size encrypted = data[16:16+original_size] if len(encrypted) < original_size: raise ValueError("PNG does not contain full payload (truncated).") key_u32 = key block12 = key + b'\x00\x00\x00\x00' + struct.pack("<I", original_size) check_crc = zlib.crc32(block12) & 0xFFFFFFFF if check_crc != crc32_field: print("Warning: CRC mismatch (payload integrity check failed).") key_bytes = key out = bytearray() for i, b in enumerate(encrypted): out.append(b ^ key_bytes[i % 4]) with open(out_path, "wb") as f: f.write(out) print(f"Wrote {len(out)} bytes to {out_path}") if __name__ == "__main__": if len(sys.argv) != 3: print("Usage: python extractor.py hidden.png recovered.bin") sys.exit(1) extract(sys.argv[1], sys.argv[2])
Extraction result

By running the script, we can obtain the zip file that contains the 6 files that were exfiltrated by the adversary.

↑ Back to top← All IR Reports|SOC · IR.REPORTS · CHICKEN0248