Dodge This Security Profile picture
Aug 20, 2019 β€’ 11 tweets β€’ 2 min read β€’ Read on X
So who want's IP Addresses of systems that attempted to login into my HitBTC account which I created but never used πŸ€£πŸ˜‚?

IP Addresses:
153.232.149.239
185.235.131.105
203.136.13.19
187.171.201.77
98.143.144.2
165.169.174.210
176.106.45.201
202.70.85.125
197.149.17.17
62.212.188.42
41.140.246.88
110.74.219.225
179.52.122.34
37.142.114.193
160.178.223.115
165.16.19.79
188.217.221.129
5.189.206.237
46.161.61.238
95.85.71.33
2.38.147.66
183.83.134.16
194.156.124.136
95.160.185.241
201.64.22.50
61.7.170.251
193.93.192.62
83.171.253.29
185.251.71.184
41.43.129.58
115.87.202.131
1.0.132.253
180.244.235.96
125.24.194.93
37.144.21.183
2.135.134.18
60.116.152.149
93.190.204.241
124.195.222.252
88.185.198.45
86.194.10.212
189.248.153.32
49.171.102.42
213.27.68.247
75.185.239.246
82.162.199.218
155.186.196.213
89.211.230.98
75.139.80.146
85.143.73.204
181.215.39.88
188.243.227.108
109.227.106.118
113.161.25.104
85.75.190.75
213.89.188.242
23.91.248.194
180.250.219.235
79.91.100.154
110.138.148.154
177.247.76.16
27.64.63.67
67.237.184.254
201.37.66.127
176.37.159.23
76.0.135.39
62.133.162.44
182.253.122.46
88.106.18.47
71.54.57.188
82.154.104.102
5.105.109.216
85.66.198.144
88.248.60.209
67.235.3.176
189.7.228.86
179.233.206.110
87.15.142.106
184.22.102.4
5.140.90.208
5.137.2.40
171.96.24.82
83.6.55.120
106.160.148.21
211.58.116.161
39.118.52.130
178.159.215.169
153.136.111.27
133.218.54.162
211.211.18.179
84.237.129.181
68.134.147.73
112.214.32.184
58.146.35.223
193.250.115.73
188.32.49.145
139.195.249.210
90.127.58.51
89.3.238.75
190.199.106.96
37.9.40.55
172.90.67.205
91.18.153.169
93.179.90.195
46.161.57.209
85.132.9.108
146.185.206.85
210.121.227.194
37.134.42.115
178.57.68.75
153.206.252.42
185.14.195.181
94.180.231.62
146.185.202.51
101.143.12.81
58.11.188.71
121.164.228.72
190.201.180.150
117.55.164.73
37.9.40.122
188.68.0.85
5.8.37.31
58.140.48.9
125.142.106.125

Login Attempts are over the last 2 years. This list might be useful for those researching crypto currency fraud/theft.
One note is at least some of the threat actors were smart in how they planned to maintain access. Some of them did succeed logging in since I didn't care about this account. But some of the threat actors setup API keys to try and maintain a backdoor.
Most victims would never realize an API key was setup allowing continued access even after they recovered their accounts.

Honestly, some of my old accounts that I don't care about become great honeypots for threat intel :).

β€’ β€’ β€’

Missing some Tweet in this thread? You can try to force a refresh
γ€€

Keep Current with Dodge This Security

Dodge This Security Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @shotgunner101

Nov 1, 2019
New Blog Post: Hancitor + COM Objects

Recently, Hancitor incorporated the use of COM to spawn IE and download stage 2 payloads. While many may have not understood the true risk of what the Hancitor campaign stumbled into it, its very dangerous.

dodgethissecurity.com/2019/11/01/han…
Specifically, my research partners and myself around 1 year ago theorized that COM objects if used to spawn IE could be used to get around/through proxy servers in environments. Proxy servers have provided a severely overestimated layer of protection.
Organization's security teams have come to assume that "Since the malware doesn't know the proxy details, auth mechanism or have user credentials callouts will fail". However, this is a faulty assumption as with COM objects + IE you can automatically get that information!
Read 14 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(