Dodge This Security Profile picture
Computer Security Professional. Everyday is a new chance to learn something new. I enjoy helping protect people from cyber threats when and where possible.
Nov 1, 2019 14 tweets 24 min read
New Blog Post: Hancitor + COM Objects

Recently, Hancitor incorporated the use of COM to spawn IE and download stage 2 payloads. While many may have not understood the true risk of what the Hancitor campaign stumbled into it, its very dangerous.

dodgethissecurity.com/2019/11/01/han… Specifically, my research partners and myself around 1 year ago theorized that COM objects if used to spawn IE could be used to get around/through proxy servers in environments. Proxy servers have provided a severely overestimated layer of protection.
Aug 20, 2019 11 tweets 2 min read
So who want's IP Addresses of systems that attempted to login into my HitBTC account which I created but never used 🤣😂?

IP Addresses:
153.232.149.239
185.235.131.105
203.136.13.19
187.171.201.77
98.143.144.2
165.169.174.210
176.106.45.201
202.70.85.125
197.149.17.17 62.212.188.42
41.140.246.88
110.74.219.225
179.52.122.34
37.142.114.193
160.178.223.115
165.16.19.79
188.217.221.129
5.189.206.237
46.161.61.238
95.85.71.33
2.38.147.66