Trends
- The top attacker country was China with 1893 unique attackers (25.76%)
- The top Exploit event was Cross Site Scripting with 62% of occurrences
Top Attacker by Country
Country | Occurrences | Percentage |
---|---|---|
China | 1893 | 25.76% |
United States | 1836 | 24.98% |
France | 476 | 6.48% |
Brazil | 438 | 5.96% |
Russia | 319 | 4.34% |
Korea | 291 | 3.96% |
India | 287 | 3.90% |
United Kingdom | 246 | 3.35% |
Canada | 216 | 2.94% |
Germany | 190 | 2.59% |
Australia | 168 | 2.29% |
Netherlands | 154 | 2.10% |
Singapore | 150 | 2.04% |
Italy | 143 | 1.95% |
Taiwan | 129 | 1.76% |
Indonesia | 127 | 1.73% |
Vietnam | 124 | 1.69% |
Hong Kong | 86 | 1.17% |
Argentina | 77 | 1.05% |
Threat Geo-location
Top Attacking Hosts
Host | Occurrences |
---|---|
82.112.32.45 | 89 |
193.235.51.113 | 75 |
192.229.232.240 | 67 |
Top Network Attackers
Origin AS | Announcement | Description |
---|---|---|
AS48642 | 82.112.32.0/19 | Joint stock company "For" |
AS15133 | 192.229.232.0/24 | MCI Communication Services, Inc. d/b/a Verizon Business |
Top Event NIDS and Exploits
Top Alarms
Type of Alarm | Occurrences |
---|---|
Network Discovery - Scan SSH | 2029 |
Stored Procedure Access - Attack | 1751 |
Attack Tool Detected - Attack | 853 |
WebServer Attack - Attack | 758 |
OTX Indicators of Compromise - PULSE | 113 |
Network Discovery - Scan SSH | 42 |
Trojan Infection - IDS Event | 12 |
Bruteforce Authentication - SSH | 6 |
WebServer Attack - XSS | 1 |
Comparison from last week
Type of Alarm | Occurrences |
---|---|
Red Piranha HIDS: IDS Event | 3073 |
Suspicious Behaviour - SSH | 276 |
OTX Indicators of Compromise - PULSE | 147 |
Stored Procedure Access - Attack | 55 |
Attack Tool Detected - Attack | 45 |
Bruteforce Authentication - SSH | 43 |
WebServer Attack - Attack | 39 |
Network Discovery - Scan SSH | 32 |
Hacking Tool - Squid Event | 8 |
CVE
This is a list of recent vulnerabilities for which exploits are available.
ID: CVE-2018-1335
Title: Apache Tika-server Command Injection Vulnerability
Vendor: Apache
ID: CVE-2019-0541
Title: Microsoft Windows MSHTML Remote Code Execution Vulnerability
Vendor: Microsoft
ID: CVE-2019-9787
Title: WordPress Remote Code Execution Vulnerability
Vendor: WordPress
ID: CVE-2019-9740
Title: Python CRLF Injection Vulnerability
Vendor: Python
ID: CVE-2019-9741
Title: Golang Go HTTP response-splitting vulnerability
Vendor: Golang
ID: CVE-2019-9020, CVE-2019-9021, CVE-2019-9023, CVE-2019-9024
Title: PHP Information Disclosure and Heap Buffer Overflow Vulnerabilities
Vendor: PHP
ID: CVE-2019-5511, CVE-2019-5512
Title: VMware Workstation Multiple Privilege Escalation Vulnerabilities
Vendor: VMWare
ID: CVE-2019-5418, CVE-2019-5419, CVE-2019-5420
Title: Ruby on Rails Multiple Security Vulnerabilities
Vendor: Ruby on Rails
Vulnerabilities
Cisco IOS and IOS XE Software CVE-2018-15373 Denial of Service Vulnerability
2019-04-05
securityfocus.com/bid/105413
Cisco IOS Software CVE-2018-0473 Denial of Service Vulnerability
2019-04-05
securityfocus.com/bid/105427
Cisco IOS XE Software CVE-2018-0470 Denial of Service Vulnerability
2019-04-05
securityfocus.com/bid/105397
Cisco IOS and IOS XE Software CVE-2018-0466 Denial of Service Vulnerability
2019-04-05
securityfocus.com/bid/105403
Multiple Cisco Products CVE-2018-0472 Denial Of Service Vulnerability
2019-04-05
securityfocus.com/bid/105418
Google Android Qualcomm Components Multiple Security Vulnerabilities
2019-04-05
securityfocus.com/bid/105872
Cisco Small Business RV320 and RV325 Routers CVE-2019-1827 Cross Site Scripting Vulnerability
2019-04-04
securityfocus.com/bid/107776
Cisco Small Business RV320 and RV325 Routers CVE-2019-1828 Weak Encryption Security Weakness
2019-04-04
securityfocus.com/bid/107774
Omron CX-Programmer CVE-2019-6556 Arbitrary Code Execution Vulnerability
2019-04-04
securityfocus.com/bid/107773
Xen HLE Constructs Denial of Service Vulnerability
2019-04-03
securityfocus.com/bid/105954
Xen Multiple Privilege Escalation and Denial of Service Vulnerabilities
2019-04-03
securityfocus.com/bid/106182
Citrix XenServer Multiple Security Vulnerabilities
2019-04-03
securityfocus.com/bid/102129
Xen CVE-2017-17044 Denial of Service Vulnerability
2019-04-03
securityfocus.com/bid/102008
Drupal Core SA-CORE-2019-004 Cross Site Scripting Vulnerability
2019-04-03
securityfocus.com/bid/107497
libvirt CVE-2019-3886 Security Bypass Vulnerability
2019-04-03
securityfocus.com/bid/107777
CentOS Web Panel CVE-2019-10261 Multiple HTML Injection Vulnerabilities
2019-04-03
securityfocus.com/bid/107769
GNU wget CVE-2019-5953 Remote Buffer Overflow Vulnerability
2019-04-03
securityfocus.com/bid/107734
Symantec VIP Enterprise Gateway CVE-2019-9696 Cross Site Scripting Vulnerability
2019-04-03
securityfocus.com/bid/107692
Siemens SCALANCE X switches CVE-2019-6569 Security Weakness
2019-04-02
securityfocus.com/bid/107465
Linux kernel CVE-2019-3882 Local Denial of Service Vulnerability
2019-04-02
securityfocus.com/bid/107782
Fortinet FortiClient CVE-2019-5585 Access Bypass Vulnerability
2019-04-02
securityfocus.com/bid/107693
Advantech WebAccess/SCADA ICSA-19-092-01 Multiple Security Vulnerabilities
2019-04-02
securityfocus.com/bid/107675