Threat Intelligence Report - August 20-26 2018

TRENDS


  • Bruteforce Authentication - SSH with 61.2% of all occurrences was the top alarm this week.   
  • China is our Top Attacker by Country this week with 939 attacks recorded.  



TOP ATTACKER COUNTRIES


CountryNo. of Attackers
China939
United States824
Russian Federation367
Brazil225
France179
India178
Vietnam170
United Kingdom164
Republic of Korea150
Netherlands112
Italy98
Canada90
Germany85
Egypt77
Australia73
Ukraine63
Indonesia54
Thailand45
Columbia43
Japan41


Top Cyber Attackers by Country August 20-26 2018



THREAT GEOLOCATION


Cyber Security Threat Geolocations August 20-26 2018



TOP ATTACKING HOSTS


HostOccurrences
123.173.16.18584
23.233.180.6428
41.37.152.22312
171.217.2.1510
141.121.122.489
37.79.173.256




TOP ALARMS


AlarmNo. of Occurrences
Delivery & Attack - Bruteforce Authentication - SSH 170
Reconnaissance & Probing - Attack Tool detected - Attack113
Environmental Awareness - OTX Indicators of Compromise - PULSE90
Reconnaissance & Probing - Database Attack - Stored Procedure Access - Attack114
Delivery & Attack - WebServer Attack - Attack31


Comparison to the Previous Report 


AlarmNo. of Occurrences
Delivery & Attack - Bruteforce Authentication - SSH 618
Reconnaissance & Probing - Attack Tool detected - Attack224
Environmental Awareness - OTX Indicators of Compromise - PULSE122
Reconnaissance & Probing - Database Attack - Stored Procedure Access - Attack42
Delivery & Attack - WebServer Attack - Attack4




EXPLOIT EVENT TYPES


Exploit Event Types August 20-26 2018




OPEN THREAT EXCHANGE


Open Threat Exchange August 20-26 2018




VULNERABILITY NEWS



Ansible Tower CVE-2018-10884 Cross Site Request Forgery Vulnerability securityfocus.com/bid/105136


Eclipse OpenJ9 CVE-2018-12539 Multiple Privilege Escalation Vulnerabilities securityfocus.com/bid/105126


IBM Java SDK CVE-2018-1517 Denial of Service Vulnerability securityfocus.com/bid/105117



Top Attacker Hosts August 20-26 2018
Details