Trends
- The top attacker country is China with 2064 unique attackers (29.36%)
- OTX Pulse was the Top Alarm of the week with 246 occurrences
- The exploit event type on top this week was Command Execution with 60% occurrences.
Top Attacker by Country
| Country | No. of Attackers | Occurrences |
|---|---|---|
| China | 2064 | 29.36% |
| United States | 1588 | 22.59% |
| France | 399 | 5.68% |
| Brazil | 351 | 4.99% |
| Russian Federation | 329 | 4.68% |
| India | 281 | 4.00% |
| Korea | 247 | 3.51% |
| United Kingdom | 246 | 3.50% |
| Netherlands | 196 | 2.79% |
| Germany | 166 | 2.36% |
| Canada | 160 | 2.28% |
| Vietnam | 145 | 2.06% |
| Indonesia | 137 | 1.95% |
| Australia | 123 | 1.75% |
| Italy | 117 | 1.66% |
| Taiwan | 113 | 1.61% |
| Singapore | 107 | 1.52% |
| Mexico | 95 | 1.35% |
| Hong Kong | 86 | 1.22% |
| Thailand | 79 | 1.12% |

Threat Geo-location

Top Attacking Hosts
| Host | Occurrences |
|---|---|
| 109.153.28.115 | 79 |
| 128.90.157.228 | 46 |
| 115.238.245.2 | 40 |
| 122.226.181.166 | 21 |
| 122.226.181.167 | 21 |
| 122.226.181.165 | 19 |
| 122.226.181.164 | 17 |
Top Alarms
| Alarm | No. of Occurrences |
|---|---|
| OTX Indicators of Compromise - PULSE | 246 |
| Attack Tool Detected - Attack | 86 |
| WebServer Attack - Attack | 54 |
| Bruteforce Authentication - SSH | 19 |
Comparison from Previous Report
| Alarm | No. of Occurrences |
|---|---|
| Attack Tool Detected - Attack | 350 |
| WebServer Attack - Attack | 309 |
| OTX Indicators of Compromise - Pulse | 192 |
| Bruteforce Authentication - SSH | 16 |
Top Network Attackers
| Origin AS | Announcement | Description |
|---|---|---|
| AS2856 | 109.144.0.0/12 | British Telecommunications PLC |
| AS22363 | 128.90.157.0/24 | Unus, Inc. |
| AS4134 | 115.224.0.0/12 | CHINANET Zhejiang province network |
| AS136190 | 122.226.180.0/23 | CHINANET-ZJ Taizhou node network |
Exploit Event Types and Top Event NIDS

Vulnerability News
Yokogawa Vnet/IP Open Communication Driver CVE-2018-16196 Denial of Service Vulnerability
2019-12-21
securityfocus.com/bid/106442
OpenAFS CVE-2018-16949 Multiple Denial of Service Vulnerabilities
2019-09-11
securityfocus.com/bid/106375
RETIRED: Adobe Acrobat and Reader CVE-2018-19725 Security Bypass Vulnerability
2019-01-04
securityfocus.com/bid/106438
Adobe Acrobat and Reader APSB18-41 Multiple Unspecified Security Bypass Vulnerabilities
2019-01-04
securityfocus.com/bid/106165
Adobe Acrobat and Reader APSB18-41 Multiple Arbitrary Code Execution Vulnerabilities
2019-01-04
securityfocus.com/bid/106164
Adobe Acrobat and Reader CVE-2018-16018 Security Bypass Vulnerability
2019-01-03
securityfocus.com/bid/106449
Hetronic Nova-M CVE-2018-19023 Authentication Bypass Vulnerability
2019-01-03
securityfocus.com/bid/106448
Adobe Acrobat and Reader CVE-2018-16011 Arbitrary Code Execution Vulnerability
2019-01-03
securityfocus.com/bid/106447
Schneider Electric Pro-face GP-Pro CVE-2018-7832 Arbitrary Code Execution Vulnerability
2019-01-03
securityfocus.com/bid/106441
OpenSSL CVE-2018-0734 Side Channel Attack Information Disclosure Vulnerability
2019-01-02
securityfocus.com/bid/105758
OpenSSL CVE-2018-5407 Side Channel Attack Information Disclosure Vulnerability
2019-01-02
securityfocus.com/bid/105897
Xen 'vmx.c' Denial of Service Vulnerability
2019-01-02
securityfocus.com/bid/105817
Artifex Ghostscript CVE-2018-19478 Denial of Service Vulnerability
2019-01-02
securityfocus.com/bid/106445
GNU Binutils CVE-2018-20657 Denial of Service Vulnerability
2019-01-02
securityfocus.com/bid/106444
IBM Quality Manager CVE-2017-1609 Cross Site Scripting Vulnerability
2019-01-02
securityfocus.com/bid/106384
F5 BIG-IP APM CVE-2018-15334 Cross Site Request Forgery Vulnerability
2019-01-01
securityfocus.com/bid/106364
Node.js Multiple Denial of Service Vulnerabilities
2019-01-01
securityfocus.com/bid/106363
GNU Binutils CVE-2018-20651 Denial of Service Vulnerability
2019-01-01
securityfocus.com/bid/106440
HP UCMDB Configuration Manager CVE-2018-18593 Multiple Security Vulnerabilities
2018-12-31
securityfocus.com/bid/106374
JasPer 'base/jas_malloc.c' Memory Leak Information Disclosure Vulnerability
2018-12-31
securityfocus.com/bid/106373
