Trends
- The top attacker country is China with 2064 unique attackers (29.36%)
- OTX Pulse was the Top Alarm of the week with 246 occurrences
- The exploit event type on top this week was Command Execution with 60% occurrences.
Top Attacker by Country
Country | No. of Attackers | Occurrences |
---|---|---|
China | 2064 | 29.36% |
United States | 1588 | 22.59% |
France | 399 | 5.68% |
Brazil | 351 | 4.99% |
Russian Federation | 329 | 4.68% |
India | 281 | 4.00% |
Korea | 247 | 3.51% |
United Kingdom | 246 | 3.50% |
Netherlands | 196 | 2.79% |
Germany | 166 | 2.36% |
Canada | 160 | 2.28% |
Vietnam | 145 | 2.06% |
Indonesia | 137 | 1.95% |
Australia | 123 | 1.75% |
Italy | 117 | 1.66% |
Taiwan | 113 | 1.61% |
Singapore | 107 | 1.52% |
Mexico | 95 | 1.35% |
Hong Kong | 86 | 1.22% |
Thailand | 79 | 1.12% |
Threat Geo-location
Top Attacking Hosts
Host | Occurrences |
---|---|
109.153.28.115 | 79 |
128.90.157.228 | 46 |
115.238.245.2 | 40 |
122.226.181.166 | 21 |
122.226.181.167 | 21 |
122.226.181.165 | 19 |
122.226.181.164 | 17 |
Top Alarms
Alarm | No. of Occurrences |
---|---|
OTX Indicators of Compromise - PULSE | 246 |
Attack Tool Detected - Attack | 86 |
WebServer Attack - Attack | 54 |
Bruteforce Authentication - SSH | 19 |
Comparison from Previous Report
Alarm | No. of Occurrences |
---|---|
Attack Tool Detected - Attack | 350 |
WebServer Attack - Attack | 309 |
OTX Indicators of Compromise - Pulse | 192 |
Bruteforce Authentication - SSH | 16 |
Top Network Attackers
Origin AS | Announcement | Description |
---|---|---|
AS2856 | 109.144.0.0/12 | British Telecommunications PLC |
AS22363 | 128.90.157.0/24 | Unus, Inc. |
AS4134 | 115.224.0.0/12 | CHINANET Zhejiang province network |
AS136190 | 122.226.180.0/23 | CHINANET-ZJ Taizhou node network |
Exploit Event Types and Top Event NIDS
Vulnerability News
Yokogawa Vnet/IP Open Communication Driver CVE-2018-16196 Denial of Service Vulnerability
2019-12-21
securityfocus.com/bid/106442
OpenAFS CVE-2018-16949 Multiple Denial of Service Vulnerabilities
2019-09-11
securityfocus.com/bid/106375
RETIRED: Adobe Acrobat and Reader CVE-2018-19725 Security Bypass Vulnerability
2019-01-04
securityfocus.com/bid/106438
Adobe Acrobat and Reader APSB18-41 Multiple Unspecified Security Bypass Vulnerabilities
2019-01-04
securityfocus.com/bid/106165
Adobe Acrobat and Reader APSB18-41 Multiple Arbitrary Code Execution Vulnerabilities
2019-01-04
securityfocus.com/bid/106164
Adobe Acrobat and Reader CVE-2018-16018 Security Bypass Vulnerability
2019-01-03
securityfocus.com/bid/106449
Hetronic Nova-M CVE-2018-19023 Authentication Bypass Vulnerability
2019-01-03
securityfocus.com/bid/106448
Adobe Acrobat and Reader CVE-2018-16011 Arbitrary Code Execution Vulnerability
2019-01-03
securityfocus.com/bid/106447
Schneider Electric Pro-face GP-Pro CVE-2018-7832 Arbitrary Code Execution Vulnerability
2019-01-03
securityfocus.com/bid/106441
OpenSSL CVE-2018-0734 Side Channel Attack Information Disclosure Vulnerability
2019-01-02
securityfocus.com/bid/105758
OpenSSL CVE-2018-5407 Side Channel Attack Information Disclosure Vulnerability
2019-01-02
securityfocus.com/bid/105897
Xen 'vmx.c' Denial of Service Vulnerability
2019-01-02
securityfocus.com/bid/105817
Artifex Ghostscript CVE-2018-19478 Denial of Service Vulnerability
2019-01-02
securityfocus.com/bid/106445
GNU Binutils CVE-2018-20657 Denial of Service Vulnerability
2019-01-02
securityfocus.com/bid/106444
IBM Quality Manager CVE-2017-1609 Cross Site Scripting Vulnerability
2019-01-02
securityfocus.com/bid/106384
F5 BIG-IP APM CVE-2018-15334 Cross Site Request Forgery Vulnerability
2019-01-01
securityfocus.com/bid/106364
Node.js Multiple Denial of Service Vulnerabilities
2019-01-01
securityfocus.com/bid/106363
GNU Binutils CVE-2018-20651 Denial of Service Vulnerability
2019-01-01
securityfocus.com/bid/106440
HP UCMDB Configuration Manager CVE-2018-18593 Multiple Security Vulnerabilities
2018-12-31
securityfocus.com/bid/106374
JasPer 'base/jas_malloc.c' Memory Leak Information Disclosure Vulnerability
2018-12-31
securityfocus.com/bid/106373