Trends
- The top attacker country is China with 2114 unique attackers (33.67%)
- OTX Pulse was the Top Alarm of the week with 227 occurrences
- The exploit event type on top this week was Command Execution with 85% occurrences.
Top Attacker by Country
| Country | No. of Attackers | Occurrences |
|---|---|---|
| China | 2114 | 33.67% |
| United States | 1141 | 18.17% |
| France | 374 | 5.96% |
| Brazil | 312 | 4.97% |
| Russian Federation | 281 | 4.48% |
| Republic of Korea | 264 | 4.20% |
| India | 255 | 4.06% |
| United Kingdom | 233 | 3.71% |
| Netherlands | 152 | 2.42% |
| Canada | 150 | 2.39% |
| Germany | 146 | 2.33% |
| Taiwan | 143 | 2.28% |
| Indonesia | 126 | 2.01% |
| Vietnam | 119 | 1.90% |
| Italy | 96 | 1.53% |
| Singapore | 88 | 1.40% |
| Hong Kong | 77 | 1.23% |
| Colombia | 72 | 1.15% |
| Mexico | 68 | 1.08% |
| Ukraine | 68 | 1.08% |

Threat Geo-location

Top Attacking Hosts
| Host | Occurrences |
|---|---|
| 122.226.181.166 | 52 |
| 122.226.181.167 | 29 |
| 71.6.146.130 | 14 |
| 58.242.83.10 | 8 |
Top Alarms
| Alarm | No. of Occurrences |
|---|---|
| OTX Indicators of Compromise - PULSE | 227 |
| Bruteforce Authentication - SSH | 18 |
| Attack Tool Detected - Attack | 15 |
| WebServer Attack - Attack | 8 |
Comparison from Previous Report
| Alarm | No. of Occurrences |
|---|---|
| OTX Indicators of Compromise - PULSE | 246 |
| Attack Tool Detected - Attack | 86 |
| WebServer Attack - Attack | 54 |
| Bruteforce Authentication - SSH | 19 |
Top Network Attackers
| Origin AS | Announcement | Description |
|---|---|---|
| AS10439 | 71.6.128.0/17 | CariNet, Inc |
| AS136190 | 122.226.180.0/23 | CHINANET-ZJ Taizhou node network |
| AS4837 | 58.242.0.0/15 | China Unicom AnHui province network |
Exploit Event Types and Top Event NIDS

Vulnerability News
Cisco Firepower Management Center CVE-2018-15458 Denial of Service Vulnerability
2019-01-09
securityfocus.com/bid/106516
Cisco IP Phone 8800 Series CVE-2018-0461 Arbitrary Script Injection Vulnerability
2019-01-09
securityfocus.com/bid/106515
Cisco Prime Network Control System CVE-2018-0482 HTML Injection Vulnerability
2019-01-09
securityfocus.com/bid/106514
Cisco Identity Services Engine Cross Site Scripting and HTML-injection Vulnerabilities
2019-01-09
securityfocus.com/bid/106513
Cisco Identity Services Engine CVE-2018-15456 Information Disclosure Vulnerability
2019-01-09
securityfocus.com/bid/106512
Cisco AsyncOS for Email Security Appliance CVE-2018-15453 Remote Denial of Service Vulnerability
2019-01-09
securityfocus.com/bid/106511
Cisco IOS and IOS XE Software CVE-2018-0282 Denial of Service Vulnerability
2019-01-09
securityfocus.com/bid/106510
Cisco Prime Infrastructure CVE-2018-15457 Cross Site Scripting Vulnerability
2019-01-09
securityfocus.com/bid/106509
Cisco TelePresence Management Suite CVE-2018-15467 Cross Site Scripting Vulnerability
2019-01-09
securityfocus.com/bid/106508
Cisco Email Security Appliance CVE-2018-15460 Remote Denial of Service Vulnerability
2019-01-09
securityfocus.com/bid/106507
