Trends
- The top attacker country is China with 2114 unique attackers (33.67%)
- OTX Pulse was the Top Alarm of the week with 227 occurrences
- The exploit event type on top this week was Command Execution with 85% occurrences.
Top Attacker by Country
Country | No. of Attackers | Occurrences |
---|---|---|
China | 2114 | 33.67% |
United States | 1141 | 18.17% |
France | 374 | 5.96% |
Brazil | 312 | 4.97% |
Russian Federation | 281 | 4.48% |
Republic of Korea | 264 | 4.20% |
India | 255 | 4.06% |
United Kingdom | 233 | 3.71% |
Netherlands | 152 | 2.42% |
Canada | 150 | 2.39% |
Germany | 146 | 2.33% |
Taiwan | 143 | 2.28% |
Indonesia | 126 | 2.01% |
Vietnam | 119 | 1.90% |
Italy | 96 | 1.53% |
Singapore | 88 | 1.40% |
Hong Kong | 77 | 1.23% |
Colombia | 72 | 1.15% |
Mexico | 68 | 1.08% |
Ukraine | 68 | 1.08% |
Threat Geo-location
Top Attacking Hosts
Host | Occurrences |
---|---|
122.226.181.166 | 52 |
122.226.181.167 | 29 |
71.6.146.130 | 14 |
58.242.83.10 | 8 |
Top Alarms
Alarm | No. of Occurrences |
---|---|
OTX Indicators of Compromise - PULSE | 227 |
Bruteforce Authentication - SSH | 18 |
Attack Tool Detected - Attack | 15 |
WebServer Attack - Attack | 8 |
Comparison from Previous Report
Alarm | No. of Occurrences |
---|---|
OTX Indicators of Compromise - PULSE | 246 |
Attack Tool Detected - Attack | 86 |
WebServer Attack - Attack | 54 |
Bruteforce Authentication - SSH | 19 |
Top Network Attackers
Origin AS | Announcement | Description |
---|---|---|
AS10439 | 71.6.128.0/17 | CariNet, Inc |
AS136190 | 122.226.180.0/23 | CHINANET-ZJ Taizhou node network |
AS4837 | 58.242.0.0/15 | China Unicom AnHui province network |
Exploit Event Types and Top Event NIDS
Vulnerability News
Cisco Firepower Management Center CVE-2018-15458 Denial of Service Vulnerability
2019-01-09
securityfocus.com/bid/106516
Cisco IP Phone 8800 Series CVE-2018-0461 Arbitrary Script Injection Vulnerability
2019-01-09
securityfocus.com/bid/106515
Cisco Prime Network Control System CVE-2018-0482 HTML Injection Vulnerability
2019-01-09
securityfocus.com/bid/106514
Cisco Identity Services Engine Cross Site Scripting and HTML-injection Vulnerabilities
2019-01-09
securityfocus.com/bid/106513
Cisco Identity Services Engine CVE-2018-15456 Information Disclosure Vulnerability
2019-01-09
securityfocus.com/bid/106512
Cisco AsyncOS for Email Security Appliance CVE-2018-15453 Remote Denial of Service Vulnerability
2019-01-09
securityfocus.com/bid/106511
Cisco IOS and IOS XE Software CVE-2018-0282 Denial of Service Vulnerability
2019-01-09
securityfocus.com/bid/106510
Cisco Prime Infrastructure CVE-2018-15457 Cross Site Scripting Vulnerability
2019-01-09
securityfocus.com/bid/106509
Cisco TelePresence Management Suite CVE-2018-15467 Cross Site Scripting Vulnerability
2019-01-09
securityfocus.com/bid/106508
Cisco Email Security Appliance CVE-2018-15460 Remote Denial of Service Vulnerability
2019-01-09
securityfocus.com/bid/106507