 
Trends
- The top attacker country is China with 2114 unique attackers (33.67%)
- OTX Pulse was the Top Alarm of the week with 227 occurrences
- The exploit event type on top this week was Command Execution with 85% occurrences.
Top Attacker by Country
| Country | No. of Attackers | Occurrences | 
|---|---|---|
| China | 2114 | 33.67% | 
| United States | 1141 | 18.17% | 
| France | 374 | 5.96% | 
| Brazil | 312 | 4.97% | 
| Russian Federation | 281 | 4.48% | 
| Republic of Korea | 264 | 4.20% | 
| India | 255 | 4.06% | 
| United Kingdom | 233 | 3.71% | 
| Netherlands | 152 | 2.42% | 
| Canada | 150 | 2.39% | 
| Germany | 146 | 2.33% | 
| Taiwan | 143 | 2.28% | 
| Indonesia | 126 | 2.01% | 
| Vietnam | 119 | 1.90% | 
| Italy | 96 | 1.53% | 
| Singapore | 88 | 1.40% | 
| Hong Kong | 77 | 1.23% | 
| Colombia | 72 | 1.15% | 
| Mexico | 68 | 1.08% | 
| Ukraine | 68 | 1.08% | 

Threat Geo-location

Top Attacking Hosts
| Host | Occurrences | 
|---|---|
| 122.226.181.166 | 52 | 
| 122.226.181.167 | 29 | 
| 71.6.146.130 | 14 | 
| 58.242.83.10 | 8 | 
Top Alarms
| Alarm | No. of Occurrences | 
|---|---|
| OTX Indicators of Compromise - PULSE | 227 | 
| Bruteforce Authentication - SSH | 18 | 
| Attack Tool Detected - Attack | 15 | 
| WebServer Attack - Attack | 8 | 
Comparison from Previous Report
| Alarm | No. of Occurrences | 
|---|---|
| OTX Indicators of Compromise - PULSE | 246 | 
| Attack Tool Detected - Attack | 86 | 
| WebServer Attack - Attack | 54 | 
| Bruteforce Authentication - SSH | 19 | 
Top Network Attackers
| Origin AS | Announcement | Description | 
|---|---|---|
| AS10439 | 71.6.128.0/17 | CariNet, Inc | 
| AS136190 | 122.226.180.0/23 | CHINANET-ZJ Taizhou node network | 
| AS4837 | 58.242.0.0/15 | China Unicom AnHui province network | 
Exploit Event Types and Top Event NIDS

Vulnerability News
Cisco Firepower Management Center CVE-2018-15458 Denial of Service Vulnerability
2019-01-09
securityfocus.com/bid/106516
Cisco IP Phone 8800 Series CVE-2018-0461 Arbitrary Script Injection Vulnerability
2019-01-09
securityfocus.com/bid/106515
Cisco Prime Network Control System CVE-2018-0482 HTML Injection Vulnerability
2019-01-09
securityfocus.com/bid/106514
Cisco Identity Services Engine Cross Site Scripting and HTML-injection Vulnerabilities
2019-01-09
securityfocus.com/bid/106513
Cisco Identity Services Engine CVE-2018-15456 Information Disclosure Vulnerability
2019-01-09
securityfocus.com/bid/106512
Cisco AsyncOS for Email Security Appliance CVE-2018-15453 Remote Denial of Service Vulnerability
2019-01-09
securityfocus.com/bid/106511
Cisco IOS and IOS XE Software CVE-2018-0282 Denial of Service Vulnerability
2019-01-09
securityfocus.com/bid/106510
Cisco Prime Infrastructure CVE-2018-15457 Cross Site Scripting Vulnerability
2019-01-09
securityfocus.com/bid/106509
Cisco TelePresence Management Suite CVE-2018-15467 Cross Site Scripting Vulnerability
2019-01-09
securityfocus.com/bid/106508
Cisco Email Security Appliance CVE-2018-15460 Remote Denial of Service Vulnerability
2019-01-09
securityfocus.com/bid/106507

