Red Piranha Threat Intelligence Report - Jan. 8 to Jan. 14 '2018

Top Attacker by Country


top country

 


Top Attacker by Host


host

 


Detailed Report on Suspicious Hosts



BehaviourScanning Hosts
Activity:Continuously using different username, password combination on existing and non-existing username
Different Types of Events Found:SSHD authentication failed

Multiple SSHD authentication failure

Multiple failed logins in a small period of time

SSH insecure connection attempt (scan)

Failed Password

Invalid User

Input UserAuth request invalid user
Type of Attack:Bruteforce





Source IP Addresses


80.82.77.1395.101.40.10103.79.143.32
212.129.39.185103.79.141.16137.221.214.32
101.178.133.241103.207.37.19871.6.202.198




SIEM Events



SIEM Events

 


AV/IPS Rules


Butter Overflow via Negative HTTP Chunk size number



Details
Date Published
January 15, 2018