Trends
- The top attacker country was China with 1169 unique attackers (24.69%)
- The top Exploit event was Cross Site Scripting with 68% of occurrences
Top Attacker by Country
Country | Occurrences | Percentage |
---|---|---|
China | 1169 | 24.69% |
United States | 1082 | 22.85% |
Russian Federation | 313 | 6.61% |
Brazil | 261 | 5.51% |
Vietnam | 237 | 5.01% |
France | 207 | 4.37% |
India | 205 | 4.33% |
Republic of Korea | 188 | 3.97% |
United Kingdom | 133 | 2.81% |
Taiwan | 132 | 2.79% |
Canada | 128 | 2.70% |
Egypt | 103 | 2.18% |
Germany | 103 | 2.18% |
Netherlands | 101 | 2.13% |
Indonesia | 93 | 1.96% |
Hong Kong | 84 | 1.77% |
Greece | 68 | 1.44% |
Italy | 65 | 1.37% |
Australia | 63 | 1.33% |
Threat Geo-location
Top Attacking Hosts
Host | Occurrences |
---|---|
58.242.83.39 | 20 |
188.92.77.235 | 8 |
66.240.205.34 | 3 |
Top Network Attackers
Origin AS | Announcement | Description |
---|---|---|
AS4837 | 58.242.0.0/15 | China Unicom AnHui province network |
AS37560 | 197.231.220.0/22 | Cyberdyne S.A |
AS10439 | 71.6.128.0/17 | CariNet, Inc |
Top Event NIDS and Exploits
Top Alarms
Type of Alarm | Occurrences |
---|---|
Automated Actionable Intelligence IOC's | 157 |
Trojan infection - IDS Event | 117 |
Network Discovery - IDS Event | 24 |
Bruteforce Authentication - SSH | 8 |
WebServer Attack - XSS | 1 |
Comparison from last week
Type of Alarm | Occurrences |
---|---|
Trojan Infection - IDS Event | 456 |
Automated Actionable Intelligence IOC's | 131 |
Bruteforce Authentication - SSH | 50 |
Network Discovery - IDS Event | 27 |
CVE
This is a list of recent vulnerabilities for which exploits are available.
ID: CVE-2019-1040
Title: Microsoft Windows NTLM Tampering Vulnerability
ID: CVE-2019-12308
Title: Microsoft Windows Security Feature Bypass Vulnerability
ID: CVE-2019-0973
Title: Microsoft Windows Installer DLL Loading Local Privilege Escalation Vulnerability
ID: CVE-2019-12735
Title: Vim and Neovim Arbitrary Code Execution Vulnerability
ID: CVE-2019-9501
Title: Broadcom WiFi Chipset Drivers Multiple Heap Buffer Overflow Vulnerabilities
ID: CVE-2019-9503
Title: Linux Kernel Security Bypass and Heap Buffer Overflow Vulnerabilities
ID: CVE-2019-0307
Title: SAP Solution Manager Remote Information Disclosure Vulnerability
Vulnerabilities
Apache HTTP Server CVE-2019-0220 Remote Security Vulnerability
securityfocus.com/bid/107670
Apache HTTP Server CVE-2019-0197 Denial of Service Vulnerability
securityfocus.com/bid/107665
Apache httpd CVE-2019-0196 Security Bypass Vulnerability
securityfocus.com/bid/107669
Microsoft Windows 'SetJobFileSecurityByName()' Function Local Privilege Escalation Vulnerability
securityfocus.com/bid/108423
Microsoft Windows CVE-2019-1064 Local Privilege Escalation Vulnerability
securityfocus.com/bid/108587
Microsoft Windows Shell CVE-2019-1053 Local Privilege Escalation Vulnerability
securityfocus.com/bid/108585
Microsoft Windows Installer CVE-2019-0973 DLL Loading Local Privilege Escalation Vulnerability
securityfocus.com/bid/108651
BD Alaris Gateway Workstation CVE-2019-10959 Arbitrary File Upload Vulnerability
securityfocus.com/bid/108765
Mozilla Thunderbird MFSA2019-17 Multiple Security Vulnerabilities
securityfocus.com/bid/108761
Multiple WAGO Industrial Managed Switches Security Bypass Vulnerability
securityfocus.com/bid/108759
Google Chrome CVE-2019-5842 Remote Security Vulnerability
securityfocus.com/bid/108758
Cisco IOS XE Software CVE-2019-1904 Cross Site Request Forgery Vulnerability
securityfocus.com/bid/108737
Microsoft Windows X.509 Certificate Denial of Service Vulnerability
securityfocus.com/bid/108694
Broadcom WiFi Chipset Drivers Multiple Heap Buffer Overflow Vulnerabilities
securityfocus.com/bid/108013
Linux Kernel Security Bypass and Heap Buffer Overflow Vulnerabilities
securityfocus.com/bid/108011
Google Android System Component Multiple Security Vulnerabilities
securityfocus.com/bid/108554
SAP Enterprise Financial Services CVE-2018-2484 Remote Authorization Bypass Vulnerability
securityfocus.com/bid/106477
SAP Solution Manager CVE-2019-0291 Local Information Disclosure Vulnerability
2019-06-11
securityfocus.com/bid/108313
SAP Business Client Unspecified Security Vulnerability
2019-06-11
securityfocus.com/bid/104436
Evernote Web Clipper for Chrome CVE-2019-12592 Cross Site Scripting Vulnerability
2019-06-11
securityfocus.com/bid/108762
Dbus CVE-2019-12749 Authentication Bypass Vulnerability
2019-06-11
securityfocus.com/bid/108751