Red Piranha Threat Intelligence Report - June 25 to July 1 2018

TRENDS


  • The number of unique attackers from the United States increased to 26%, reaching the first place this week. 
  • Most of the top attacking hosts are from the United States and from the same Network. 
  • The top alarm was: AlienVault HIDS: Web Server 400 error code with 117619 occurrences. 


TOP ATTACKER COUNTRIES


Country No. of Attackers Percentage
United States 1075 26%
China 807 19.5%
Russian Federation 323 7.8%
Brazil 250 6.2%
India 198 5.3%
France 178 4.0%
Australia 150 3.5%
Republic of Korea 130 3.4%
Vietnam 119 3.4%
Germany 116 3.3%
Singapore 116 3.2%
United Kingdom 109 2.8%
Netherlands 107 2.5%
Italy 79 2.1%
Japan 77 1.9%
Hong Kong 73 1.8%
Indonesia 72 1.6%
Canada 71 1.6%
Poland 62 1.5%
Ukraine 57 1.4%

Top Cyber Attackers by Country June 25 - July 1 2018


THREAT GEOLOCATION


Cyber Security Threat Geolocations June 25 - July 1 2018


TOP ATTACKING HOSTS


Top Attacker Hosts June 25 - July 1 2018


TOP ATTACKING NETWORKS


Origin AS Announcement Description
AS63949 45.33.96.0/21 Linode


TOP ALARMS


 

Alarm No. of Occurrences
AlienVault HIDS: Web Server 400 error code 117619
Reconnaissance & Probing - Attack Tool detected - Attack 16208
AlienVault NIDS: "ET SCAN NMAP -sS window 1024" 1542
Environmental Awareness - OTX Indicators of Compromise - PULSE 1507
Delivery & Attack - WebServer Attack - Attack 468
Delivery & Attack - Bruteforce Authentication - SSH 327
Reconnaissance & Probing - Database Attack - Stored Procedure Access - Attack 79
Delivery & Attack - Bruteforce Authentication - Linux/Unix 18
Exploitation & Installation - WebServer Attack - XSS 1

                           

Comparison to the Previous Report

Alarm No. of Occurrences
Environmental Awareness - OTX Indicators of Compromise - PULSE 1075
Delivery & Attack - Bruteforce Authentication - SSH 429
Delivery & Attack - Bruteforce Authentication - Linux/Unix 40
Delivery & Attack - WebServer Attack - SQL Injection - Attack Pattern Detection 2

Top Cyber Security Alarms June 25 - July 1 2018
Details