Threat_Intelligence_Report

Trends


  • The top attacker country was China with 2661 unique attackers (27.10%)
  • The top Exploit event was Command Execution with 41% of occurrences



Top Attacker by Country


CountryNo. of AttackersPercentage
China266127.10%
United States227623.18%
France6126.23%
Brazil5896.00%
India4224.30%
Russian Federation3803.87%
Korea3763.83%
United Kingdom3283.34%
Germany3053.11%
Canada2522.57%
Australia2112.15%
Vietnam2052.09%
Taiwan1992.03%
Singapore1921.96%
Netherlands1881.91%
Indonesia1851.88%
Italy1841.87%
Hong Kong1471.50%
Greece1081.10%


Top Cyber Attackers by Country March 11-17 2019



Threat Geo-location


Cyber Security Threat Geolocations March 11-17 2019



Top Attacking Hosts


HostOccurrences
59.167.22.51709
115.238.245.2590
185.176.27.110407
159.65.175.37339
122.226.181.165315
163.172.68.20268




Top Network Attackers


Origin ASAnnouncementDescription
AS473959.167.0.0/16iiNet Limited
AS4134115.224.0.0/12CHINANET Zhejiang province network
AS204428185.176.27.0/24IP Dunaev Yuriy Vyacheslavovich
AS14061159.65.160.0/20DigitalOcean, LLC
AS136190122.226.180.0/23CHINANET-ZJ Taizhou node network
AS12876163.172.0.0/16ONLINE SAS



Exploit Event Types and Top Event NIDS


Top Event NIDS and Exploits March 11-17 2019



Top Alarms


Type of AlarmNo. of Occurrences
Network Discovery - SourceIP Observed on Multiple RP Network11,186
Network Discovery - IDS Event Drop List6,253
Network Discovery - IDS Event Drop List Rule 31170
Network Discovery - Scan Nmap504
OTX Indicators of Compromise - PULSE213
Network Discovery - IDS Event98
Database Attack - Stored Procedure Access - Attack26
Network Discovery - Scan SSH26
Attack Tool Detected - Attack14
WebServer Attack - Attack10
Trojan Infection - IDS Event3


Comparison from Last Week


Type of AlarmNo. of Occurrences
Network Discovery - IDS Event Drop List2,428
OTX Indicators of Compromise - PULSE117
Database Attack - Stored Procedure Access - Attack51
Attack Tool Detected - Attack35
WebServer Attack - Attack33
Trojan Infection - IDS Event13
Bruteforce Authentication - SSH2




CVE


This is a list of recent vulnerabilities for which exploits are available.

ID: CVE-2019-5786
Title: Google Chrome User After Free Arbitrary Code Execution Vulnerability
Vendor: Microsoft

ID: CVE-2019-0187
Title: Apache JMeter Remote Code Execution Vulnerability
Vendor: Apache

ID: CVE-2019-1596 
Title: Cisco NX-OS Software Bash Shell Local Privilege Escalation Vulnerability
Vendor: Cisco

ID: CVE-2019-1707
Title: Cisco DNA Center Access Contract HTML Injection Vulnerability
Vendor: Cisco

ID: CVE-2019-0809 
Title: Microsoft Visual Studio Remote Code Execution Vulnerability
Vendor: Microsoft

ID: CVE-2019-0603
Title: Microsoft Windows TFTP Server Remote Code Execution Vulnerability
Vendor: Microsoft

ID: CVE-2019-0808, CVE-2019-0797
Title: Microsoft Windows Win32k Elevation of Privilege Vulnerability
Vendor: Microsoft

ID: CVE-2019-7816
Title: Adobe ColdFusion Arbitrary File-Upload Vulnerability
Vendor: Adobe 



Vulnerabilities


Microsoft Windows Win32k CVE-2019-0808 Local Privilege Escalation Vulnerability
securityfocus.com/bid/107331

Oracle Java SE CVE-2019-2449 Remote Security Vulnerability
securityfocus.com/bid/106597

Oracle Java SE CVE-2018-11212 Remote Security Vulnerability
securityfocus.com/bid/106583

Apache Solr CVE-2017-3164 Server Side Request Forgery Security Bypass Vulnerability
securityfocus.com/bid/107026

Lenovo Dynamic Power Reduction Utility CVE-2019-6149 Local Privilege Escalation Vulnerability
securityfocus.com/bid/107438

Cloud Foundry Container Runtime CVE-2019-3780 Privilege Escalation Vulnerability
securityfocus.com/bid/107434

VMware Workstation Multiple Privilege Escalation Vulnerabilities
securityfocus.com/bid/107429

Top Attacker Hosts March 11-17 2018
Details