Threat_Intelligence_Report

Trends


  • The top attacker country was China with 2651 unique attackers (29.71%)
  • The top Exploit event was Command Execution with 41% of occurrences



Top Attacker by Country


CountryOccurrencesPercentage
China265129.71%
United States192821.61%
France5696.38%
Brazil4955.55%
Korea4234.74%
India4064.55%
Russia3413.82%
United Kingdom2983.34%
Canada2312.59%
Germany2122.38%
Italy2122.38%
Indonesia1842.06%
Netherlands 1761.97%
Vietnam1611.80%
Singapore1521.70%
Taiwan1411.58%
Australia1281.43%
Mexico1101.23%
Hong Kong1041.17%


Top Cyber Attackers by Country March 18-24 2019



Threat Geo-location


Cyber Security Threat Geolocations March 18-24 2019



Top Attacking Hosts


HostOccurrences
188.92.77.23559
210.1.224.9223
185.176.27.11822




Top Network Attackers


Origin ASAnnouncementDescription
AS43513188.92.72.0/21Sia Nano IT
AS45785210.1.224.0/24SERVICE HOSTING
AS204428185.176.27.0/24IP Dunaev Yuriy Vyacheslavovich



Exploit Event Types and Top Event NIDS


Top Event NIDS and Exploits March 18-24 2019



Top Alarms



Type of AlarmNo. of Occurrences
Red Piranha HIDS: IDS Event1536
OTX Indicators of Compromise - PULSE109
Network Discovery - Scan SSH71
Database Attack - Stored Procedure Access - Attack56
Attack Tool Detected - Attack19
System Compromise - Suspicious Behaviour - SSH14
Delivery & Attack - WebServer Attack - Attack10
Delivery & Attack - Network Discovery - IDS Event9
Delivery & Attack - Bruteforce Authentication - SSH4
Environmental Awareness - Trojan infection - IDS Event2


Comparison from last week


Type of AlarmNo. of Occurrences
Network Discovery - SourceIP Observed on Multiple RP Network11,186
Network Discovery - IDS Event Drop List6,253
Network Discovery - IDS Event Drop List Rule 31170
Network Discovery - Scan Nmap504
OTX Indicators of Compromise - PULSE213
Network Discovery - IDS Event98
Database Attack - Stored Procedure Access - Attack26
Network Discovery - Scan SSH26
Attack Tool Detected - Attack14
WebServer Attack - Attack10
Trojan Infection - IDS Event3




CVE


This is a list of recent vulnerabilities for which exploits are available.

ID: CVE-2018-1335
Title: Apache Tika-server Command Injection Vulnerability
Vendor: Apache

ID: CVE-2019-0541
Title: Microsoft Windows MSHTML Remote Code Execution Vulnerability
Vendor: Microsoft

ID: CVE-2019-9787 
Title: WordPress Remote Code Execution Vulnerability
Vendor: WordPress

ID: CVE-2019-9740
Title: Python CRLF Injection Vulnerability
Vendor: Python

ID: CVE-2019-9741
Title: Golang Go HTTP response-splitting vulnerability
Vendor: Golang

ID: CVE-2019-9020, CVE-2019-9021, CVE-2019-9023, CVE-2019-9024
Title: PHP Information Disclosure and Heap Buffer Overflow Vulnerabilities
Vendor: PHP

ID: CVE-2019-5511, CVE-2019-5512
Title: VMware Workstation Multiple Privilege Escalation Vulnerabilities
Vendor: VMWare

ID: CVE-2019-5418, CVE-2019-5419, CVE-2019-5420
Title: Ruby on Rails Multiple Security Vulnerabilities
Vendor: Ruby on Rails



Vulnerabilities


Oracle Java SE CVE-2019-2426 Information Disclosure Vulnerability
2019-03-22
securityfocus.com/bid/106590

IBM Java SDK CVE-2018-1890 Local Privilege Escalation Vulnerability
2019-03-22
securityfocus.com/bid/107448

QEMU CVE-2019-8934 Local Information Disclosure Vulnerability
2019-03-22
securityfocus.com/bid/107115

PuTTY Multiple Security Vulnerabilities
2019-03-22
securityfocus.com/bid/107484

Cloud Foundry Cloud Controller API CVE-2017-8037 Incomplete Fix Information Disclosure Vulnerability
2019-03-22
securityfocus.com/bid/100448

Opencontainers runc CVE-2019-5736 Local Command Execution Vulnerability
2019-03-22
securityfocus.com/bid/106976

Mozilla Firefox Unspecified Remote Code Execution Vulnerability
2019-03-22
securityfocus.com/bid/107534

Atlassian SourceTree CVE-2018-20234 Arbitrary Code Execution Vulnerability
2019-03-21
securityfocus.com/bid/107414

Red Hat JBoss BPMS CVE-2016-6343 Cross Site Scripting Vulnerability
2019-03-21
securityfocus.com/bid/96987

Mozilla Firefox MFSA2019-01 Multiple Security Vulnerabilities
2019-03-20
securityfocus.com/bid/106773

Gemalto Sentinel UltraPro ICSA-19-073-02 Security Vulnerability
2019-03-20
securityfocus.com/bid/107415

Cisco IP Phone 8800 Series CVE-2019-1764 Cross Site Request Forgery Vulnerability
2019-03-20
securityfocus.com/bid/107502

Cisco IP Phone 8800 Series CVE-2019-1765 Path Traversal Arbitrary File Write Vulnerability
2019-03-20
securityfocus.com/bid/107500

Top Attacker Hosts March 18-24 2019
Details