Threat_Intelligence_Report

Trends


  • The top attacker country was China with 2430 unique attackers (27.05%)
  • The top Exploit event was Command Execution with 87% of occurrences



Top Attacker by Country


CountryNo. of AttackersPercentage
China243027.05%
United States194221.61%
France5596.22%
Brazil5315.91%
Korea4334.82%
Russian Federation4144.61%
India3994.44%
United Kingdom2682.98%
Vietnam2672.97%
Taiwan2662.96%
Canada2422.69%
Germany2342.60%
Italy1972.19%
Indonesia1641.83%
Netherlands1601.78%
Singapore1501.67%
Australia1361.51%
Argentina981.09%
Thailand951.06%


Top Cyber Attackers by Country March 3-10 2019




Threat Geo-location


Cyber Security Threat Geolocations March 3-10 2019



Top Attacking Hosts


HostOccurrences
185.176.27.11099
46.35.173.8290
88.149.158.9084
185.222.211.15860
185.176.26.10754
103.75.182.4152
185.10.68.20241




Top Network Attackers


Origin ASAnnouncementDescription
AS204428185.176.27.0/24IP Dunaev Yuriy Vyacheslavovich
AS4777146.35.168.0/21Digital Cable Television Ltd
AS3561288.149.128.0/17EOLO S.p.A
AS205092185.222.211.0/24OUTSOURCE GRID LIMITED
AS57271185.176.26.0/24IP Kirichenko Andrey Evgenievich
AS38733103.75.182.0/23BQT computer technology
AS200651185.10.68.0/24Flokinet Ltd



Exploit Event Types and Top Event NIDS


Top Event NIDS and Exploits March 3-10 2019



Top Alarms


Type of AlarmNo. of Occurrences
Network Discovery - IDS Event Drop List2,428
OTX Indicators of Compromise - PULSE117
Database Attack - Stored Procedure Access - Attack51
Attack Tool Detected - Attack35
WebServer Attack - Attack33
Trojan Infection - IDS Event13
Bruteforce Authentication - SSH2


Comparison from Last Week


Type of AlarmNo. of Occurrences
Red Piranha IDS Event17414
OTX Indicators of Compromise - PULSE88
Network Discovery - IDS Event Drop List32
Database Attack - Stored Procedure Access - Attack2
Attack Tool Detected - Attack2




CVE


This is a list of recent vulnerabilities for which exploits are available.

ID: CVE-2018-1999002
Title: Jenkins Arbitrary File Access Vulnerability  
Vendor: Jenkins
 
ID: CVE-2018-19519
Title: Tcpdump Buffer Overflow Vulnerability
Vendor: Tcpdump
 
ID: CVE-2019-6340 
Title: Drupal Remote Code Execution Vulnerability (SA-CORE-2019-003) 
Vendor: Drupal
 
ID: CVE-2018-19107
Title: Exiv2 Denial of Service Vulnerability
Vendor: Exiv2
 
ID: CVE-2018-20122
Title: Fastweb Fastgate Remote Code Execution Vulnerability
Vendor: Fastweb
 
ID: CVE-2019-7238
Title: Nexus Repository Manager 3 Remote Code Execution Vulnerability 
Vendor: Nexus Repository

ID: CVE-2018-20250
Title: WinRAR Arbitrary Code Execution Vulnerability 
Vendor: RARLAB
  
ID: CVE-2018-20250
Title: Cisco Routers Management Interface Remote Command Execution Vulnerability - (cisco-sa-20190227-rmi-cmd-ex)
Vendor: Cisco


Vulnerabilities


Google Chrome CVE-2019-5786 'FileReader' Use After Free Arbitrary Code Execution Vulnerability
securityfocus.com/bid/107213

Linux kernel CVE-2019-7221 Local Denial of Service Vulnerability
securityfocus.com/bid/107294

Cisco NX-OS Software CVE-2019-1602 Local Insecure File Permissions Vulnerability
securityfocus.com/bid/107332

Cisco NX-OS Software CVE-2019-1603 Local Privilege Escalation Vulnerability
securityfocus.com/bid/107328

Cisco NX-OS Software Extensible Authentication Protocol Denial of Service Vulnerability
securityfocus.com/bid/107325

Top Attacker Hosts March 3-10 2019
Details