Trends
- The top attacker country was the United States with 815 unique attackers (25.19%)
- The top Exploit event was SQL injection with 80% of occurrences
Top Attacker by Country
Country | Occurrences | Percentage |
---|---|---|
United States | 815 | 25.19% |
China | 800 | 24.73% |
France | 177 | 5.47% |
Brazil | 172 | 5.32% |
India | 144 | 4.45% |
Russian Federation | 143 | 4.42% |
Republic of Korea | 137 | 4.23% |
United Kingdom | 108 | 3.34% |
Netherlands | 104 | 3.21% |
Germany | 87 | 2.69% |
Canada | 82 | 2.53% |
Vietnam | 82 | 2.53% |
Taiwan | 78 | 2.41% |
Australia | 60 | 1.85% |
Greece | 59 | 1.82% |
Italy | 53 | 1.64% |
Indonesia | 48 | 1.48% |
Singapore | 47 | 1.45% |
Turkey | 39 | 1.21% |
Threat Geo-location
Top Attacking Hosts
Host | Occurrences |
---|---|
58.242.83.39 | 28 |
50.62.177.238 | 16 |
185.94.111.1 | 14 |
197.231.221.211 | 13 |
93.174.93.23 | 10 |
Top Network Attackers
Origin AS | Announcement | Description |
---|---|---|
AS4837 | 58.242.0.0/15 | China Unicom AnHui province network |
AS26496 | 50.62.0.0/15 | GoDaddy.com, LLC |
AS197068 | 185.94.108.0/22 | HLL LLC |
AS37560 | 197.231.220.0/22 | Cyberdyne S.A. |
AS202425 | 93.174.93.0/24 | IP Volume Inc. |
Top Event NIDS and Exploits
Top Alarms
Type of Alarm | Occurrences |
---|---|
OTX Indicators of Compromise - PULSE | 142 |
Database Attack - Stored Procedure Access - Attack | 40 |
Bruteforce Authentication - SSH | 9 |
WebServer Attack - Attack | 8 |
Attack Tool detected - Attach | 1 |
Comparison from last week
Type of Alarm | Occurrences |
---|---|
Attack Tool detected - Attack | 290 |
OTX Indicators of Compromise - PULSE | 134 |
Bruteforce Authentication - SSH | 2 |
CVE
This is a list of recent vulnerabilities for which exploits are available.
ID: CVE-2019-1727
Title: Cisco NX-OS Software Local Privilege Escalation Vulnerability
ID: CVE-2019-1806
Title: Cisco Small Business Series Switches Denial of Service Vulnerability
Vendor: Cisco
ID: CVE-2017-14491
Title: Dnsmasq Multiple Security Vulnerabilities
Vendor: Thekelleys
ID: CVE-2015-5504
Title: Drupal Novalnet Payment Module- Ubercart Module SQL Injection Vulnerability
Vendor: Drupal
ID: CVE-2019-11205
Title: Multiple TIBCO Products Multiple Unspecified Cross-Site Scripting Vulnerabilities
Vendor: Tibco
ID: CVE-2019-11328
Title: Singularity Insecure Permissions Local Privilege Escalation Vulnerability
Vendor: Sylabs
ID: CVE-2019-10139
Title: cockpit-ovirt Local Information Disclosure Vulnerability
Vendor: oVirt
ID: CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091
Title: Intel Processor MDS Vulnerabilities
Vendor: Intel
Vulnerabilities
Adobe Flash Player CVE-2019-7837 Use After Free Arbitrary Code Execution Vulnerability
2019-05-24
securityfocus.com/bid/108312
Multiple F-Secure Windows Endpoint Protection Products Local Code Execution Vulnerability
2019-05-24
securityfocus.com/bid/108443
Multiple VMware Products CVE-2019-5519 Local Code Execution Vulnerability
2019-05-24
securityfocus.com/bid/107535
Atlassian Bitbucket Server CVE-2019-3397 Directory Traversal Vulnerability
2019-05-23
securityfocus.com/bid/108447
Siemens SIMATIC Products ICSA-19-134-08 Multiple Security Vulnerabilities
2019-05-22
securityfocus.com/bid/108404
Intel Microarchitectural Data Sampling Multiple Local Information Disclosure Vulnerabilities
2019-05-22
securityfocus.com/bid/108330
Nagios XI '/nagiosxi/login.php' SQL Injection Vulnerability
2019-05-22
securityfocus.com/bid/108446
curl/libcURL CVE-2019-5436 Heap Buffer Overflow Vulnerability
2019-05-22
securityfocus.com/bid/108435
QEMU CVE-2019-12247 Integer Overflow Vulnerability
2019-05-22
securityfocus.com/bid/108434
curl/libcURL CVE-2019-5435 Multiple Integer Overflow Vulnerabilities
2019-05-22
securityfocus.com/bid/108433
QEMU CVE-2019-12155 Local Denial of Service Vulnerability
2019-05-22
securityfocus.com/bid/108429
Apache Camel CVE-2019-0188 XML External Entity Injection Vulnerability
2019-05-22
securityfocus.com/bid/108422
Microsoft Windows 'SetJobFileSecurityByName()' Function Local Privilege Escalation Vulnerability
2019-05-21
securityfocus.com/bid/108423
Mozilla Firefox Multiple Security Vulnerabilities
2019-05-21
securityfocus.com/bid/108421