Trends
- The top attacker country was the United States with 1151 unique attackers (25.49%)
- The top Exploit event was SQL injection with 80% of occurrences
Top Attacker by Country
Country | Occurrences | Percentage |
---|---|---|
United States | 1151 | 25.49% |
China | 1041 | 23.06% |
Brazil | 275 | 6.09% |
United Kingdom | 268 | 5.94% |
France | 227 | 5.03% |
Republic of Korea | 199 | 4.41% |
Russian Federation | 194 | 4.30% |
India | 175 | 3.88% |
Vietnam | 124 | 2.75% |
Netherlands | 120 | 2.66% |
Taiwan | 117 | 2.59% |
Germany | 115 | 2.55% |
Canada | 112 | 2.48% |
Australia | 83 | 1.84% |
Italy | 67 | 1.48% |
Indonesia | 65 | 1.44% |
Greece | 63 | 1.40% |
Singapore | 60 | 1.33% |
Hong Kong | 59 | 1.31% |
Threat Geo-location
Top Attacking Hosts
Host | Occurrences |
---|---|
134.209.74.119 | 60 |
58.242.83.39 | 24 |
77.154.194.148 | 18 |
79.62.150.45 | 15 |
Top Network Attackers
Origin AS | Announcement | Description |
---|---|---|
AS14061 | 134.209.64.0/20 | Digital Ocean |
AS4837 | 58.242.0.0/15 | China Unicom AnHui province network |
AS15557 | 77.144.0.0/12 | SFR SA |
AS3269 | 79.62.0.0/16 | Telecom Italia S.p.A |
Top Event NIDS and Exploits
Top Alarms
Type of Alarm | Occurrences |
---|---|
OTX Indicators of Compromise - PULSE | 119 |
Database Attack - Stored Procedure Access - Attack | 89 |
WebServer Attack - Attack | 45 |
Bruteforce Authentication - SSH | 28 |
Trojan Injection - IDS Event | 4 |
Comparison from last week
Type of Alarm | Occurrences |
---|---|
Attack Tool Detected - Attack | 246 |
Store Procedure Access - Attack | 246 |
WebServer Attack - Attack | 184 |
OTX Indicators of Compromise - PULSE | 158 |
Bruteforce Authentication - SSH | 11 |
Network Discovery - IDS Event | 5 |
CVE
This is a list of recent vulnerabilities for which exploits are available.
ID: CVE-2019-0703
Title: Windows SMB Information Disclosure Vulnerability
Vendor: Windows
ID: CVE-2019-2725
Title: Oracle WebLogic Server Remote Code Execution Vulnerability
Vendor: Oracle
ID: CVE-2019-3400
Title: Atlassian JIRA Cross Site Scripting Vulnerability
Vendor: Atlassian
ID: CVE-2019-1708
Title: Multiple Cisco Products CVE-2019-1708 Denial of Service Vulnerability
Vendor: Cisco
ID: CVE-2019-1701
Title: Multiple Cisco Products Multiple Cross Site Scripting Vulnerabilities
Vendor: Cisco
Vulnerabilities
Multiple VMware Products CVE-2019-5518 Out of Bounds Read Write Local Code Execution Vulnerability
2019-05-10
securityfocus.com/bid/107541
Alpine Linux Docker Image CVE-2019-5021 Hard Coded Credentials Authentication Bypass Vulnerability
2019-05-08
securityfocus.com/bid/108288
Kaspersky Antivirus Engine CVE-2019-8285 Heap Buffer Overflow Vulnerability
2019-05-08
securityfocus.com/bid/108284
Linux Kernel CVE-2019-11815 Race Condition Vulnerability
2019-05-08
securityfocus.com/bid/108283
Multiple F5 BIG-IP Products CVE-2019-6619 Denial of Service Vulnerability
2019-05-08
securityfocus.com/bid/108190
Symantec AV Engine CVE-2019-9698 Arbitrary File Deletion Vulnerability
2019-05-08
securityfocus.com/bid/108128
Cisco Firepower Threat Defense Software CVE-2019-1703 Denial of Service Vulnerability
2019-05-07
securityfocus.com/bid/108170
Jenkins Multiple Security Vulnerabilities
2019-05-07
securityfocus.com/bid/108159
Linux Kernel CVE-2019-11810 Denial of Service Vulnerability
2019-05-07
securityfocus.com/bid/108286
Linux Kernel CVE-2018-20836 Race Condition Vulnerability
2019-05-07
securityfocus.com/bid/108196
Cisco Elastic Services Controller CVE-2019-1867 Authentication Bypass Vulnerability
2019-05-07
securityfocus.com/bid/108184
NVIDIA Tegra TLK Widevine Trust CVE-2018-6243 Privilege Escalation Vulnerability
2019-05-06
securityfocus.com/bid/108287
Facebook Thrift CVE-2019-3565 Remote Denial of Service Vulnerability
2019-05-06
securityfocus.com/bid/108280
Facebook Thrift CVE-2019-3552 Remote Denial of Service Vulnerability
2019-05-06
securityfocus.com/bid/108279
Google Android Broadcom Components CVE-2018-19860 Remote Code Execution Vulnerability
2019-05-06
securityfocus.com/bid/108277
Facebook Thrift CVE-2019-3558 Remote Denial of Service Vulnerability
2019-05-06
securityfocus.com/bid/108274