Red Piranha Threat Intelligence Report - Nov. 26 to Dec. 2 2017

Top Attacker by Country


4-12



Top Attacker by Host


host



Detailed Report on Suspicious Host


Behaviour:Scanning Hosts
Activity:Continously using different username, password combination on existing and non-existing username
Different Types of Events Found:SSHD authentication failed

Multiple SSHD authentication failure

Multiple failed logins in a small period of time

SSH insecure connection attempt (scan

Failed Password

Invalid User

Input UserAuth request invalid user
Type of Attack:Bruteforce



Source IP Addresses


198.98.57.2135.101.40.10100.1.1.1
198.98.52.241103.99.0.191199.195.248.31
74.208.144.305.188.10.156139.59.209.18



Top OTX Activity


OTX



Alarms Report


alarms



Threat Geolocation


threat geo loc



AV/IPS Rules


SVN/Git Remote Code Execution through malicious attempt to crash named using malformed RNDC Packet.



Details
Date Published
December 04, 2017