Red Piranha Threat Intelligence Report - Oct. 15-21 2017



TOP 10 ATTACKER (BY COUNTRY)

CHINA is our current top Attacker


otx1





otx2



Detailed Report on Suspicious hosts


Behavior: Scanning hosts

Activity: Continuously using different username password combination existing and non-existing usernames.

We have found following different types of events:

SSHD authentication failed.

Multiple SSHD authentication failures.

Multiple failed logins in a small period of time.

SSH insecure connection attempt (scan).

Failed Password

Invalid User

Input userauth request invalid user

Type of attack: Bruteforce

Source IP Addresses:

221.194.47.242203.249.22.182103.79.143.32

121.18.238.28103.79.143.141103.79.143.34

103.79.141.15074.208.144.30103.79.143.108


TOP OTX Activity

otx2


THREAT GEOLOCATION

threat geo loc

SIEM EVENTS

siem


AV/IPS Rules: Locky Malware Phishing Campaign Rule

Details
Date Published
November 23, 2017