Red Piranha Threat Intelligence Report - October 1-7 2018

TRENDS



  • United States in on top of the list with 1477 unique attackers (25.7%)
  • All exploits events were Command Execution (100%)
  • The Top Alarm was Reconnaissance & Probing - Database Attack - Stored Procedure Access - Attack with 2705 occurences (39.9%).



TOP ATTACKER COUNTRIES


CountryNo. of AttackersPercentage
United States147725.7%
China119020.7%
Russian Federation4357.6%
Brazil3405.9%
France2764.8%
Vietnam2113.7%
India2033.5%
Germany1833.2%
Korea1793.1%
United Kingdom1562.7%
Australia1542.7%
Netherlands1542.7%
Canada1212.1%
Taiwan1182.1%
Italy1071.9%
Indonesia951.7%
Egypt911.6%
Japan871.5%
Singapore801.4%
Ukraine791.4%


Top Cyber Attackers by Country October 1-7 2018



THREAT GEOLOCATION


Cyber Security Threat Geolocations October 1-7 2018




TOP ATTACKING HOSTS


Top Attacker Hosts October 1-7 2018




TOP ALARMS



AlarmNo. of Occurrences
Reconnaissance & Probing — Database Attack - Stored Procedure Access2705
Reconnaissance & Probing — Attack Tool detected1524
Delivery & Attack — WebServer Attack — Attack    1355
AlienVault HIDS: Multiple XSS (Cross Site Scripting) attempts from same source IP894


Comparison to Previous Week


AlarmNo. of Occurrences
OTX Indicators of Compromise - PULSE151
Bruteforce Authentication - SSH41
Database Attack - Stored Procedure Access - Attack21
Attack Tool detected - Attack8




EXPLOIT EVENT TYPES AND TOP EVENTS NIDS


Top Event NIDS and Exploits October 1-7 2018



OPEN THREAT EXCHANGE


Pulses SubscribedIndicatorsLast UpdatedNumber of AlarmsNumber of Events
5,775873,8542018-10-09 00:22:405,67211,943



VULNERABILITIES


Adobe Acrobat and Reader CVE-2018-12838 Stack Overflow Vulnerability
2018-10-01
securityfocus.com/bid/105444

Adobe Acrobat and Reader APSB18-30 Type Confusion Multiple Arbitrary Code Execution Vulnerabilities
2018-10-01
securityfocus.com/bid/105443

Adobe Acrobat and Reader Untrusted Pointer Dereference Arbitrary Code Execution Vulnerabilities
2018-10-01
securityfocus.com/bid/105442

Adobe Acrobat and Reader APSB18-30 Multiple Arbitrary Code Execution Vulnerabilities
2018-10-01
securityfocus.com/bid/105441

Adobe Acrobat and Reader CVE-2018-12841 Arbitrary Code Execution Vulnerability
2018-10-01
securityfocus.com/bid/105440

Top Cyber Security Alarms October 1-7 2018
Details