Trends
- The top attacker country was the United States with 1105 unique attackers (27.72%)
- The top Exploit event was Miscellaneous with 70% of occurrences
Top Attacker by Country
Country | Occurrences | Percentage |
---|---|---|
United States | 1105 | 27.72% |
China | 950 | 23.83% |
Brazil | 202 | 5.07% |
France | 189 | 4.74% |
Russian Federation | 172 | 4.31% |
Republic of Korea | 156 | 3.91% |
India | 153 | 3.84% |
Germany | 124 | 3.11% |
United Kingdom | 121 | 3.03% |
Canada | 112 | 2.81% |
Vietnam | 107 | 2.68% |
Netherlands | 97 | 2.43% |
Australia | 96 | 2.41% |
Taiwan | 93 | 2.33% |
Singapore | 82 | 2.06% |
Italy | 63 | 1.58% |
Indonesia | 62 | 1.56% |
Greece | 60 | 1.50% |
Spain | 43 | 1.08% |
Threat Geo-location
Top Attacking Hosts
Host/IP Address |
---|
51.68.11.231 |
213.251.182.110 |
50.62.176.21 |
174.136.12.168 |
178.62.119.137 |
46.4.50.7 |
85.13.131.13 |
Top Network Attackers
Country | Origin AS | Announcement | Description |
---|---|---|---|
AS16276 | 51.68.0.0/16 | OVH SAS | |
AS62729 | 174.136.12.0/22 | A Small Orange LLC | |
AS14061 | 178.62.64.0/18 | DigitalOcean London | |
AS24940 | 46.4.0.0/16 | Hetzner Online GmbH | |
AS34788 | 85.13.131.0/24 | Neue Medien Muennich GmbH |
Top Event NIDS and Exploits
Top Alarms
Type of Alarm | Occurrences |
---|---|
Attack Tool Detected - Attack | 246 |
Store Procedure Access - Attack | 246 |
WebServer Attack - Attack | 184 |
OTX Indicators of Compromise - PULSE | 158 |
Bruteforce Authentication - SSH | 11 |
Network Discovery - IDS Event | 5 |
Comparison from last week
Type of Alarm | Occurrences |
---|---|
OTX Indicators of Compromise - PULSE | 210 |
Attack Tool Detected - Attack | 44 |
Bruteforce Authentication - SSH | 35 |
WebServer Attack - Attack | 34 |
Trojan Infection - IDS Event | 21 |
Database Attack - Stored Procedure Access - Attack | 9 |
Network Discovery - IDS Event | 7 |
CVE
This is a list of recent vulnerabilities for which exploits are available.
ID: CVE-2019-3844
Title: systemd Local Privilege Escalation Vulnerability
Vendor: systemd
ID: CVE-2019-6467
Title: ISC BIND Remote Denial of Service Vulnerability
Vendor: ISC
ID: CVE-2018-2004
Title: IBM Jazz Reporting Service Cross Site Scripting Vulnerability
Vendor: IBM
ID: CVE-2019-11035
Title: PHP Multiple Heap Buffer Overflow Vulnerabilities
Vendor: PHP
ID: CVE-2019-11244
Title: Kubernetes Local Unauthorized Access Vulnerability
Vendor: Kubernetes
ID: CVE-2019-9208
Title: Wireshark Multiple Denial of Service Vulnerabilities
Vendor: Wireshark
Vulnerabilities
Oracle E-Business Suite cpuapr2019 Multiple Security Vulnerabilities
securityfocus.com/bid/107938
Oracle WebLogic Server Deserialization Remote Command Execution Vulnerability
securityfocus.com/bid/108074
Microsoft Visual Studio 'asm' Remote Memory Corruption Vulnerability
securityfocus.com/bid/108122
Multiple GE Communicator components ICSA-19-122-02 Multiple Security Vulnerabilities
securityfocus.com/bid/108143
Linux Kernel CVE-2019-11683 Remote Denial of Service Vulnerability
securityfocus.com/bid/108142
Eclipse OpenJ9 CVE-2019-10245 Denial of Service Vulnerability
securityfocus.com/bid/108094
Cisco Nexus 9000 Series Fabric Switches CVE-2019-1592 Local Privilege Escalation Vulnerability
securityfocus.com/bid/108146
Cisco Prime Network Registrar CVE-2019-1852 Cross Site Scripting Vulnerability
securityfocus.com/bid/108145
Cisco Adaptive Security Appliance Software CVE-2019-1706 Denial of Service Vulnerability
securityfocus.com/bid/108144
Cisco Nexus 9000 Series Fabric Switches CVE-2019-1587 Information Disclosure Vulnerability
securityfocus.com/bid/108141
Cisco Small Business Switches CVE-2019-1859 Authentication Bypass Vulnerability
securityfocus.com/bid/108140
Cisco Small Business RV320 and RV325 Routers CVE-2019-1724 Session Hijacking Vulnerability
securityfocus.com/bid/108139
Multiple Cisco Products CVE-2019-1635 Denial Of Service Vulnerability
securityfocus.com/bid/108138
Multiple Cisco Products CVE-2018-15388 Denial of Service Vulnerability
securityfocus.com/bid/108137
Cisco Nexus 9000 Series Fabric Switches CVE-2019-1803 Local Privilege Escalation Vulnerability
securityfocus.com/bid/108136
Cisco Firepower Threat Defense Software CVE-2019-1699 Local Command Injection Vulnerability
securityfocus.com/bid/108135
Cisco Umbrella CVE-2019-1807 Session Hijacking Vulnerability
securityfocus.com/bid/108134
Cisco Nexus 9000 Series Fabric Switches CVE-2019-1590 Authentication Bypass Vulnerability
securityfocus.com/bid/108133
Cisco Adaptive Security Appliance Software CVE-2019-1713 Cross Site Request Forgery Vulnerability
securityfocus.com/bid/108132
Cisco Web Security Appliance CVE-2019-1816 Local Command Injection Vulnerability
securityfocus.com/bid/108131
Cisco Web Security Appliance CVE-2019-1817 Remote Denial of Service Vulnerability
securityfocus.com/bid/108130
Cisco Application Policy Infrastructure Controller Local Privilege Escalation Vulnerability
securityfocus.com/bid/108129