Red Piranha Threat Intelligence Report - Dec. 3 to Dec. 9 2017

Top Attacker by Country


tc


Top Attacker by Host


TH


Detailed Report on Suspicious Host


Behaviour: Scanning Hosts
Activity: Continously using different username, password combination on existing and non-existing username
Different Types of Events Found: SSHD authentication failed
Multiple SSHD authentication failure
Multiple failed logins in a small period of time
SSH insecure connection attempt (scan
Failed Password
Invalid User
Input UserAuth request invalid user
Type of Attack: Bruteforce

Source IP Addresses


188.226.185.34 178.62.217.132 185.165.31.10
95.211.202.85 5.101.40.10 195.62.13.75
89.39.104.180 199.195.248.31 185.12.179.49


Alarms Report


Alarms Report


Threat Geolocation


threat geo loc


AV/IPS Rules


IceID Banking Trojan (NO ZEUS PANDA BANKER)

Details
Date Published
December 11, 2017