Red Piranha Threat Intelligence Report - Oct. 15-21 2017

TOP 10 ATTACKER (BY COUNTRY)

CHINA is our current top Attacker

otx1

otx2

Detailed Report on Suspicious hosts

Behavior: Scanning hosts

Activity: Continuously using different username password combination existing and non-existing usernames.

We have found following different types of events:

SSHD authentication failed.

Multiple SSHD authentication failures.

Multiple failed logins in a small period of time.

SSH insecure connection attempt (scan).

Failed Password

Invalid User

Type of attack: Bruteforce

Source IP Addresses:

221.194.47.242203.249.22.182103.79.143.32

121.18.238.28103.79.143.141103.79.143.34

103.79.141.15074.208.144.30103.79.143.108

TOP OTX Activity

otx2

THREAT GEOLOCATION

threat geo loc

SIEM EVENTS

siem

AV/IPS Rules: Locky Malware Phishing Campaign Rule

Details
Date Published
November 23, 2017