threat-intelligence-report

Trends


  • The top attacker country was China with 2337 unique attackers (29.82%)
  • The top Exploit event was Shellcode with 50% of occurrences



Top Attacker by Country


CountryOccurrencesPercentage
China172129.21%
United States125221.25%
France4096.94%
Brazil3085.23%
Russian Federation2404.07%
India2333.95%
United Kingdom2183.70%
Canada2173.68%
Republic of Korea2123.60%
Germany1592.70%
Vietnam1352.29%
Netherlands1232.09%
Singapore1212.05%
Indonesia1121.90%
Taiwan1031.75%
Italy941.60%
Greece911.54%
Australia791.34%
Mexico651.10%


Top Cyber Attackers by Country April 22-28 2019



Threat Geo-location


Cyber Security Threat Geolocations April 22-28 2019



Top Attacking Hosts


HostOccurrences
193.36.117.23856
71.6.146.18521
74.82.47.512
95.58.194.1488
58.242.83.397




Top Network Attackers


CountryOrigin ASAnnouncementDescription
EstoniaAS206804193.36.117.0/24ESTNOC-GLOBAL
USAS1043971.6.128.0/17CariNet, INC
USAS693974.82.0.0/18Hurricane Electric LLC
KazakhstanAS919895.56.0.0/14JSC Kazakhtelecom
ChinaAS483758.242.0.0/15China Unicom AnHui province network




Top Event NIDS and Exploits


Top Event NIDS and Exploits April 22-28 2019



Top Alarms



Type of AlarmOccurrences
OTX Indicators of Compromise - PULSE210
Attack Tool Detected - Attack44
Bruteforce Authentication - SSH35
WebServer Attack - Attack34
Trojan Infection - IDS Event21
Database Attack - Stored Procedure Access - Attack9
Network Discovery - IDS Event7

                 
Comparison from last week

Type of AlarmOccurrences
OTX Indicators of Compromise - PULSE183
Attack Tool Detected - Attack40
Database Attack - Stored Procedure Access - Attack28
Network Discovery - Scan SSH27
Trojan Infection - IDS Event21
WebServer Attack - Attack8
Bruteforce Authentication - SSH7


 



CVE


This is a list of recent vulnerabilities for which exploits are available.

ID: CVE-2019-3799
Title: Spring Cloud Config Directory Traversal Vulnerability
Vendor: Spring

ID: CVE-2019-11387
Title: OWASP ModSecurity Core Rule Set (CRS) Remote Denial of Service Vulnerability
Vendor: OWASP 

ID: CVE-2019-1777
Title: Cisco Registered Envelope Service HTML Injection Vulnerability
Vendor: Cisco

ID: CVE-2019-1792
Title: Cisco Umbrella Cross Site Scripting Vulnerability
Vendor: Cisco

ID: CVE-2019-4012
Title: Multiple IBM Products SQL Injection Vulnerability
Vendor: IBM

ID: CVE-2019-10691
Title: Dovecot Denial of Service Vulnerability
Vendor: Dovecot

ID: CVE-2019-10893
Title: CentOS Web Panel HTML Injection Vulnerability
Vendor: CentOS

ID: CVE-2019-0859
Title: Microsoft Windows Win32k Local Privilege Escalation Vulnerability
Vendor: Microsoft

ID: CVE-2019-9208, CVE-2019-9209, CVE-2019-9214
Title: Wireshark Multiple Denial of Service Vulnerabilities
Vendor: Wireshark

ID: CVE-2019-11035, CVE-2019-11034
Title: PHP Multiple Heap Buffer Overflow Vulnerabilities
Vendor: PHP



Vulnerabilities


Ghostscript 'shading_param' Remote Code Execution Vulnerability
2019-04-26
securityfocus.com/bid/105178

Atlassian Confluence Server and Confluence Data Center Directory Traversal Vulnerability
2019-04-26
securityfocus.com/bid/108067

Linux Kernel CVE-2019-3900 Denial of Service Vulnerability
2019-04-25
securityfocus.com/bid/108076

Oracle WebLogic Server Deserialization Remote Command Execution Vulnerability
2019-04-25
securityfocus.com/bid/108074

Linux Kernel 'perf_event_open()' Function Local Information Disclosure Vulnerability
2019-04-24
securityfocus.com/bid/89937

ISC BIND CVE-2018-5743 Remote Denial of Service Vulnerability
2019-04-24
securityfocus.com/bid/108077

Pulse Connect Secure and Pulse Policy Secure Multiple Security Vulnerabilities
2019-04-24
securityfocus.com/bid/108073

ISC BIND CVE-2019-6467 Remote Denial of Service Vulnerability
2019-04-24
securityfocus.com/bid/108071

ISC BIND CVE-2019-6468 Remote Denial of Service Vulnerability
2019-04-24
securityfocus.com/bid/108070

GraphicsMagick CVE-2019-11505 Heap Buffer Overflow Vulnerability
2019-04-24
securityfocus.com/bid/108063

GraphicsMagick 'coders/xwd.c' Multiple Denial of Service Vulnerabilities
2019-04-24
securityfocus.com/bid/108055

Palo Alto Networks Global Protect Client CVE-2019-1573 Local Information Disclosure Vulnerability
2019-04-23
securityfocus.com/bid/107868

Redhat KeyCloak CVE-2019-3868 Session Hijacking Vulnerability
2019-04-23
securityfocus.com/bid/108061

Linux Kernel CVE-2019-11487 Multiple Denial of Service Vulnerabilities
2019-04-23
securityfocus.com/bid/108054

Fujifilm FCR Capsula X/Carbon X Denial of Service and Access Bypass Vulnerabilities
2019-04-23
securityfocus.com/bid/108052

Apache Zeppelin CVE-2017-12619 Session Fixation Vulnerability
2019-04-23
securityfocus.com/bid/108050

Rockwell Automation MicroLogix 1400 and CompactLogix 5370 Controllers Open Redirection Vulnerability
2019-04-23
securityfocus.com/bid/108049

Top Attacker Hosts April 22-28 2019
Details