Threat_Intelligence_Report

Trends



  • The top attacker country was United States with 2203 unique attackers (30.98%)
  • OTX Pulse was the Top Alarm of the week with 579 occurrences (93.2%)
  • The exploit event type on top this week was Cross Site Scripting with 71% occurrences.



Top Attacker by Country


CountryNo. of AttackersOccurrences
United States292427.30%
China251823.51%
Brazil5455.09%
Russian Federation5405.04%
France5334.98%
Indonesia5104.76%
United Kingdom4083.81%
Germany3673.43%
India3573.33%
Korea3112.90%
Canada2702.52%
Netherlands2632.46%
Italy1901.77%
Australia1891.76%
Singapore1791.67%
Vietnam1731.62%
Taiwan1661.55%
Poland1341.25%
Hong Kong1331.24%


Top Cyber Attackers by Country  Jan 21 -27 2019



Threat Geo-location


Cyber Security Threat Geolocations Jan 21-27 2019



Top Attacking Hosts


HostOccurrences
216.218.142.50568
203.166.220.2449
185.117.83.50426
158.69.221.198411




Top Alarms


AlarmNo. of Occurrences
OTX Indicators of Compromise - PULSE579
Bruteforce Authentication - SSH36
WebServer Attack - XSS4
Database Attack - Stored Procedure Access - Attack1
Attack Tool Detected - Attack1


Comparison from Previous Report


AlarmNo. of Occurrences
OTX Indicators of Compromise - PULSE275
Bruteforce Authentication - SSH4
Attack Tool Detected - Attack1




Top Network Attackers


Origin ASAnnouncementDescription
AS6939216.218.128.0/17Hurricane Electric LLC
AS10143115.70.31.0/24Exetel Broadband Users
AS63981203.166.220.0/22183 Electric Road, North Point, Hong Kong
AS203918185.117.83.0/24Securax Ltd
AS16276158.69.0.0/16OVH Hosting, Inc.



Exploit Event Types and Top Event NIDS



Top Attacker Hosts Jan 21-27 2019
Details