Threat_Intelligence_Report

Trends



  • China is on top of the list with 835 unique attackers (21.4%)
  • Command and execution was the top exploit event of the week with 55% of occurrences



Top Attacker by Country


CountryNo. of AttackersPercentage
China83521.4%
United States74819.2%
Russian Federation3238.3%
Brazil2957.6%
France2456.3%
India1503.8%
Republic of Korea1473.8%
Ukraine1313.4%
Netherlands1213.1%
Germany1112.8%
United Kingdom1022.6%
Canada992.5%
Vietnam972.5%
Indonesia912.3%
Australia852.2%
Taiwan792.0%
Italy711.8%
Poland611.6%
Turkey561.4%


Top Cyber Attackers by Country  November 5-11 2018



Top Attacking Hosts


HostOccurrences
116.31.116.52132
89.248.172.207121
60.191.38.7787
206.189.201.14953
94.102.49.12334
94.102.63.2731
71.6.202.19827
118.67.248.12218




Top Alarms


AlarmNo. of Occurrences
Database Attack - Stored Process Access - Attack2516
Attack Tool Detected - Attack1267
WebServer Attack - Attack1163
OTX Indicators of Compromise - PULSE125
Bruteforce Authentication - SSH33
WebServer Attack - XSS5
Bruteforce Authentication - Windows Login1


Comparison from Previous Report


AlarmNo. of Occurrences
OTX Indicators of Compromise - PULSE116
Database Attack - Stored Process Access - Attack52
Bruteforce Authentication - SSH48
Attack Tool Detected - Attack25



Red Piranha - Open Threat Exchange


Pulses SubscribedIndicatorsLast UpdatedNumber of AlarmsNumber of Events
5,951882,5912018-11-12 14:00:476,2939,576




Vulnerabilities


Vuln: FreeBSD TCP Reassembly CVE-2018-6922 Denial Of Service Vulnerability
securityfocus.com/bid/105058

Vuln: Google Chrome V8 Out of Bounds Memory Access Vulnerability
securityfocus.com/bid/105879

Vuln: Multiple VMware Products CVE-2018-6982 Information Disclosure Vulnerability
securityfocus.com/bid/105882



Common Vulnerabilities and Exposures (CVE) 



CVE-2018-19185
An issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/asn1/ber_encoder.c. This is exploitable even after CVE-2018-18834 has been patched, with a different dataSetValue sequence than the CVE-2018-18834 attack vector.


CVE-2018-19192
An issue was discovered in XiaoCms 20141229. admin/index.php?c=content&a=add&catid=3 has CSRF, as demonstrated by entering news via the data[content] parameter.


CVE-2018-19193
An issue was discovered in XiaoCms 20141229. There is XSS via the largest input box on the "New news" screen.


CVE-2018-19194
An issue was discovered in XiaoCms 20141229. /admin/index.php?c=database allows full path disclosure in a "failed to open stream" error message.


CVE-2018-19195
An issue was discovered in XiaoCms 20141229. There is XSS related to the template\default\show_product.html file.

Details