Red Piranha Threat Intelligence Report - Oct. 22-28 2017

TOP 10 ATTACKER (BY COUNTRY)


CHINA is our current top Attacker

1

TOP 10 ATTACKER (BY HOST)


2

Detailed Report on Suspicious hosts


Behavior: Scanning hosts

Activity: Continuously using different username password combination existing and non-existing usernames.

We have found following different types of events:

SSHD authentication failed.

Multiple SSHD authentication failures.

Multiple failed logins in a small period of time.

SSH insecure connection attempt (scan).

Failed Password

Invalid User

Input user-auth request invalid user

Type of attack: Bruteforce

Source IP Addresses:

5.101.40.10164.132.226.90203.249.22.182

71.6.202.19845.33.105.178198.98.57.43

77.72.82.18362.138.2.239103.79.143.60



TOP OTX Activity


otx



SIEM EVENTS


siem events



THREAT GEOLOCATION


geoloc



AV/IPS Rules


Remcos Rat Mail Spam rule

Microsoft DDE Exploit Rule

Details
Date Published
October 30, 2017