-->

whaust

2020年3月30日 星期一

Threat List from 2020/03/28 - 2020/03/30

Top 20 Threats




Top 100 Threats

---------------------------







NTP Amplification REQ_MON_GETLIST Request Found
NTP Amplification Denial-Of-Service Attack
Non-RFC Compliant DNS Traffic on Port 53/5353
Suspicious TLS Evasion Found
Telnet Authentication Failed
Windows SMB Login Attempt
Suspicious HTTP Evasion Found
MSSQL DB Login Authentication Failed
MSSQL Login failed for user 'sa' execution
SMB: User Password Brute Force Attempt
Telnet Authentication Brute Force Attempt
Microsoft SQL Server User Authentication Brute Force Attempt
Virus.mirai:ciqrgscslt.hopto.org
SIPVicious Scanner Detection
Microsoft Windows SMB Negotiate Request
Non-RFC Compliant TELNET Traffic on Port 23
Non-RFC Compliant FTP Traffic on Port 21
DNS ANY Request
Non-RFC Compliant DNS Traffic on Port 53/5353
NetBIOS null session
HTTP Non-RFC Compliant Request
Non-RFC Compliant HTTP Traffic on Port 80
Abnormal SSL traffic on port 443
Mirai.Gen Command And Control Traffic
Gafgyt.Gen Command And Control Traffic
Non-RFC Compliant SSL Traffic on Port 443
Non-RFC Compliant DNS Traffic on Port 53/5353
HTTP Unauthorized Error
POODLE Bites Vulnerability
Netis/Netcore Router Default Credential Remote Code Execution Vulnerability
Microsoft Communicator INVITE Flood Denial of Service Vulnerability
Suspicious HTTP Response Found
Non-RFC Compliant DNS Traffic on Port 53/5353
RPC Portmapper DUMP Request Detected
SSH2 Login Attempt
HTTP Non RFC-Compliant Response Found
SIP Register Request Attempt
HTTP WWW-Authentication Failed
Non-RFC Compliant TELNET Traffic on Port 23
Suspicious or malformed HTTP Referer field
HTTP Unauthorized Brute Force Attack
DNS ANY Queries Brute Force DOS Attack
Use of insecure SSLv3.0 Found in Server Response
JavaScript Obfuscation Detected
SIP Invalid Sent-by Address Found
Suspicious JavaScript Evasion Detected
Suspicious DNS Query (Virus.virut:formatmcl.gicp.net)
PHP DIESCAN Information Disclosure Vulnerability
Suspicious DNS Query (Virus.virut:formatmcl.gicp.net)
NetBIOS nbtstat query
GTPv1 Echo Request Message
Metasploit VxWorks WDB Agent Scanner Detection
Non-RFC Compliant TFTP Traffic on Port 69
Non-RFC Compliant HTTP Traffic on Port 80
DDoS.nitol:iamnull.no-ip.org
Malware.mdrop:xmr.pool.minergate.com
DNS Long qname Detection
JavaScript Obfuscation Detected
Non-RFC Compliant HTTP Traffic on Port 80
JavaScript Obfuscation Detected
HTTP: User Authentication Brute Force Attempt
dropper.Gen Command And Control Traffic
Non-RFC Compliant MS-DS-SMB Traffic on Port 445
Non-RFC Compliant MS-DS-SMB Traffic on Port 445
IP Address Disclosure Detection
SIP Malformed Request: Unknown URI Schemes in Header Fields
Non-RFC Compliant HTTP Traffic on Port 80
Non-RFC Compliant NTP Traffic on Port 123
SSH User Authentication Brute Force Attempt
HTTP OPTIONS Method
Backdoor.gafgyt:switchnets.net
Non-RFC Compliant MS-DS-SMB Traffic on Port 445
Non-RFC Compliant MS-DS-SMB Traffic on Port 445
ASUS/Netcore Router Default Credential Remote Code Execution Vulnerability
JavaScript Obfuscation Detected
Non-RFC Compliant HTTP Traffic on Port 80
Suspicious DNS Query (Virus.sality:alain.forgeot.free.fr)
SIP Register Message Brute Force Attack
TrojanDropper.delfsnif:0x0ss.sytes.net
XMRig Miner Command and Control Traffic Detection
Morto RDP Request Traffic
SSH2 Failed Login Attempt
Non-RFC Compliant SMTP Traffic on Port 25
Bifrose Command And Control Traffic
generic:bt.7081.com
generic:download.zzb5.cn
Non-RFC Compliant HTTP Traffic on Port 80
Failed Authentication Through Mail Protocol
Suspicious File Downloading Detection
Non-RFC Compliant DNS Traffic on Port 53/5353
flystudio.buqi C2 traffic
generic:deepsecu.com
Suspicious DNS Query (trojan.softcnapp:i.fahpvdxw.cn)
VBScript Obfuscation
Avtech Devices Unauthenticated Command Injection Vulnerability
Multiple CCTV-DVR Remote Command Injection Vulnerability
Ncrack RDP scan
Microsoft Windows SMB Remote Code Execution Vulnerability
generic:transmapp.com

沒有留言:

張貼留言

Popular