TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

F5 Labs

Regional Threat Perspectives: Canada

2019-05-28 · Read original ↗

ATT&CK techniques detected

6 predictions
T1110Brute Force
87%
“secure sip 5061, microsoft samba port 445, ms sql port 1433, mysql port 3306, ssh port 22, microsoft rdp port 3389 and telnet port 23. web applications taking traffic on ports 80, 81, 8080, and 443 should be protected with a web application firewall, be continually scanned for we…”
T1071.001Web Protocols
62%
“regional threat perspectives : canada f5 labs, in conjunction with our partner baffin bay networks, researched attacks by geographic region to get a better understanding of the threat landscape region to region. we sought to understand if the global attack landscape was consisten…”
T1071.001Web Protocols
61%
“target regions of asns attacking canada top attacking ip addresses unlike the consistency seen between networks attacking canada, european, and australian systems, there was no consistency in the ip addresses used in those networks to attack. forty - eight of the top 50 ip addres…”
T1190Exploit Public-Facing Application
58%
“1, 2019 comparing ports targeted in canada versus the us, europe, or australia, canada was the only region where dns port 53 and the upnp port 37215 were on the top 20 targeted port list. the upnp port relates to huawei small office home office ( soho ) routers with a remote code…”
T1071.001Web Protocols
54%
“addresses targeting canadian systems are from ovh sas ’ s network. - the top attacked port was sip 5060, followed by microsoft smb, and then http port 80. sip was targeted 8. 3 times more than microsoft smb. top attacking countries canadian systems receive attacks from systems al…”
T1584.005Botnet
42%
“), launched 5. 5 times more attacks from systems in france and germany than host palace web solutions ( asn 133229 ), a hosting provider from the netherlands, which took second place. the top 4 attacking networks targeting canadian systems in this period were the same top 4 netwo…”

Summary

Europe was Canada’s primary source of attack traffic targeting VoIP systems and web applications.