National/Industry/Cloud Exposure Report (NICER) 2020
Common Information
Type | Value |
---|---|
UUID | 62356582-7628-408f-9219-d3b954c5a8bd |
Fingerprint | c9e8e219e293dc419fccdfb1bec917baac0f85bc14b6384e2205659f32c1b7a0 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | Sept. 8, 2020, 1:07 p.m. |
Added to db | June 18, 2024, 10:07 a.m. |
Last updated | Aug. 31, 2024, 7:51 a.m. |
Headline | National/Industry/Cloud Exposure Report (NICER) 2020 |
Title | National/Industry/Cloud Exposure Report (NICER) 2020 |
Detected Hints/Tags/Attributes | 145/2/315 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Autonomous System Number | 1 | AS4809 |
|
Details | CVE | 1 | cve-2015-1419 |
|
Details | CVE | 1 | cve-2011-0762 |
|
Details | CVE | 1 | cve-2007-5962 |
|
Details | CVE | 6 | cve-2015-3306 |
|
Details | CVE | 1 | cve-2013-4359 |
|
Details | CVE | 1 | cve-2017-7418 |
|
Details | CVE | 1 | cve-2009-4593 |
|
Details | CVE | 1 | cve-2017-16892 |
|
Details | CVE | 63 | cve-2020-0796 |
|
Details | CVE | 1 | cve-2019-070855 |
|
Details | CVE | 197 | cve-2019-0708 |
|
Details | CVE | 161 | cve-2019-19781 |
|
Details | CVE | 2 | cve-2015-4335 |
|
Details | CVE | 2 | cve-2018-1000115 |
|
Details | CVE | 1 | cve-2017-8361 |
|
Details | CVE | 1 | cve-2013-2275 |
|
Details | CVE | 1 | cve-2012-1452 |
|
Details | CVE | 1 | cve-2016-1000107 |
|
Details | CVE | 1 | cve-2016-6440 |
|
Details | CVE | 1 | cve-2012-0038 |
|
Details | CVE | 1 | cve-2012-1835 |
|
Details | CVE | 1 | cve-2016-8827 |
|
Details | CVE | 1 | cve-2011-3868 |
|
Details | CVE | 1 | cve-2011-0607 |
|
Details | CVE | 1 | cve-2007-6740 |
|
Details | CVE | 1 | cve-2013-4564 |
|
Details | CVE | 1 | cve-2016-0948 |
|
Details | CVE | 1 | cve-2016-0956 |
|
Details | CVE | 1 | cve-2009-2047 |
|
Details | CVE | 1 | cve-2015-5670 |
|
Details | CVE | 3 | cve-2017-8577 |
|
Details | CVE | 1 | cve-2014-0134 |
|
Details | CVE | 1 | cve-2015-5355 |
|
Details | CVE | 1 | cve-2012-5932 |
|
Details | CVE | 1 | cve-2014-8089 |
|
Details | CVE | 1 | cve-2015-5685 |
|
Details | CVE | 1 | cve-2016-1000109 |
|
Details | CVE | 2 | cve-2015-5672 |
|
Details | CVE | 1 | cve-2016-5596 |
|
Details | CVE | 1 | cve-2016-5600 |
|
Details | CVE | 1 | cve-2016-4261 |
|
Details | CVE | 1 | cve-2016-4263 |
|
Details | CVE | 1 | cve-2016-4264 |
|
Details | CVE | 1 | cve-2016-4268 |
|
Details | Domain | 30 | www.iso.org |
|
Details | Domain | 2 | www.ntia.gov |
|
Details | Domain | 3 | www1.nyc.gov |
|
Details | Domain | 1 | restaurant-grades.page |
|
Details | Domain | 2 | www.wireguard.com |
|
Details | Domain | 31 | xkcd.com |
|
Details | Domain | 4127 | github.com |
|
Details | Domain | 1 | httparchive.org |
|
Details | Domain | 1 | httpparchive.org |
|
Details | Domain | 68 | tools.ietf.org |
|
Details | Domain | 33 | groups.google.com |
|
Details | Domain | 1 | mozilla.dev |
|
Details | Domain | 2 | www.chromestatus.com |
|
Details | Domain | 2 | www.alibabacloud.com |
|
Details | Domain | 72 | aws.amazon.com |
|
Details | Domain | 3 | www.ovh.co.uk |
|
Details | Domain | 281 | docs.microsoft.com |
|
Details | Domain | 14 | attackerkb.com |
|
Details | Domain | 1 | pomoc.home.pl |
|
Details | Domain | 2 | rsync.samba.org |
|
Details | Domain | 13 | blog.rapid7.com |
|
Details | Domain | 1 | us.ovhcloud.com |
|
Details | Domain | 1 | nameyouwant.myqnapcloud.com |
|
Details | Domain | 1 | post.office |
|
Details | Domain | 6 | ics-cert.kaspersky.com |
|
Details | Domain | 8 | www.digitalocean.com |
|
Details | Domain | 7 | www.law.cornell.edu |
|
Details | Domain | 1 | help.realvnc.com |
|
Details | Domain | 145 | www.us-cert.gov |
|
Details | Domain | 14 | www.citrix.com |
|
Details | Domain | 622 | en.wikipedia.org |
|
Details | Domain | 5 | mariadb.org |
|
Details | Domain | 1 | www.percona.com |
|
Details | Domain | 50 | cloud.google.com |
|
Details | Domain | 1 | unitedlayer.com |
|
Details | Domain | 14 | www.godaddy.com |
|
Details | Domain | 26 | azure.microsoft.com |
|
Details | Domain | 3 | www.ovh.com |
|
Details | Domain | 6 | www.guardicore.com |
|
Details | Domain | 1 | etcd.io |
|
Details | Domain | 4 | memcached.org |
|
Details | Domain | 1 | ja.wikipedia.org |
|
Details | Domain | 1 | intl.cloud.tencent.com |
|
Details | Domain | 5 | redis.io |
|
Details | Domain | 4 | antirez.com |
|
Details | Domain | 1 | docs.ovh.com |
|
Details | Domain | 52 | blog.cloudflare.com |
|
Details | Domain | 15 | www.shadowserver.org |
|
Details | Domain | 71 | kubernetes.io |
|
Details | Domain | 831 | example.com |
|
Details | Domain | 145 | threatpost.com |
|
Details | Domain | 17 | www.isc.org |
|
Details | Domain | 2 | cleanbrowsing.org |
|
Details | Domain | 7 | bgpview.io |
|
Details | Domain | 1 | www.fobul.net |
|
Details | Domain | 1 | www.iij.ad |
|
Details | Domain | 1 | developerers.google.com |
|
Details | Domain | 3 | pi-hole.net |
|
Details | Domain | 7 | www.nginx.com |
|
Details | Domain | 2 | getdnsapi.net |
|
Details | Domain | 1 | pkg.ssnet.ca |
|
Details | Domain | 1 | autotest.powerdns.com |
|
Details | Domain | 3 | www.powerdns.com |
|
Details | Domain | 3 | support.ntp.org |
|
Details | Domain | 7 | news.netcraft.com |
|
Details | Domain | 641 | nvd.nist.gov |
|
Details | Domain | 1 | tech.ltd |
|
Details | Domain | 1 | www.fidelix.com |
|
Details | Domain | 61 | www.netscout.com |
|
Details | Domain | 78 | securityaffairs.co |
|
Details | Domain | 113 | www.usenix.org |
|
Details | Domain | 454 | www.google.com |
|
Details | Domain | 29 | www.cvedetails.com |
|
Details | Domain | 63 | www.rapid7.com |
|
Details | Domain | 17 | cloudfront.net |
|
Details | Domain | 3 | opendata.rapid7.com |
|
Details | Domain | 1 | map.internetintel.oracle.com |
|
Details | Domain | 1 | svn.nmap.org |
|
Details | Domain | 8 | www.maxmind.com |
|
Details | Domain | 360 | attack.mitre.org |
|
Details | 1 | nobody@pkg.ssnet.ca |
||
Details | 1 | jenkins@autotest.powerdns.com |
||
Details | File | 33 | www.iso |
|
Details | File | 2 | iso-3166-country-codes.html |
|
Details | File | 1 | ssh_banners.xml |
|
Details | File | 1 | dev.pl |
|
Details | File | 1 | 92048.htm |
|
Details | File | 1 | 92046.htm |
|
Details | File | 2 | ftp.xml |
|
Details | File | 1 | ftp_banners.xml |
|
Details | File | 1 | ポーランドではhome.pl |
|
Details | File | 3 | home.pl |
|
Details | File | 1 | 54016.htm |
|
Details | File | 1 | csa%20sandworm%20actors%20exploiting%20vulnerability%20in%20exim%20transfer%20agent%2020200528.pdf |
|
Details | File | 1 | citrix-workspace-on-aws.html |
|
Details | File | 1 | sql_server.xml |
|
Details | File | 1 | draft-huitema-quic-dnsoquic-06.html |
|
Details | File | 1 | fbi-cisa-e-skiming-atacks.html |
|
Details | File | 3 | statistics.html |
|
Details | File | 1 | top-50-products.php |
|
Details | File | 2 | http_servers.xml |
|
Details | File | 15 | www.max |
|
Details | Github username | 46 | rapid7 |
|
Details | Github username | 1 | microsoftarchive |
|
Details | Github username | 3 | zmap |
|
Details | IPv4 | 1 | 4.93.0.4 |
|
Details | IPv4 | 18 | 10.1.1.1 |
|
Details | IPv4 | 142 | 192.168.0.1 |
|
Details | IPv4 | 1 | 52.85.146.50 |
|
Details | MITRE ATT&CK Techniques | 60 | T1043 |
|
Details | MITRE ATT&CK Techniques | 23 | T1094 |
|
Details | MITRE ATT&CK Techniques | 1 | T1320 |
|
Details | MITRE ATT&CK Techniques | 1 | T1382 |
|
Details | MITRE ATT&CK Techniques | 1 | T1324 |
|
Details | MITRE ATT&CK Techniques | 2 | T1311 |
|
Details | MITRE ATT&CK Techniques | 31 | T1499 |
|
Details | MITRE ATT&CK Techniques | 92 | T1048 |
|
Details | MITRE ATT&CK Techniques | 422 | T1041 |
|
Details | MITRE ATT&CK Techniques | 245 | T1203 |
|
Details | MITRE ATT&CK Techniques | 109 | T1210 |
|
Details | MITRE ATT&CK Techniques | 191 | T1133 |
|
Details | MITRE ATT&CK Techniques | 7 | T1187 |
|
Details | MITRE ATT&CK Techniques | 58 | T1498 |
|
Details | MITRE ATT&CK Techniques | 176 | T1135 |
|
Details | MITRE ATT&CK Techniques | 4 | T1145 |
|
Details | MITRE ATT&CK Techniques | 10 | T1108 |
|
Details | MITRE ATT&CK Techniques | 141 | T1219 |
|
Details | MITRE ATT&CK Techniques | 13 | T1076 |
|
Details | MITRE ATT&CK Techniques | 492 | T1105 |
|
Details | MITRE ATT&CK Techniques | 159 | T1021 |
|
Details | MITRE ATT&CK Techniques | 67 | T1505 |
|
Details | MITRE ATT&CK Techniques | 1 | T1340 |
|
Details | MITRE ATT&CK Techniques | 1 | T1184 |
|
Details | MITRE ATT&CK Techniques | 444 | T1071 |
|
Details | MITRE ATT&CK Techniques | 1006 | T1082 |
|
Details | MITRE ATT&CK Techniques | 245 | T1016 |
|
Details | MITRE ATT&CK Techniques | 50 | T1072 |
|
Details | MITRE ATT&CK Techniques | 306 | T1078 |
|
Details | Url | 2 | https://www.iso.org/iso-3166-country-codes.html |
|
Details | Url | 1 | https://www.ntia.gov/sbom |
|
Details | Url | 1 | https://www1.nyc.gov/site/doh/services/restaurant-grades.page |
|
Details | Url | 1 | https://www.wireguard.com |
|
Details | Url | 1 | https://xkcd.com/2176 |
|
Details | Url | 1 | https://github.com/rapid7/recog/blob/master/xml/ssh_banners.xml |
|
Details | Url | 1 | https://httparchive.org/reports/page-weight?start=latest&view=list |
|
Details | Url | 1 | https://tools.ietf.org/html/rfc354 |
|
Details | Url | 1 | https://groups.google.com/forum/#!msg/mozilla.dev.platform/fqczut9ay_o/jt4dlrdjawaj |
|
Details | Url | 1 | https://www.chromestatus.com/feature/6246151319715840 |
|
Details | Url | 1 | https://aws.amazon.com/jp/blogs/news/new-aws-transfer-for-ftp-and-ftps-in-addition-to-existing-sftp |
|
Details | Url | 1 | https://www.ovh.co.uk/web-hosting/ftp.xml |
|
Details | Url | 1 | https://docs.microsoft.com/ja/azure/app-service/deploy-ftp |
|
Details | Url | 1 | https://tools.ietf.org/html/rfc1635 |
|
Details | Url | 1 | https://github.com/rapid7/recog/blob/master/xml |
|
Details | Url | 1 | https://attackerkb.com/topics/slwqqwdczx/cve-2015-1419 |
|
Details | Url | 1 | https://attackerkb.com/topics/pmufmyuita/cve-2011-0762 |
|
Details | Url | 1 | https://attackerkb.com/topics/nqtiyfr916/cve-2007-5962 |
|
Details | Url | 1 | https://attackerkb.com/topics/1qhi2ndx91/cve-2015-3306 |
|
Details | Url | 1 | https://attackerkb.com/topics/ydjqlthxih/cve-2013-4359 |
|
Details | Url | 1 | https://attackerkb.com/topics/g2r203lfxr/cve-2017-7418 |
|
Details | Url | 1 | https://attackerkb.com/topics/dybjggfggi/cve-2009-4593 |
|
Details | Url | 1 | https://attackerkb.com/topics/shhl7hn1qt/cve-2017-16892 |
|
Details | Url | 1 | https://tools.ietf.org/html/rfc2228 |
|
Details | Url | 1 | https://pomoc.home.pl/baza-wiedzy/bezpieczne-polaczenie-ftps-z-serwerem-w-home-pl |
|
Details | Url | 1 | https://docs.microsoft.com/ja-jp/azure/app-service/deploy-ftp |
|
Details | Url | 1 | https://attackerkb.com/topics/2lcxe3epaz/cve-2020-0796---smbghostをご覧ください |
|
Details | Url | 1 | https://tools.ietf.org/html/rfc5781 |
|
Details | Url | 1 | https://rsync.samba.org/tech_report |
|
Details | Url | 1 | https://blog.rapid7.com/2018/12/21/rsunk-your-battleship-an-ocean-of-data-exposed-through-rsync |
|
Details | Url | 1 | https://www.alibabacloud.com/help/ja/doc-detail/54016.htm |
|
Details | Url | 1 | https://www.alibabacloud.com/blog/speeding-up-network-file-transfers-with- |
|
Details | Url | 1 | https://us.ovhcloud.com/public-cloud/cloud-archive |
|
Details | Url | 1 | https://medium.com/bugbountywriteup/qnap-pre-auth-root-rce-affecting-450k-devices-on-the-internet-d55488d28a05 |
|
Details | Url | 1 | https://media.defense.gov/2020/may/28/2002306626/-1/-1/0/csa%20sandworm%20actors%20exploiting%20vulnerability%20in%20exim%20transfer%20agent%2020200528.pdf |
|
Details | Url | 2 | https://tools.ietf.org/html/rfc6143 |
|
Details | Url | 1 | https://ics-cert.kaspersky.com/reports/2019/11/22/vnc-vulnerability-research/#_toc22133279 |
|
Details | Url | 1 | https://support.us.ovhcloud.com/hc/en-us/articles/360002208690-how-to-access-a-public-cloud-instance-via-vnc |
|
Details | Url | 1 | https://aws.amazon.com/premiumsupport/knowledge-center/ec2-linux-2-install-gui |
|
Details | Url | 1 | https://www.alibabacloud.com/blog/how-to-install-and-configure-vnc-on-an-alibaba-cloud-ecs-instance_595135 |
|
Details | Url | 1 | https://www.digitalocean.com/community/tutorial_collections/47 |
|
Details | Url | 1 | https://www.law.cornell.edu/uscode/text/18/1030 |
|
Details | Url | 1 | https://attackerkb.com/search?q=libvnc |
|
Details | Url | 1 | https://attackerkb.com/search?q=tightvnc |
|
Details | Url | 1 | https://attackerkb.com/search?q=turbovnc |
|
Details | Url | 1 | https://attackerkb.com/search?q=ultravnc |
|
Details | Url | 1 | https://help.realvnc.com/hc/en-us/articles/360002250077-introduction-to-multi-factor-authentication- |
|
Details | Url | 1 | https://attackerkb.com/topicsl/cve-2019-0708 |
|
Details | Url | 1 | https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-rdpbcgr/5073f4ed-1e93-45e1-b039-6e30c385867c |
|
Details | Url | 1 | https://blog.rapid7.com/2020/01/17/active-exploitation-of-citrix-netscaler-cve-2019-19781-what-you-need-to-know |
|
Details | Url | 1 | https://github.com/rapid7/recog/search?q=citrix&unscoped_q=citrix |
|
Details | Url | 1 | https://attackerkb.com/topics/x22buzozyj/cve-2019-19781 |
|
Details | Url | 4 | https://www.us-cert.gov/ncas/alerts/aa20-031a |
|
Details | Url | 1 | https://www.citrix.com/global-partners/amazon-web-services/citrix-workspace-on-aws.html |
|
Details | Url | 1 | https://en.wikipedia.org/wiki/sabre_ |
|
Details | Url | 2 | https://mariadb.org |
|
Details | Url | 1 | https://www.percona.com |
|
Details | Url | 1 | https://cloud.google.com/sql |
|
Details | Url | 1 | https://www.alibabacloud.com/product/apsaradb-for-rds-mysql |
|
Details | Url | 1 | https://aws.amazon.com/jp/rds/mysql |
|
Details | Url | 1 | https://www.ovh.co.uk/cloud-databases |
|
Details | Url | 1 | https://unitedlayer.com |
|
Details | Url | 5 | https://www.godaddy.com |
|
Details | Url | 1 | https://news.sophos.com/en-us/2019/05/24/gandcrab-spreading-via-directed-attacks-against-mysql-servers |
|
Details | Url | 1 | https://azure.microsoft.com/ja-jp/services/sql-database |
|
Details | Url | 1 | https://www.ovh.com/world/dolvated-server/distributions/sql_server.xml |
|
Details | Url | 1 | https://aws.amazon.com/sql |
|
Details | Url | 1 | https://www.guardicore.com/2020/04/vollgar-ms-sql-servers-under-attack |
|
Details | Url | 1 | https://www.scmagazine.com/home/security-news/gaming/skip-2-0-backdoor-malware-provides-magic-password-to-access-mssql-accounts |
|
Details | Url | 1 | https://etcd.io |
|
Details | Url | 1 | https://memcached.org |
|
Details | Url | 1 | https://ja.wikipedia.org/wiki/nosql |
|
Details | Url | 1 | https://intl.cloud.tencent.com/product/crs |
|
Details | Url | 1 | https://azure.microsoft.com/ja/services/cache |
|
Details | Url | 1 | https://aws.amazon.com/jp/redis |
|
Details | Url | 1 | https://aws.amazon.com/jp/elasticache |
|
Details | Url | 1 | http://attackerkb.com/cve-2015-4335 |
|
Details | Url | 1 | https://redis.io/topics/quickstart#: |
|
Details | Url | 4 | http://antirez.com/news/96 |
|
Details | Url | 1 | https://github.com/microsoftarchive/redis/releases |
|
Details | Url | 1 | https://blog.trendmicro.com/trendlabs-security-intelligence/exposed-redis-instances-abused-for-remote-code-execution-cryptocurrency-mining |
|
Details | Url | 1 | https://www.alibabacloud.com/product/apsaradb-for-memcache |
|
Details | Url | 1 | https://docs.ovh.com/gb/en/dedicated/securing-server-with-memcached-service |
|
Details | Url | 1 | https://blog.rapid7.com/2018/02/27/the-flip-side-of-memcrashed |
|
Details | Url | 1 | https://attackerkb.com/topics/km2ux55z24/cve-2018-1000115-major-amplections-ddos-vulnerability |
|
Details | Url | 1 | https://blog.cloudflare.com/memcrashed-major-ampsification-attacks-from-port-11211 |
|
Details | Url | 2 | https://www.shadowserver.org |
|
Details | Url | 1 | https://kubernetes.io |
|
Details | Url | 1 | https://tools.ietf.org/html/rfc1034 |
|
Details | Url | 1 | https://www.itworldcanada.com/article/why-ovh-opened-the-worlds-largest-datacentre-in-the-great-white-north/387358 |
|
Details | Url | 2 | https://www.us-cert.gov/ncas/alerts/ta13-088a |
|
Details | Url | 1 | https://threatpost.com/verizon-data-breach-report-dos-skyrockets-espionage-dips/155843 |
|
Details | Url | 1 | https://attackerkb.com/search?q=nxnsattack |
|
Details | Url | 1 | https://www.isc.org/presentations |
|
Details | Url | 1 | https://www.spamhaus.org/news/article/797/the-current-state-of-domain-hijacking-and-a-specific-look-at-the-ongoing-issues-at-godaddy |
|
Details | Url | 1 | https://tools.ietf.org/html/rfc7858 |
|
Details | Url | 2 | https://tools.ietf.org/html/rfc8484 |
|
Details | Url | 1 | https://tools.ietf.org/id/draft-huitema-quic-dnsoquic-06.html |
|
Details | Url | 1 | https://tools.ietf.org/html/rfc2549 |
|
Details | Url | 1 | https://en.wikipedia.org/wiki/daniel_b._cid |
|
Details | Url | 1 | https://cleanbrowsing.org |
|
Details | Url | 1 | https://bgpview.io/asn/205157 |
|
Details | Url | 1 | http://www.fobul.net |
|
Details | Url | 1 | https://www.iij.ad/jp/ja |
|
Details | Url | 1 | https://developerers.google.com/speed/public-dns/docs/dns-over-tls |
|
Details | Url | 2 | https://pi-hole.net |
|
Details | Url | 1 | https://www.nginx.com/blog/ussion-nginx-as-doh-gateway |
|
Details | Url | 1 | https://getdnsapi.net |
|
Details | Url | 2 | https://www.powerdns.com |
|
Details | Url | 1 | https://tools.ietf.org/html/rfc5905 |
|
Details | Url | 1 | http://support.ntp.org/bin/view/main/webhome |
|
Details | Url | 1 | https://news.netcraft.com/archives/category/web-server-survey |
|
Details | Url | 1 | https://en.wikipedia.org/wiki/gopher_ |
|
Details | Url | 1 | https://tools.ietf.org/html/draft-tsvwg-quic-protocol-02 |
|
Details | Url | 1 | https://nvd.nist.gov/products/cpe |
|
Details | Url | 1 | https://www.fidelix.com/building-automation |
|
Details | Url | 1 | https://www.netscout.com/theatreport |
|
Details | Url | 1 | https://securityaffairs.co/wordpress/92899/cyber-crime/fbi-cisa-e-skiming-atacks.html |
|
Details | Url | 1 | https://www.darkreading.com/vulnerabilities---threats/eternalblue-longevity-underscores-patching-problem/d/d-id/1337233 |
|
Details | Url | 1 | https://ja.wikipedia.org/wiki/ipv4によると |
|
Details | Url | 1 | https://www.usenix.org/conference/woot14/workshop-program/presentation/adrian |
|
Details | Url | 1 | https://www.google.com/intl/en/ipv6/statistics.html |
|
Details | Url | 1 | https://www.cvedetails.com/top-50-products.php |
|
Details | Url | 3 | https://opendata.rapid7.com |
|
Details | Url | 1 | https://github.com/rapid7/recog |
|
Details | Url | 1 | https://github.com/rapid7/recog/blob/master/xml/http_servers.xml#l176 |
|
Details | Url | 1 | https://github.com/zmap/zmap |
|
Details | Url | 1 | https://map.internetintel.oracle.com |
|
Details | Url | 1 | https://www.rapid7.com/ja/info/national-exposure-index |
|
Details | Url | 1 | https://svn.nmap.org/nmap/nmap-services |
|
Details | Url | 1 | https://www.maxmind.com/ja/home |
|
Details | Url | 57 | https://attack.mitre.org |