National/Industry/Cloud Exposure Report (NICER) 2020
Image Description
Common Information
Type Value
UUID 62356582-7628-408f-9219-d3b954c5a8bd
Fingerprint c9e8e219e293dc419fccdfb1bec917baac0f85bc14b6384e2205659f32c1b7a0
Analysis status DONE
Considered CTI value 2
Text language
Published Sept. 8, 2020, 1:07 p.m.
Added to db June 18, 2024, 10:07 a.m.
Last updated Aug. 31, 2024, 7:51 a.m.
Headline National/Industry/Cloud Exposure Report (NICER) 2020
Title National/Industry/Cloud Exposure Report (NICER) 2020
Detected Hints/Tags/Attributes 145/2/315
Attributes
Details Type #Events CTI Value
Details Autonomous System Number 1
AS4809
Details CVE 1
cve-2015-1419
Details CVE 1
cve-2011-0762
Details CVE 1
cve-2007-5962
Details CVE 6
cve-2015-3306
Details CVE 1
cve-2013-4359
Details CVE 1
cve-2017-7418
Details CVE 1
cve-2009-4593
Details CVE 1
cve-2017-16892
Details CVE 63
cve-2020-0796
Details CVE 1
cve-2019-070855
Details CVE 197
cve-2019-0708
Details CVE 161
cve-2019-19781
Details CVE 2
cve-2015-4335
Details CVE 2
cve-2018-1000115
Details CVE 1
cve-2017-8361
Details CVE 1
cve-2013-2275
Details CVE 1
cve-2012-1452
Details CVE 1
cve-2016-1000107
Details CVE 1
cve-2016-6440
Details CVE 1
cve-2012-0038
Details CVE 1
cve-2012-1835
Details CVE 1
cve-2016-8827
Details CVE 1
cve-2011-3868
Details CVE 1
cve-2011-0607
Details CVE 1
cve-2007-6740
Details CVE 1
cve-2013-4564
Details CVE 1
cve-2016-0948
Details CVE 1
cve-2016-0956
Details CVE 1
cve-2009-2047
Details CVE 1
cve-2015-5670
Details CVE 3
cve-2017-8577
Details CVE 1
cve-2014-0134
Details CVE 1
cve-2015-5355
Details CVE 1
cve-2012-5932
Details CVE 1
cve-2014-8089
Details CVE 1
cve-2015-5685
Details CVE 1
cve-2016-1000109
Details CVE 2
cve-2015-5672
Details CVE 1
cve-2016-5596
Details CVE 1
cve-2016-5600
Details CVE 1
cve-2016-4261
Details CVE 1
cve-2016-4263
Details CVE 1
cve-2016-4264
Details CVE 1
cve-2016-4268
Details Domain 30
www.iso.org
Details Domain 2
www.ntia.gov
Details Domain 3
www1.nyc.gov
Details Domain 1
restaurant-grades.page
Details Domain 2
www.wireguard.com
Details Domain 31
xkcd.com
Details Domain 4127
github.com
Details Domain 1
httparchive.org
Details Domain 1
httpparchive.org
Details Domain 68
tools.ietf.org
Details Domain 33
groups.google.com
Details Domain 1
mozilla.dev
Details Domain 2
www.chromestatus.com
Details Domain 2
www.alibabacloud.com
Details Domain 72
aws.amazon.com
Details Domain 3
www.ovh.co.uk
Details Domain 281
docs.microsoft.com
Details Domain 14
attackerkb.com
Details Domain 1
pomoc.home.pl
Details Domain 2
rsync.samba.org
Details Domain 13
blog.rapid7.com
Details Domain 1
us.ovhcloud.com
Details Domain 1
nameyouwant.myqnapcloud.com
Details Domain 1
post.office
Details Domain 6
ics-cert.kaspersky.com
Details Domain 8
www.digitalocean.com
Details Domain 7
www.law.cornell.edu
Details Domain 1
help.realvnc.com
Details Domain 145
www.us-cert.gov
Details Domain 14
www.citrix.com
Details Domain 622
en.wikipedia.org
Details Domain 5
mariadb.org
Details Domain 1
www.percona.com
Details Domain 50
cloud.google.com
Details Domain 1
unitedlayer.com
Details Domain 14
www.godaddy.com
Details Domain 26
azure.microsoft.com
Details Domain 3
www.ovh.com
Details Domain 6
www.guardicore.com
Details Domain 1
etcd.io
Details Domain 4
memcached.org
Details Domain 1
ja.wikipedia.org
Details Domain 1
intl.cloud.tencent.com
Details Domain 5
redis.io
Details Domain 4
antirez.com
Details Domain 1
docs.ovh.com
Details Domain 52
blog.cloudflare.com
Details Domain 15
www.shadowserver.org
Details Domain 71
kubernetes.io
Details Domain 831
example.com
Details Domain 145
threatpost.com
Details Domain 17
www.isc.org
Details Domain 2
cleanbrowsing.org
Details Domain 7
bgpview.io
Details Domain 1
www.fobul.net
Details Domain 1
www.iij.ad
Details Domain 1
developerers.google.com
Details Domain 3
pi-hole.net
Details Domain 7
www.nginx.com
Details Domain 2
getdnsapi.net
Details Domain 1
pkg.ssnet.ca
Details Domain 1
autotest.powerdns.com
Details Domain 3
www.powerdns.com
Details Domain 3
support.ntp.org
Details Domain 7
news.netcraft.com
Details Domain 641
nvd.nist.gov
Details Domain 1
tech.ltd
Details Domain 1
www.fidelix.com
Details Domain 61
www.netscout.com
Details Domain 78
securityaffairs.co
Details Domain 113
www.usenix.org
Details Domain 454
www.google.com
Details Domain 29
www.cvedetails.com
Details Domain 63
www.rapid7.com
Details Domain 17
cloudfront.net
Details Domain 3
opendata.rapid7.com
Details Domain 1
map.internetintel.oracle.com
Details Domain 1
svn.nmap.org
Details Domain 8
www.maxmind.com
Details Domain 360
attack.mitre.org
Details Email 1
nobody@pkg.ssnet.ca
Details Email 1
jenkins@autotest.powerdns.com
Details File 33
www.iso
Details File 2
iso-3166-country-codes.html
Details File 1
ssh_banners.xml
Details File 1
dev.pl
Details File 1
92048.htm
Details File 1
92046.htm
Details File 2
ftp.xml
Details File 1
ftp_banners.xml
Details File 1
ポーランドではhome.pl
Details File 3
home.pl
Details File 1
54016.htm
Details File 1
csa%20sandworm%20actors%20exploiting%20vulnerability%20in%20exim%20transfer%20agent%2020200528.pdf
Details File 1
citrix-workspace-on-aws.html
Details File 1
sql_server.xml
Details File 1
draft-huitema-quic-dnsoquic-06.html
Details File 1
fbi-cisa-e-skiming-atacks.html
Details File 3
statistics.html
Details File 1
top-50-products.php
Details File 2
http_servers.xml
Details File 15
www.max
Details Github username 46
rapid7
Details Github username 1
microsoftarchive
Details Github username 3
zmap
Details IPv4 1
4.93.0.4
Details IPv4 18
10.1.1.1
Details IPv4 142
192.168.0.1
Details IPv4 1
52.85.146.50
Details MITRE ATT&CK Techniques 60
T1043
Details MITRE ATT&CK Techniques 23
T1094
Details MITRE ATT&CK Techniques 1
T1320
Details MITRE ATT&CK Techniques 1
T1382
Details MITRE ATT&CK Techniques 1
T1324
Details MITRE ATT&CK Techniques 2
T1311
Details MITRE ATT&CK Techniques 31
T1499
Details MITRE ATT&CK Techniques 92
T1048
Details MITRE ATT&CK Techniques 422
T1041
Details MITRE ATT&CK Techniques 245
T1203
Details MITRE ATT&CK Techniques 109
T1210
Details MITRE ATT&CK Techniques 191
T1133
Details MITRE ATT&CK Techniques 7
T1187
Details MITRE ATT&CK Techniques 58
T1498
Details MITRE ATT&CK Techniques 176
T1135
Details MITRE ATT&CK Techniques 4
T1145
Details MITRE ATT&CK Techniques 10
T1108
Details MITRE ATT&CK Techniques 141
T1219
Details MITRE ATT&CK Techniques 13
T1076
Details MITRE ATT&CK Techniques 492
T1105
Details MITRE ATT&CK Techniques 159
T1021
Details MITRE ATT&CK Techniques 67
T1505
Details MITRE ATT&CK Techniques 1
T1340
Details MITRE ATT&CK Techniques 1
T1184
Details MITRE ATT&CK Techniques 444
T1071
Details MITRE ATT&CK Techniques 1006
T1082
Details MITRE ATT&CK Techniques 245
T1016
Details MITRE ATT&CK Techniques 50
T1072
Details MITRE ATT&CK Techniques 306
T1078
Details Url 2
https://www.iso.org/iso-3166-country-codes.html
Details Url 1
https://www.ntia.gov/sbom
Details Url 1
https://www1.nyc.gov/site/doh/services/restaurant-grades.page
Details Url 1
https://www.wireguard.com
Details Url 1
https://xkcd.com/2176
Details Url 1
https://github.com/rapid7/recog/blob/master/xml/ssh_banners.xml
Details Url 1
https://httparchive.org/reports/page-weight?start=latest&view=list
Details Url 1
https://tools.ietf.org/html/rfc354
Details Url 1
https://groups.google.com/forum/#!msg/mozilla.dev.platform/fqczut9ay_o/jt4dlrdjawaj
Details Url 1
https://www.chromestatus.com/feature/6246151319715840
Details Url 1
https://aws.amazon.com/jp/blogs/news/new-aws-transfer-for-ftp-and-ftps-in-addition-to-existing-sftp
Details Url 1
https://www.ovh.co.uk/web-hosting/ftp.xml
Details Url 1
https://docs.microsoft.com/ja/azure/app-service/deploy-ftp
Details Url 1
https://tools.ietf.org/html/rfc1635
Details Url 1
https://github.com/rapid7/recog/blob/master/xml
Details Url 1
https://attackerkb.com/topics/slwqqwdczx/cve-2015-1419
Details Url 1
https://attackerkb.com/topics/pmufmyuita/cve-2011-0762
Details Url 1
https://attackerkb.com/topics/nqtiyfr916/cve-2007-5962
Details Url 1
https://attackerkb.com/topics/1qhi2ndx91/cve-2015-3306
Details Url 1
https://attackerkb.com/topics/ydjqlthxih/cve-2013-4359
Details Url 1
https://attackerkb.com/topics/g2r203lfxr/cve-2017-7418
Details Url 1
https://attackerkb.com/topics/dybjggfggi/cve-2009-4593
Details Url 1
https://attackerkb.com/topics/shhl7hn1qt/cve-2017-16892
Details Url 1
https://tools.ietf.org/html/rfc2228
Details Url 1
https://pomoc.home.pl/baza-wiedzy/bezpieczne-polaczenie-ftps-z-serwerem-w-home-pl
Details Url 1
https://docs.microsoft.com/ja-jp/azure/app-service/deploy-ftp
Details Url 1
https://attackerkb.com/topics/2lcxe3epaz/cve-2020-0796---smbghostをご覧ください
Details Url 1
https://tools.ietf.org/html/rfc5781
Details Url 1
https://rsync.samba.org/tech_report
Details Url 1
https://blog.rapid7.com/2018/12/21/rsunk-your-battleship-an-ocean-of-data-exposed-through-rsync
Details Url 1
https://www.alibabacloud.com/help/ja/doc-detail/54016.htm
Details Url 1
https://www.alibabacloud.com/blog/speeding-up-network-file-transfers-with-
Details Url 1
https://us.ovhcloud.com/public-cloud/cloud-archive
Details Url 1
https://medium.com/bugbountywriteup/qnap-pre-auth-root-rce-affecting-450k-devices-on-the-internet-d55488d28a05
Details Url 1
https://media.defense.gov/2020/may/28/2002306626/-1/-1/0/csa%20sandworm%20actors%20exploiting%20vulnerability%20in%20exim%20transfer%20agent%2020200528.pdf
Details Url 2
https://tools.ietf.org/html/rfc6143
Details Url 1
https://ics-cert.kaspersky.com/reports/2019/11/22/vnc-vulnerability-research/#_toc22133279
Details Url 1
https://support.us.ovhcloud.com/hc/en-us/articles/360002208690-how-to-access-a-public-cloud-instance-via-vnc
Details Url 1
https://aws.amazon.com/premiumsupport/knowledge-center/ec2-linux-2-install-gui
Details Url 1
https://www.alibabacloud.com/blog/how-to-install-and-configure-vnc-on-an-alibaba-cloud-ecs-instance_595135
Details Url 1
https://www.digitalocean.com/community/tutorial_collections/47
Details Url 1
https://www.law.cornell.edu/uscode/text/18/1030
Details Url 1
https://attackerkb.com/search?q=libvnc
Details Url 1
https://attackerkb.com/search?q=tightvnc
Details Url 1
https://attackerkb.com/search?q=turbovnc
Details Url 1
https://attackerkb.com/search?q=ultravnc
Details Url 1
https://help.realvnc.com/hc/en-us/articles/360002250077-introduction-to-multi-factor-authentication-
Details Url 1
https://attackerkb.com/topicsl/cve-2019-0708
Details Url 1
https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-rdpbcgr/5073f4ed-1e93-45e1-b039-6e30c385867c
Details Url 1
https://blog.rapid7.com/2020/01/17/active-exploitation-of-citrix-netscaler-cve-2019-19781-what-you-need-to-know
Details Url 1
https://github.com/rapid7/recog/search?q=citrix&unscoped_q=citrix
Details Url 1
https://attackerkb.com/topics/x22buzozyj/cve-2019-19781
Details Url 4
https://www.us-cert.gov/ncas/alerts/aa20-031a
Details Url 1
https://www.citrix.com/global-partners/amazon-web-services/citrix-workspace-on-aws.html
Details Url 1
https://en.wikipedia.org/wiki/sabre_
Details Url 2
https://mariadb.org
Details Url 1
https://www.percona.com
Details Url 1
https://cloud.google.com/sql
Details Url 1
https://www.alibabacloud.com/product/apsaradb-for-rds-mysql
Details Url 1
https://aws.amazon.com/jp/rds/mysql
Details Url 1
https://www.ovh.co.uk/cloud-databases
Details Url 1
https://unitedlayer.com
Details Url 5
https://www.godaddy.com
Details Url 1
https://news.sophos.com/en-us/2019/05/24/gandcrab-spreading-via-directed-attacks-against-mysql-servers
Details Url 1
https://azure.microsoft.com/ja-jp/services/sql-database
Details Url 1
https://www.ovh.com/world/dolvated-server/distributions/sql_server.xml
Details Url 1
https://aws.amazon.com/sql
Details Url 1
https://www.guardicore.com/2020/04/vollgar-ms-sql-servers-under-attack
Details Url 1
https://www.scmagazine.com/home/security-news/gaming/skip-2-0-backdoor-malware-provides-magic-password-to-access-mssql-accounts
Details Url 1
https://etcd.io
Details Url 1
https://memcached.org
Details Url 1
https://ja.wikipedia.org/wiki/nosql
Details Url 1
https://intl.cloud.tencent.com/product/crs
Details Url 1
https://azure.microsoft.com/ja/services/cache
Details Url 1
https://aws.amazon.com/jp/redis
Details Url 1
https://aws.amazon.com/jp/elasticache
Details Url 1
http://attackerkb.com/cve-2015-4335
Details Url 1
https://redis.io/topics/quickstart#:
Details Url 4
http://antirez.com/news/96
Details Url 1
https://github.com/microsoftarchive/redis/releases
Details Url 1
https://blog.trendmicro.com/trendlabs-security-intelligence/exposed-redis-instances-abused-for-remote-code-execution-cryptocurrency-mining
Details Url 1
https://www.alibabacloud.com/product/apsaradb-for-memcache
Details Url 1
https://docs.ovh.com/gb/en/dedicated/securing-server-with-memcached-service
Details Url 1
https://blog.rapid7.com/2018/02/27/the-flip-side-of-memcrashed
Details Url 1
https://attackerkb.com/topics/km2ux55z24/cve-2018-1000115-major-amplections-ddos-vulnerability
Details Url 1
https://blog.cloudflare.com/memcrashed-major-ampsification-attacks-from-port-11211
Details Url 2
https://www.shadowserver.org
Details Url 1
https://kubernetes.io
Details Url 1
https://tools.ietf.org/html/rfc1034
Details Url 1
https://www.itworldcanada.com/article/why-ovh-opened-the-worlds-largest-datacentre-in-the-great-white-north/387358
Details Url 2
https://www.us-cert.gov/ncas/alerts/ta13-088a
Details Url 1
https://threatpost.com/verizon-data-breach-report-dos-skyrockets-espionage-dips/155843
Details Url 1
https://attackerkb.com/search?q=nxnsattack
Details Url 1
https://www.isc.org/presentations
Details Url 1
https://www.spamhaus.org/news/article/797/the-current-state-of-domain-hijacking-and-a-specific-look-at-the-ongoing-issues-at-godaddy
Details Url 1
https://tools.ietf.org/html/rfc7858
Details Url 2
https://tools.ietf.org/html/rfc8484
Details Url 1
https://tools.ietf.org/id/draft-huitema-quic-dnsoquic-06.html
Details Url 1
https://tools.ietf.org/html/rfc2549
Details Url 1
https://en.wikipedia.org/wiki/daniel_b._cid
Details Url 1
https://cleanbrowsing.org
Details Url 1
https://bgpview.io/asn/205157
Details Url 1
http://www.fobul.net
Details Url 1
https://www.iij.ad/jp/ja
Details Url 1
https://developerers.google.com/speed/public-dns/docs/dns-over-tls
Details Url 2
https://pi-hole.net
Details Url 1
https://www.nginx.com/blog/ussion-nginx-as-doh-gateway
Details Url 1
https://getdnsapi.net
Details Url 2
https://www.powerdns.com
Details Url 1
https://tools.ietf.org/html/rfc5905
Details Url 1
http://support.ntp.org/bin/view/main/webhome
Details Url 1
https://news.netcraft.com/archives/category/web-server-survey
Details Url 1
https://en.wikipedia.org/wiki/gopher_
Details Url 1
https://tools.ietf.org/html/draft-tsvwg-quic-protocol-02
Details Url 1
https://nvd.nist.gov/products/cpe
Details Url 1
https://www.fidelix.com/building-automation
Details Url 1
https://www.netscout.com/theatreport
Details Url 1
https://securityaffairs.co/wordpress/92899/cyber-crime/fbi-cisa-e-skiming-atacks.html
Details Url 1
https://www.darkreading.com/vulnerabilities---threats/eternalblue-longevity-underscores-patching-problem/d/d-id/1337233
Details Url 1
https://ja.wikipedia.org/wiki/ipv4によると
Details Url 1
https://www.usenix.org/conference/woot14/workshop-program/presentation/adrian
Details Url 1
https://www.google.com/intl/en/ipv6/statistics.html
Details Url 1
https://www.cvedetails.com/top-50-products.php
Details Url 3
https://opendata.rapid7.com
Details Url 1
https://github.com/rapid7/recog
Details Url 1
https://github.com/rapid7/recog/blob/master/xml/http_servers.xml#l176
Details Url 1
https://github.com/zmap/zmap
Details Url 1
https://map.internetintel.oracle.com
Details Url 1
https://www.rapid7.com/ja/info/national-exposure-index
Details Url 1
https://svn.nmap.org/nmap/nmap-services
Details Url 1
https://www.maxmind.com/ja/home
Details Url 57
https://attack.mitre.org