From Uganda Computer Emergency Response Team CERT (UCC) …….
Good morning Ladies and Gentlemen,
The CERT maintains a research honeypot which is run to gather information about the motives and tactics of hacker communities targeting different networks. The primary objective of the honeypot is to provide cyber security situational intelligence and also to research the threats that operators face and to learn how to better protect against those threats.
From the gathered information we note that at one any time we are under attack either directly or indirectly.
Over the last 24 hours we see persistent attacks from the following sources (countries). This information confirms the fact that cyber-attacks are real happenings and are a global problem.
| Country | Count |
1 | China | 1,728 |
2 | Brazil | 785 |
3 | Ukraine | 734 |
4 | United States | 727 |
5 | Russia | 674 |
6 | France | 655 |
7 | Czechia | 635 |
8 | Argentina | 468 |
9 | Iraq | 378 |
10 | Mexico | 295 |
We note the attacks are geared towards the following ports, with traffic mismatch. For example we note SIP traffic being routed to port 80, yet SIP traffic uses port 5060 and 5061 for communications.
dest_port | count |
22 | 4262 |
23 | 1481 |
80 | 1325 |
5060 | 1201 |
5358 | 145 |
3389 | 122 |
2323 | 77 |
8080 | 72 |
8545 | 65 |
443 | 57 |
Similarly, we note the following usernames /passwords are the most commonly used for attempted account hijacking;
| Top Usernames | Top Passwords |
1 | Admin | support |
2 | Support | admin |
3 | User | password |
4 | Administrator | 1234 |
5 | Default | Default |
We strongly encourage you to avoid using the above usernames or passwords as they are the most commonly used for account hijacking. Most computing devices use the above usernames by default, it is recommended you change the usernames to those that are not easily guessed or used.
Regards
COMPUTER EMERGENCY RESPONSE TEAM
Uganda Communications Commission
42-44, Spring Road - Bugolobi, P.O Box 7376 Kampala.
Toll free: 0800 133 911 www.ug-cert.ug
You are receiving this message because you are a leader of the community I-Network Uganda. All community leaders receive these notifications immediately regardless of their email settings for this community.