Bulgaria (BG) Threat Intelligence

BG

Bulgaria has 20,059 malicious IP addresses with 650,535 abuse reports. Top threat categories include suspicious activity, ssh bruteforce, severe abuse, generic bruteforce, moderate threat. Top attacking networks: Tamatiya EOOD (1,926 IPs), ColocaTel Inc. (1,873 IPs), Vivacom Bulgaria EAD (1,191 IPs). Data collected since 2023-04-08, last activity 2026-08-22.

Threat Assessment: Bulgaria shows substantial cyber threat activity, ranking among the top threat source countries worldwide. The dominant attack types are suspicious activity, ssh bruteforce, severe abuse. The majority of threats originate from networks operated by Tamatiya EOOD and ColocaTel Inc..

Total Reports
650,535
Unique IPs
20,059
First Seen
2023-04-08
Last Activity
2026-08-22

Top Threat Categories

Suspicious Activity 12,500
Ssh Bruteforce 8,173
Severe Abuse 3,910
Generic Bruteforce 1,204
Moderate Threat 988

Top Attacking Networks

AS50360 Tamatiya EOOD
1,926 IPs
AS213438 ColocaTel Inc.
1,873 IPs
AS8866 Vivacom Bulgaria EAD
1,191 IPs

Most Reported IPs in Bulgaria

195.178.110.30 2,609 reports
195.178.110.26 721 reports
195.178.110.135 708 reports
91.92.199.36 694 reports
195.178.110.199 675 reports

Access this data via API

Get Bulgaria threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/BG

View full API documentation

See how we classify and verify threats →

Check any IP from Bulgaria

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS50360 Intelligence AS213438 Intelligence AS8866 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...