Bulgaria (BG) Threat Intelligence

BG

Bulgaria has 20,476 malicious IP addresses with 693,649 abuse reports. Top threat categories include suspicious activity, ssh bruteforce, severe abuse, tcp scan, generic bruteforce. Top attacking networks: Tamatiya EOOD (2,154 IPs), ColocaTel Inc. (1,874 IPs), Vivacom Bulgaria EAD (1,208 IPs). Data collected since 2023-04-08, last activity 2026-09-06.

Threat Assessment: Bulgaria shows substantial cyber threat activity, ranking among the top threat source countries worldwide. The dominant attack types are suspicious activity, ssh bruteforce, severe abuse. The majority of threats originate from networks operated by Tamatiya EOOD and ColocaTel Inc..

Total Reports
693,649
Unique IPs
20,476
First Seen
2023-04-08
Last Activity
2026-09-06

Top Threat Categories

Suspicious Activity 12,500
Ssh Bruteforce 8,659
Severe Abuse 3,910
Tcp Scan 3,635
Generic Bruteforce 1,313

Top Attacking Networks

AS50360 Tamatiya EOOD
2,154 IPs
AS213438 ColocaTel Inc.
1,874 IPs
AS8866 Vivacom Bulgaria EAD
1,208 IPs

Most Reported IPs in Bulgaria

195.178.110.30 3,479 reports
78.128.113.46 825 reports
5.188.206.34 820 reports
78.128.112.30 819 reports
5.188.206.30 817 reports

Access this data via API

Get Bulgaria threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/BG

View full API documentation

See how we classify and verify threats →

Check any IP from Bulgaria

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS50360 Intelligence AS213438 Intelligence AS8866 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...