Bulgaria (BG) Threat Intelligence

BG

Bulgaria has 10,121 malicious IP addresses with 332,266 abuse reports. Top threat categories include suspicious activity, ssh bruteforce, severe abuse, moderate threat, generic bruteforce. Top attacking networks: Tamatiya EOOD (1,069 IPs), Vivacom Bulgaria EAD (625 IPs), Techoff Srv Limited (512 IPs). Data collected since 2023-04-08, last activity 2026-04-07.

Threat Assessment: Bulgaria shows substantial cyber threat activity, ranking among the top threat source countries worldwide. The dominant attack types are suspicious activity, ssh bruteforce, severe abuse. The majority of threats originate from networks operated by Tamatiya EOOD and Vivacom Bulgaria EAD.

Total Reports
332,266
Unique IPs
10,121
First Seen
2023-04-08
Last Activity
2026-04-07

Top Threat Categories

Suspicious Activity 12,500
Ssh Bruteforce 5,605
Severe Abuse 3,910
Moderate Threat 988
Generic Bruteforce 605

Top Attacking Networks

AS50360 Tamatiya EOOD
1,069 IPs
AS8866 Vivacom Bulgaria EAD
625 IPs
AS48090 Techoff Srv Limited
512 IPs

Most Reported IPs in Bulgaria

195.178.110.30 4,215 reports
78.128.112.74 992 reports
195.178.110.15 486 reports
93.123.109.38 392 reports
212.233.136.201 255 reports

Access this data via API

Get Bulgaria threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/BG

View full API documentation

See how we classify and verify threats →

Check any IP from Bulgaria

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS50360 Intelligence AS8866 Intelligence AS48090 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...