Estonia (EE) Threat Intelligence

EE

Estonia has 3,449 malicious IP addresses with 55,320 abuse reports. Top threat categories include suspicious activity, severe abuse, ssh bruteforce, moderate threat, high threat. Top attacking networks: Orion Network Limited (1,080 IPs), WS Telecom Inc (372 IPs), Angelnet Limited (224 IPs). Data collected since 2024-04-28, last activity 2026-07-27.

Threat Assessment: Estonia exhibits moderate cyber threat activity, with a notable number of malicious IPs across multiple attack categories. The dominant attack types are suspicious activity, severe abuse, ssh bruteforce. The majority of threats originate from networks operated by Orion Network Limited and WS Telecom Inc.

Total Reports
55,320
Unique IPs
3,449
First Seen
2024-04-28
Last Activity
2026-07-27

Top Threat Categories

Suspicious Activity 1,159
Severe Abuse 363
Ssh Bruteforce 111
Moderate Threat 81
High Threat 33

Top Attacking Networks

AS58065 Orion Network Limited
1,080 IPs
AS209372 WS Telecom Inc
372 IPs
AS57858 Angelnet Limited
224 IPs

Most Reported IPs in Estonia

109.206.241.199 519 reports
83.166.50.15 510 reports
85.29.246.199 500 reports
213.35.128.24 468 reports
95.85.245.51 458 reports

Access this data via API

Get Estonia threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/EE

View full API documentation

See how we classify and verify threats →

Check any IP from Estonia

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS58065 Intelligence AS209372 Intelligence AS57858 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...