Ghana (GH) Threat Intelligence

GH

Ghana has 3,496 malicious IP addresses with 143,289 abuse reports. Top threat categories include tcp scan, suspicious activity, malware distribution, severe abuse, high threat. Top attacking networks: Scancom Limited (1,521 IPs), VODAFONE GHANA AS INTERNATIONAL TRANSIT (769 IPs), Teledata, Ghana (412 IPs). Data collected since 2025-05-05, last activity 2026-09-23.

Threat Assessment: Ghana exhibits moderate cyber threat activity, with a notable number of malicious IPs across multiple attack categories. The dominant attack types are tcp scan, suspicious activity, malware distribution. The majority of threats originate from networks operated by Scancom Limited and VODAFONE GHANA AS INTERNATIONAL TRANSIT.

Total Reports
143,289
Unique IPs
3,496
First Seen
2025-05-05
Last Activity
2026-09-23

Top Threat Categories

Tcp Scan 14,927
Suspicious Activity 7,417
Malware Distribution 3,369
Severe Abuse 2,118
High Threat 2,080

Top Attacking Networks

AS30986 Scancom Limited
1,521 IPs
AS29614 VODAFONE GHANA AS INTERNATIONAL TRANSIT
769 IPs
AS35091 Teledata, Ghana
412 IPs

Most Reported IPs in Ghana

41.242.115.84 1,078 reports
41.242.115.83 1,066 reports
102.223.92.101 1,024 reports
80.87.83.229 994 reports
41.204.63.118 953 reports

Access this data via API

Get Ghana threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/GH

View full API documentation

See how we classify and verify threats →

Check any IP from Ghana

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS30986 Intelligence AS29614 Intelligence AS35091 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...