Lebanon (LB) Threat Intelligence

LB

Lebanon has 2,172 malicious IP addresses with 43,694 abuse reports. Top threat categories include tcp scan, suspicious activity, malware distribution, intrusion attempt, high threat. Top attacking networks: IncoNet Data Management sal (294 IPs), TerraNet sal (199 IPs), OGERO (194 IPs). Data collected since 2022-10-05, last activity 2026-09-23.

Threat Assessment: Lebanon exhibits moderate cyber threat activity, with a notable number of malicious IPs across multiple attack categories. The dominant attack types are tcp scan, suspicious activity, malware distribution. The majority of threats originate from networks operated by IncoNet Data Management sal and TerraNet sal.

Total Reports
43,694
Unique IPs
2,172
First Seen
2022-10-05
Last Activity
2026-09-23

Top Threat Categories

Tcp Scan 4,123
Suspicious Activity 1,971
Malware Distribution 924
Intrusion Attempt 469
High Threat 371

Top Attacking Networks

AS9051 IncoNet Data Management sal
294 IPs
AS39010 TerraNet sal
199 IPs
AS42003 OGERO
194 IPs

Most Reported IPs in Lebanon

109.233.21.109 964 reports
141.105.81.218 851 reports
193.227.179.227 616 reports
185.104.71.22 598 reports
91.151.238.195 458 reports

Access this data via API

Get Lebanon threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/LB

View full API documentation

See how we classify and verify threats →

Check any IP from Lebanon

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS9051 Intelligence AS39010 Intelligence AS42003 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...