Lebanon (LB) Threat Intelligence

LB

Lebanon has 2,092 malicious IP addresses with 41,886 abuse reports. Top threat categories include suspicious activity, severe abuse, moderate threat, ssh bruteforce, high threat. Top attacking networks: IncoNet Data Management sal (268 IPs), TerraNet sal (186 IPs), OGERO (181 IPs). Data collected since 2022-10-05, last activity 2026-09-06.

Threat Assessment: Lebanon exhibits moderate cyber threat activity, with a notable number of malicious IPs across multiple attack categories. The dominant attack types are suspicious activity, severe abuse, moderate threat. The majority of threats originate from networks operated by IncoNet Data Management sal and TerraNet sal.

Total Reports
41,886
Unique IPs
2,092
First Seen
2022-10-05
Last Activity
2026-09-06

Top Threat Categories

Suspicious Activity 550
Severe Abuse 258
Moderate Threat 18
Ssh Bruteforce 16
High Threat 16

Top Attacking Networks

AS9051 IncoNet Data Management sal
268 IPs
AS39010 TerraNet sal
186 IPs
AS42003 OGERO
181 IPs

Most Reported IPs in Lebanon

109.233.21.109 760 reports
141.105.81.218 752 reports
185.104.71.22 598 reports
193.227.179.227 594 reports
91.151.238.195 458 reports

Access this data via API

Get Lebanon threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/LB

View full API documentation

See how we classify and verify threats →

Check any IP from Lebanon

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS9051 Intelligence AS39010 Intelligence AS42003 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...