Mongolia (MN) Threat Intelligence

MN

Mongolia has 1,283 malicious IP addresses with 75,475 abuse reports. Top threat categories include tcp scan, suspicious activity, high threat, malware distribution, severe abuse. Top attacking networks: UNIVISION LLC (539 IPs), Mobinet LLC. AS Mobinet Internet Service Provider (150 IPs), GEMNET LLC (133 IPs). Data collected since 2025-10-13, last activity 2026-09-22.

Threat Assessment: Mongolia exhibits moderate cyber threat activity, with a notable number of malicious IPs across multiple attack categories. The dominant attack types are tcp scan, suspicious activity, high threat. The majority of threats originate from networks operated by UNIVISION LLC and Mobinet LLC. AS Mobinet Internet Service Provider.

Total Reports
75,475
Unique IPs
1,283
First Seen
2025-10-13
Last Activity
2026-09-22

Top Threat Categories

Tcp Scan 8,605
Suspicious Activity 4,240
High Threat 1,265
Malware Distribution 1,210
Severe Abuse 343

Top Attacking Networks

AS17882 UNIVISION LLC
539 IPs
AS9484 Mobinet LLC. AS Mobinet Internet Service Provider
150 IPs
AS45204 GEMNET LLC
133 IPs

Most Reported IPs in Mongolia

202.21.114.114 813 reports
66.181.171.136 778 reports
43.228.131.114 741 reports
203.21.120.126 725 reports
203.23.199.88 656 reports

Access this data via API

Get Mongolia threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/MN

View full API documentation

See how we classify and verify threats →

Check any IP from Mongolia

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS17882 Intelligence AS9484 Intelligence AS45204 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...