MW (MW) Threat Intelligence

MW

MW has 149 malicious IP addresses with 2,800 abuse reports. Top threat categories include repeat offender, ssh bruteforce, severe abuse, suspicious activity. Top attacking networks: TELEKOM-NETWORKS-MALAWI (54 IPs), Airtel (22 IPs), AIRTEL (22 IPs). Data collected since 2025-11-06, last activity 2026-04-13.

Threat Assessment: MW has a relatively low level of observed cyber threat activity. The dominant attack types are repeat offender, ssh bruteforce, severe abuse. The majority of threats originate from networks operated by TELEKOM-NETWORKS-MALAWI and Airtel.

Total Reports
2,800
Unique IPs
149
First Seen
2025-11-06
Last Activity
2026-04-13

Top Threat Categories

Repeat Offender 7
Ssh Bruteforce 6
Severe Abuse 2
Suspicious Activity 2

Top Attacking Networks

AS36913 TELEKOM-NETWORKS-MALAWI
54 IPs
AS37440 Airtel
22 IPs
AS327708 AIRTEL
22 IPs

Most Reported IPs in MW

41.75.122.7 206 reports
196.216.10.111 188 reports
41.216.228.199 188 reports
196.11.86.153 187 reports
102.213.28.196 185 reports

Access this data via API

Get MW threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/MW

View full API documentation

See how we classify and verify threats →

Check any IP from MW

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS36913 Intelligence AS37440 Intelligence AS327708 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...