Norway (NO) Threat Intelligence

NO

Norway has 2,858 malicious IP addresses with 120,941 abuse reports. Top threat categories include suspicious activity, severe abuse, moderate threat, high threat, ssh bruteforce. Top attacking networks: Telia Norge AS (297 IPs), M247 Europe SRL (262 IPs), Glesys AB (233 IPs). Data collected since 2025-10-13, last activity 2026-04-08.

Threat Assessment: Norway exhibits moderate cyber threat activity, with a notable number of malicious IPs across multiple attack categories. The dominant attack types are suspicious activity, severe abuse, moderate threat. The majority of threats originate from networks operated by Telia Norge AS and M247 Europe SRL.

Total Reports
120,941
Unique IPs
2,858
First Seen
2025-10-13
Last Activity
2026-04-08

Top Threat Categories

Suspicious Activity 3,549
Severe Abuse 1,398
Moderate Threat 315
High Threat 266
Ssh Bruteforce 45

Top Attacking Networks

AS25400 Telia Norge AS
297 IPs
AS9009 M247 Europe SRL
262 IPs
AS42708 Glesys AB
233 IPs

Most Reported IPs in Norway

185.40.4.38 217 reports
85.19.195.12 216 reports
185.42.170.203 215 reports
217.170.199.90 214 reports
185.40.4.127 214 reports

Access this data via API

Get Norway threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/NO

View full API documentation

See how we classify and verify threats →

Check any IP from Norway

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS25400 Intelligence AS9009 Intelligence AS42708 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...