SO (SO) Threat Intelligence

SO

SO has 348 malicious IP addresses with 12,160 abuse reports. Top threat categories include suspicious activity, severe abuse, ssh bruteforce, moderate threat, spam. Top attacking networks: Hormuud Telecom Somalia INC (135 IPs), SOMTEL INTERNATIONAL Ltd (59 IPs), Somtel-Somalia-AS (28 IPs). Data collected since 2025-10-13, last activity 2026-09-06.

Threat Assessment: SO has a relatively low level of observed cyber threat activity. The dominant attack types are suspicious activity, severe abuse, ssh bruteforce. The majority of threats originate from networks operated by Hormuud Telecom Somalia INC and SOMTEL INTERNATIONAL Ltd.

Total Reports
12,160
Unique IPs
348
First Seen
2025-10-13
Last Activity
2026-09-06

Top Threat Categories

Suspicious Activity 195
Severe Abuse 115
Ssh Bruteforce 43
Moderate Threat 34
Spam 4

Top Attacking Networks

AS37371 Hormuud Telecom Somalia INC
135 IPs
AS37563 SOMTEL INTERNATIONAL Ltd
59 IPs
AS328469 Somtel-Somalia-AS
28 IPs

Most Reported IPs in SO

197.231.202.201 750 reports
41.223.109.134 670 reports
41.78.74.209 600 reports
197.220.92.219 471 reports
197.220.92.185 375 reports

Access this data via API

Get SO threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/SO

View full API documentation

See how we classify and verify threats →

Check any IP from SO

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS37371 Intelligence AS37563 Intelligence AS328469 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...