SO (SO) Threat Intelligence

SO

SO has 365 malicious IP addresses with 12,970 abuse reports. Top threat categories include tcp scan, suspicious activity, malware distribution, high threat, severe abuse. Top attacking networks: Hormuud Telecom Somalia INC (145 IPs), SOMTEL INTERNATIONAL Ltd (64 IPs), Somtel-Somalia-AS (29 IPs). Data collected since 2025-10-13, last activity 2026-09-22.

Threat Assessment: SO has a relatively low level of observed cyber threat activity. The dominant attack types are tcp scan, suspicious activity, malware distribution. The majority of threats originate from networks operated by Hormuud Telecom Somalia INC and SOMTEL INTERNATIONAL Ltd.

Total Reports
12,970
Unique IPs
365
First Seen
2025-10-13
Last Activity
2026-09-22

Top Threat Categories

Tcp Scan 1,664
Suspicious Activity 739
Malware Distribution 402
High Threat 394
Severe Abuse 115

Top Attacking Networks

AS37371 Hormuud Telecom Somalia INC
145 IPs
AS37563 SOMTEL INTERNATIONAL Ltd
64 IPs
AS328469 Somtel-Somalia-AS
29 IPs

Most Reported IPs in SO

197.231.202.201 895 reports
41.223.109.134 706 reports
41.78.74.209 660 reports
197.220.92.185 614 reports
197.220.92.219 471 reports

Access this data via API

Get SO threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/SO

View full API documentation

See how we classify and verify threats →

Check any IP from SO

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS37371 Intelligence AS37563 Intelligence AS328469 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...