Ukraine (UA) Threat Intelligence

UA

Ukraine has 50,836 malicious IP addresses with 1,109,053 abuse reports. Top threat categories include suspicious activity, severe abuse, moderate threat, high threat, ssh bruteforce. Top attacking networks: Kyivstar PJSC (3,754 IPs), CHP Zarko Alexandr Ivanovich (1,771 IPs), FOP Dmytro Nedilskyi (1,536 IPs). Data collected since 2023-07-04, last activity 2026-07-28.

Threat Assessment: Ukraine shows substantial cyber threat activity, ranking among the top threat source countries worldwide. The dominant attack types are suspicious activity, severe abuse, moderate threat. The majority of threats originate from networks operated by Kyivstar PJSC and CHP Zarko Alexandr Ivanovich.

Total Reports
1,109,053
Unique IPs
50,836
First Seen
2023-07-04
Last Activity
2026-07-28

Top Threat Categories

Suspicious Activity 44,928
Severe Abuse 4,510
Moderate Threat 3,012
High Threat 1,751
Ssh Bruteforce 1,174

Top Attacking Networks

AS15895 Kyivstar PJSC
3,754 IPs
AS56812 CHP Zarko Alexandr Ivanovich
1,771 IPs
AS211736 FOP Dmytro Nedilskyi
1,536 IPs

Most Reported IPs in Ukraine

77.87.40.114 537 reports
92.113.142.203 537 reports
128.0.104.44 533 reports
82.193.122.91 517 reports
31.42.184.158 516 reports

Access this data via API

Get Ukraine threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/UA

View full API documentation

See how we classify and verify threats →

Check any IP from Ukraine

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS15895 Intelligence AS56812 Intelligence AS211736 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...