Ukraine (UA) Threat Intelligence

UA

Ukraine has 48,326 malicious IP addresses with 1,067,300 abuse reports. Top threat categories include suspicious activity, severe abuse, moderate threat, high threat, ssh bruteforce. Top attacking networks: Kyivstar PJSC (3,657 IPs), CHP Zarko Alexandr Ivanovich (1,680 IPs), FOP Dmytro Nedilskyi (1,536 IPs). Data collected since 2023-07-04, last activity 2026-07-13.

Threat Assessment: Ukraine shows substantial cyber threat activity, ranking among the top threat source countries worldwide. The dominant attack types are suspicious activity, severe abuse, moderate threat. The majority of threats originate from networks operated by Kyivstar PJSC and CHP Zarko Alexandr Ivanovich.

Total Reports
1,067,300
Unique IPs
48,326
First Seen
2023-07-04
Last Activity
2026-07-13

Top Threat Categories

Suspicious Activity 44,928
Severe Abuse 4,510
Moderate Threat 3,012
High Threat 1,751
Ssh Bruteforce 1,150

Top Attacking Networks

AS15895 Kyivstar PJSC
3,657 IPs
AS56812 CHP Zarko Alexandr Ivanovich
1,680 IPs
AS211736 FOP Dmytro Nedilskyi
1,536 IPs

Most Reported IPs in Ukraine

128.0.104.44 454 reports
62.182.85.212 450 reports
77.87.40.114 449 reports
31.42.184.158 446 reports
92.113.142.203 446 reports

Access this data via API

Get Ukraine threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/UA

View full API documentation

See how we classify and verify threats →

Check any IP from Ukraine

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS15895 Intelligence AS56812 Intelligence AS211736 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...