Ukraine (UA) Threat Intelligence

UA

Ukraine has 70,780 malicious IP addresses with 1,832,109 abuse reports. Top threat categories include tcp scan, suspicious activity, high threat, malware distribution, intrusion attempt. Top attacking networks: Kyivstar PJSC (4,152 IPs), LLC Eksintech (2,136 IPs), CHP Zarko Alexandr Ivanovich (2,049 IPs). Data collected since 2023-07-04, last activity 2026-09-20.

Threat Assessment: Ukraine shows substantial cyber threat activity, ranking among the top threat source countries worldwide. The dominant attack types are tcp scan, suspicious activity, high threat. The majority of threats originate from networks operated by Kyivstar PJSC and LLC Eksintech.

Total Reports
1,832,109
Unique IPs
70,780
First Seen
2023-07-04
Last Activity
2026-09-20

Top Threat Categories

Tcp Scan 539,825
Suspicious Activity 171,505
High Threat 44,265
Malware Distribution 41,190
Intrusion Attempt 8,580

Top Attacking Networks

AS15895 Kyivstar PJSC
4,152 IPs
AS3255 LLC Eksintech
2,136 IPs
AS56812 CHP Zarko Alexandr Ivanovich
2,049 IPs

Most Reported IPs in Ukraine

77.87.40.114 1,002 reports
82.193.122.91 932 reports
46.201.247.21 921 reports
91.219.196.17 884 reports
176.36.146.80 871 reports

Access this data via API

Get Ukraine threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/UA

View full API documentation

See how we classify and verify threats →

Check any IP from Ukraine

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS15895 Intelligence AS3255 Intelligence AS56812 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...