Ukraine (UA) Threat Intelligence

UA

Ukraine has 50,835 malicious IP addresses with 1,109,048 abuse reports. Top threat categories include suspicious activity, severe abuse, moderate threat, high threat, ssh bruteforce. Top attacking networks: Kyivstar PJSC (3,754 IPs), CHP Zarko Alexandr Ivanovich (1,771 IPs), FOP Dmytro Nedilskyi (1,536 IPs). Data collected since 2023-07-04, last activity 2026-07-28.

Threat Assessment: Ukraine shows substantial cyber threat activity, ranking among the top threat source countries worldwide. The dominant attack types are suspicious activity, severe abuse, moderate threat. The majority of threats originate from networks operated by Kyivstar PJSC and CHP Zarko Alexandr Ivanovich.

Total Reports
1,109,048
Unique IPs
50,835
First Seen
2023-07-04
Last Activity
2026-07-28

Top Threat Categories

Suspicious Activity 44,928
Severe Abuse 4,510
Moderate Threat 3,012
High Threat 1,751
Ssh Bruteforce 1,174

Top Attacking Networks

AS15895 Kyivstar PJSC
3,754 IPs
AS56812 CHP Zarko Alexandr Ivanovich
1,771 IPs
AS211736 FOP Dmytro Nedilskyi
1,536 IPs

Most Reported IPs in Ukraine

77.87.40.114 536 reports
92.113.142.203 536 reports
128.0.104.44 532 reports
82.193.122.91 516 reports
31.42.184.158 515 reports

Access this data via API

Get Ukraine threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/UA

View full API documentation

See how we classify and verify threats →

Check any IP from Ukraine

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS15895 Intelligence AS56812 Intelligence AS211736 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...