Viewing historical forecast View Latest
AI Threat Forecast 2025-12-01T06:00:28.156836 #121

Threat Intelligence Briefing

Analysis period: 2025-12-01T00:00:02.191479 - 2025-12-01T06:00:02.191479 (6 hours)

Executive Summary

The threat landscape shows an 18% increase in global activity over the past 6 hours, with 715 threats from 562 unique IPs across 57 countries. Nordic countries recorded 8 total threats: Sweden (5), Finland (2), and Denmark (1), primarily involving malware_c2 and ssh_bruteforce. Globally, China (CN) led with 114 threats, followed by the US (104) and Netherlands (NL) with 73. The top threat categories were malware_c2 (322), ssh_bruteforce (261), and botnet_c2 (64), indicating persistent malware and brute force campaigns targeting SSH services. The top attacking IPs include <a href="https://ip.wayscloud.services/ip-intelligence/78.191.248.116" target="_blank">78.191.248.116</a> (TR, 23 malware_c2 attacks) and <a href="https://ip.wayscloud.services/ip-intelligence/45.140.17.124" target="_blank">45.140.17.124</a> (RU, 11 bruteforce attacks). Notably, NL-based IPs <a href="https://ip.wayscloud.services/ip-intelligence/188.166.125.34" target="_blank">188.166.125.34</a> and <a href="https://ip.wayscloud.services/ip-intelligence/164.92.217.181" target="_blank">164.92.217.181</a> showed concentrated SSH brute force attempts. Defenders should prioritize blocking these IPs and enhance SSH security with rate-limiting and multi-factor authentication. Monitor Nordic networks for malware_c2 callback traffic, particularly in Sweden.