Threat Intelligence Briefing
Analysis period: 2025-12-04T00:00:02.193369 - 2025-12-04T06:00:02.193369 (6 hours)
Executive Summary
The threat landscape has escalated dramatically with a 638.1% increase in global threats compared to the previous 6-hour period, totaling 1,144 incidents. Severe abuse dominates with 777 cases (68% of total), followed by malware C2 (288) and botnet C2 (79). The US (351), China (151), and Singapore (68) are top source countries. Nordic activity remains lower but concerning, with Finland (10), Sweden (9), and Norway (4) reporting incidents primarily involving malware C2 and severe abuse. Notably, 100% of Nordic threats originated from unique IPs, suggesting distributed attack patterns. High-priority IPs include malware C2 operators <a href="https://ip.wayscloud.services/ip-intelligence/102.205.170.10" target="_blank">102.205.170.10</a> (KE) and <a href="https://ip.wayscloud.services/ip-intelligence/18.207.124.163" target="_blank">18.207.124.163</a> (US), plus botnet C2 node <a href="https://ip.wayscloud.services/ip-intelligence/194.116.236.109" target="_blank">194.116.236.109</a> (TR). Attacks show increased targeting of cloud infrastructure, with 72% of global IPs being datacenter-hosted. Immediate actions: blocklisted high-frequency IPs, increase monitoring of AWS (US) and Leaseweb (NL) networks, and implement stricter egress filtering for Nordic clients due to rising malware C2 risks.