Threat Intelligence Briefing
Analysis period: 2025-12-05T00:00:01.533345 - 2025-12-05T06:00:01.533345 (6 hours)
Executive Summary
The global threat landscape has surged 88% compared to the previous 6-hour period, with 1,098 threats originating from 1,023 unique IPs across 64 countries. The US (304), China (154), and Singapore (76) were the top attack sources, with severe abuse (637) and malware C2 (391) dominating attack categories. In the Nordic region, Sweden (8), Finland (4), and Norway (3) reported activity, primarily malware C2 and severe abuse. The 104.21.*.* subnet hosted multiple malware C2 nodes, while <a href="https://ip.wayscloud.services/ip-intelligence/85.120.229.147" target="_blank">85.120.229.147</a> (Romania) emerged as a significant botnet C2 threat. Attackers increasingly leverage cloud-hosted infrastructure, with no Tor exits detected in this period. Prioritize blocking traffic from the 104.21.*.* subnet and monitor for lateral movement attempts from Nordic-region IPs. Deploy enhanced endpoint detection for malware C2 patterns observed in Swedish and Finnish traffic.