Threat Intelligence Briefing
Analysis period: 2025-12-07T12:00:02.520150 - 2025-12-07T18:00:02.520150 (6 hours)
Executive Summary
The global threat landscape showed a 12% decrease in activity compared to the previous 6-hour period, with 5,317 threats detected from 4,012 unique IPs across 93 countries. Malware command-and-control (C2) remained the top category (42% of threats), followed by severe abuse (17%) and attacks (12%). Nordic countries saw limited but notable activity: Sweden (13 threats, primarily attacks and severe abuse), Norway (10 threats, dominated by brute force attempts), and Finland (8 threats, focusing on web attacks). The US, Netherlands, and China were the top source countries globally. Tactical intelligence highlights persistent brute force attacks from IPs <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> (RU) and <a href="https://ip.wayscloud.services/ip-intelligence/188.166.48.134" target="_blank">188.166.48.134</a> (NL), both targeting SSH services. The Netherlands also hosted <a href="https://ip.wayscloud.services/ip-intelligence/134.122.62.168" target="_blank">134.122.62.168</a>, which combined web attacks with brute force. Recommendations include tightening SSH access controls and monitoring traffic from these IPs, particularly for Nordic networks facing repeated web and brute force attempts.