Threat Intelligence Briefing
Analysis period: 2025-12-11T18:00:01.582773 - 2025-12-12T00:00:01.582773 (6 hours)
Executive Summary
Global threat activity decreased by 34.3% compared to the previous 6-hour period, with 866,049 total threats detected from 433,675 unique IPs. Suspicious activity accounted for 71.8% of all threats, followed by severe abuse (19.6%). The US (164,059) and China (142,931) remained top sources, while Nordic countries showed distinct patterns: Sweden (6,047 threats) had Tor exit node activity, Finland (2,304) exhibited web attacks and brute force attempts, and Norway (1,138) saw concentrated high-threat activity. Iceland's 221 threats included notable spam campaigns. Four of the top five malicious IPs originated from Dutch hosting providers, specializing in SSH brute force attacks (<a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> from Russia being most active). Organizations should prioritize blocking Dutch-hosted IP ranges <a href="https://ip.wayscloud.services/ip-intelligence/167.99.212.128" target="_blank">167.99.212.128</a>/24 and <a href="https://ip.wayscloud.services/ip-intelligence/64.227.76.232" target="_blank">64.227.76.232</a>/24, while Nordic defenders must monitor SSH authentication logs for unusual patterns from Swedish and Finnish IPs.