Threat Intelligence Briefing
Analysis period: 2025-12-17T18:00:01.833331 - 2025-12-18T00:00:01.833331 (6 hours)
Executive Summary
The global threat landscape showed a slight decrease of 1.9% in the last 6 hours, with 852,634 threats detected. Suspicious activity dominated (72% of total), followed by severe abuse (20%). The US and China remained top sources, while Nordic countries accounted for 10,404 threats. Sweden led Nordic activity with 5,599 threats (2802 unique IPs), primarily attacks and brute force. Finland followed with 2,351 threats, including notable spam activity. Norway and Denmark saw web attacks and SSH brute force, while Iceland had minimal but concentrated threats. The Netherlands and Russia were prominent in SSH brute force attacks via IPs like <a href="https://ip.wayscloud.services/ip-intelligence/167.172.36.25" target="_blank">167.172.36.25</a> and <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a>. Monitor these IPs closely, as they show repeated severe abuse patterns. Nordic ISPs should prioritize SSH hardening and web application firewalls given the regional focus on brute force and web attacks. Deploy rate-limiting for SSH ports and review logs for connections from these high-risk IPs.