Threat Intelligence Briefing
Analysis period: 2025-12-24T06:00:01.736400 - 2025-12-24T12:00:01.736400 (6 hours)
Executive Summary
The global threat landscape remained stable with 28,639 threats detected (+0.0% change), primarily malware C2 (42%) and attacks (22%). Nordic countries saw 229 threats, with Norway (115), Sweden (51), and Finland (49) as top targets. Norway experienced attacks, brute force, and spam, while Sweden showed tor_exit node activity. The Netherlands (NL) was the primary attack source globally (2,634 threats), with Russian IP <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> notable for brute force attempts. Monitor Dutch IPs <a href="https://ip.wayscloud.services/ip-intelligence/146.190.229.70" target="_blank">146.190.229.70</a> (11 attacks) and <a href="https://ip.wayscloud.services/ip-intelligence/164.90.206.43" target="_blank">164.90.206.43</a> (8 attacks) for SSH brute force patterns. Nordic ISPs should prioritize blocking NL-based SSH brute force attempts, which increased 15% regionally. Deploy geofencing for NL and RU IP ranges during peak attack windows.