Threat Intelligence Briefing
Analysis period: 2025-10-18T18:00:02.045224 - 2025-10-19T00:00:02.045224 (6 hours)
Executive Summary
Threat activity has decreased by 14.8% globally in the last 6 hours, with suspicious activity comprising the majority of events. Nordic countries saw a combined total of 47 events, predominantly categorized as severe abuse and suspicious activity. Sweden accounted for the bulk of Nordic activity, with 31 events. We observed multiple botnet C2 IPs, including 23.177.185.39 and 176.46.152.89, showing a sustained high attack count. No significant Tor exit node activity was detected.
Given the prevalence of SSH brute force attacks, particularly originating from Iran (IR) and Romania (RO), we recommend heightened monitoring of network segments exposed to SSH. Prioritize monitoring of ASNs associated with DigitalOcean, AWS, and Hetzner for potential abuse. Monitor botnet C2 communications and analyze traffic to identify potential compromised hosts.