Threat Intelligence Briefing
Analysis period: 2025-10-28T00:00:01.771386 - 2025-10-28T06:00:01.771386 (6 hours)
Executive Summary
The threat landscape has intensified, evidenced by a 37.9% surge in reported threats compared to the previous six-hour window. Globally, SSH brute-force attempts and malware command-and-control (C2) activity constitute the majority of malicious traffic. Romania, the US, and China are the top originating countries. Limited activity was observed in the Nordic region, specifically Finland, with a single SSH brute-force event detected. No significant abuse of major hosting providers was observed.
Given the increase in C2 activity, monitor networks hosting infrastructure in ASNs associated with observed IPs, including those originating from Romania and Ukraine. Track IP addresses 151.241.100.63 and 104.21.61.223, which exhibited high botnet and malware C2 activity, respectively. Continue monitoring for SSH brute-force attacks, adjusting thresholds to account for the elevated activity.