Threat Intelligence Briefing
Analysis period: 2026-07-05T00:00:01.529393 - 2026-07-05T06:00:01.529393 (6 hours)
Executive Summary
Global threat activity increased significantly, with 175,140 total threats reported—51.8% higher than the previous 6-hour period. This surge is primarily driven by reconnaissance (107K events) and attacks, diverging from the 7-day average trend of gradual fluctuation. The US, China, and Russia remain dominant sources, but notable pressure emerged from PH and RO IPs linked to malware C2 and SSH brute-force campaigns. Nordic countries show stable patterns, though SE and FI reported elevated botnet and malware C2 activity tied to known persistent threat actors, not new campaigns. The rise is concentrated in datacenter and residential ISP infrastructure, with Google, Microsoft, and DigitalOcean hosting a disproportionate share of malicious activity.
Consider temporary blocking or rate-limiting traffic from CIDR blocks associated with the top malware C2 IPs in the PH and RO ranges, particularly 103.11.41.0/24 and 80.94.92.128/25. Focus on patterns: the cluster of PH-based C2 servers has been active for over three weeks, indicating infrastructure reuse rather than ephemeral hosting. Deprioritize isolated SSH brute-force attempts from single IPs in DE and NL, as these align with routine background noise. Monitor for further escalation from US-hosted C2 nodes, especially those tied to <a href="https://ip.wayscloud.services/ip-intelligence/147.93.191.75" target="_blank">147.93.191.75</a>.