Bulgaria (BG) Threat Intelligence

BG

Bulgaria has 19,700 malicious IP addresses with 630,678 abuse reports. Top threat categories include suspicious activity, ssh bruteforce, severe abuse, generic bruteforce, moderate threat. Top attacking networks: Tamatiya EOOD (1,924 IPs), ColocaTel Inc. (1,873 IPs), Vivacom Bulgaria EAD (1,164 IPs). Data collected since 2023-04-08, last activity 2026-08-15.

Threat Assessment: Bulgaria shows substantial cyber threat activity, ranking among the top threat source countries worldwide. The dominant attack types are suspicious activity, ssh bruteforce, severe abuse. The majority of threats originate from networks operated by Tamatiya EOOD and ColocaTel Inc..

Total Reports
630,678
Unique IPs
19,700
First Seen
2023-04-08
Last Activity
2026-08-15

Top Threat Categories

Suspicious Activity 12,500
Ssh Bruteforce 7,883
Severe Abuse 3,910
Generic Bruteforce 1,148
Moderate Threat 988

Top Attacking Networks

AS50360 Tamatiya EOOD
1,924 IPs
AS213438 ColocaTel Inc.
1,873 IPs
AS8866 Vivacom Bulgaria EAD
1,164 IPs

Most Reported IPs in Bulgaria

195.178.110.30 2,401 reports
195.178.110.26 671 reports
195.178.110.135 665 reports
91.92.199.36 642 reports
94.156.152.234 631 reports

Access this data via API

Get Bulgaria threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/BG

View full API documentation

See how we classify and verify threats →

Check any IP from Bulgaria

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS50360 Intelligence AS213438 Intelligence AS8866 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...