Denmark (DK) Threat Intelligence

DK

Denmark has 2,051 malicious IP addresses with 107,110 abuse reports. Top threat categories include web attack, ssh bruteforce, generic bruteforce, mail bruteforce, web scanner. Top attacking networks: Glesys AB (369 IPs), M247 Europe SRL (275 IPs), Hi3G Access AB (225 IPs). Data collected since 2025-12-06, last activity 2026-04-16.

Threat Assessment: Denmark exhibits moderate cyber threat activity, with a notable number of malicious IPs across multiple attack categories. The dominant attack types are web attack, ssh bruteforce, generic bruteforce. The majority of threats originate from networks operated by Glesys AB and M247 Europe SRL.

Total Reports
107,110
Unique IPs
2,051
First Seen
2025-12-06
Last Activity
2026-04-16

Top Threat Categories

Web Attack 19
Ssh Bruteforce 12
Generic Bruteforce 2
Mail Bruteforce 1
Web Scanner 1

Top Attacking Networks

AS42708 Glesys AB
369 IPs
AS9009 M247 Europe SRL
275 IPs
AS44034 Hi3G Access AB
225 IPs

Most Reported IPs in Denmark

185.129.61.9 231 reports
185.129.61.4 228 reports
185.129.61.1 227 reports
185.129.61.7 225 reports
185.129.61.8 224 reports

Access this data via API

Get Denmark threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/DK

View full API documentation

See how we classify and verify threats →

Check any IP from Denmark

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS42708 Intelligence AS9009 Intelligence AS44034 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...