Iran (IR) Threat Intelligence

IR

Iran has 15,394 malicious IP addresses with 518,728 abuse reports. Top threat categories include ssh bruteforce, spam, web attack, generic bruteforce, repeat offender. Top attacking networks: Iran Telecommunication Company PJS (2,457 IPs), Farahoosh Dena PLC (1,600 IPs), Limited Network LTD (1,258 IPs). Data collected since 2023-08-30, last activity 2026-04-16.

Threat Assessment: Iran shows substantial cyber threat activity, ranking among the top threat source countries worldwide. The dominant attack types are ssh bruteforce, spam, web attack. The majority of threats originate from networks operated by Iran Telecommunication Company PJS and Farahoosh Dena PLC.

Total Reports
518,728
Unique IPs
15,394
First Seen
2023-08-30
Last Activity
2026-04-16

Top Threat Categories

Ssh Bruteforce 870
Spam 130
Web Attack 99
Generic Bruteforce 68
Repeat Offender 20

Top Attacking Networks

AS58224 Iran Telecommunication Company PJS
2,457 IPs
AS44208 Farahoosh Dena PLC
1,600 IPs
AS213790 Limited Network LTD
1,258 IPs

Most Reported IPs in Iran

78.109.200.147 230 reports
185.213.165.65 229 reports
79.175.151.48 225 reports
185.116.160.35 222 reports
109.122.251.18 221 reports

Access this data via API

Get Iran threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/IR

View full API documentation

See how we classify and verify threats →

Check any IP from Iran

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS58224 Intelligence AS44208 Intelligence AS213790 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...