Norway (NO) Threat Intelligence

NO

Norway has 3,200 malicious IP addresses with 117,816 abuse reports. Top threat categories include web attack, ssh bruteforce, mail bruteforce, tcp scan, ddos. Top attacking networks: Telenor Norge AS (374 IPs), Telia Norge AS (348 IPs), M247 Europe SRL (264 IPs). Data collected since 2025-12-06, last activity 2026-04-16.

Threat Assessment: Norway exhibits moderate cyber threat activity, with a notable number of malicious IPs across multiple attack categories. The dominant attack types are web attack, ssh bruteforce, mail bruteforce. The majority of threats originate from networks operated by Telenor Norge AS and Telia Norge AS.

Total Reports
117,816
Unique IPs
3,200
First Seen
2025-12-06
Last Activity
2026-04-16

Top Threat Categories

Web Attack 461
Ssh Bruteforce 51
Mail Bruteforce 10
Tcp Scan 7
Ddos 3

Top Attacking Networks

AS2119 Telenor Norge AS
374 IPs
AS25400 Telia Norge AS
348 IPs
AS9009 M247 Europe SRL
264 IPs

Most Reported IPs in Norway

46.29.238.171 233 reports
85.19.195.12 217 reports
185.12.59.118 216 reports
188.113.80.177 212 reports
188.124.133.173 212 reports

Access this data via API

Get Norway threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/NO

View full API documentation

See how we classify and verify threats →

Check any IP from Norway

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS2119 Intelligence AS25400 Intelligence AS9009 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...