Ukraine (UA) Threat Intelligence

UA

Ukraine has 61,388 malicious IP addresses with 1,290,987 abuse reports. Top threat categories include suspicious activity, severe abuse, moderate threat, high threat, ssh bruteforce. Top attacking networks: Kyivstar PJSC (3,827 IPs), Virtual Systems LLC (1,905 IPs), CHP Zarko Alexandr Ivanovich (1,902 IPs). Data collected since 2023-07-04, last activity 2026-08-15.

Threat Assessment: Ukraine shows substantial cyber threat activity, ranking among the top threat source countries worldwide. The dominant attack types are suspicious activity, severe abuse, moderate threat. The majority of threats originate from networks operated by Kyivstar PJSC and Virtual Systems LLC.

Total Reports
1,290,987
Unique IPs
61,388
First Seen
2023-07-04
Last Activity
2026-08-15

Top Threat Categories

Suspicious Activity 44,928
Severe Abuse 4,510
Moderate Threat 3,012
High Threat 1,751
Ssh Bruteforce 1,217

Top Attacking Networks

AS15895 Kyivstar PJSC
3,827 IPs
AS30860 Virtual Systems LLC
1,905 IPs
AS56812 CHP Zarko Alexandr Ivanovich
1,902 IPs

Most Reported IPs in Ukraine

77.87.40.114 648 reports
92.113.142.203 639 reports
82.193.122.91 623 reports
91.219.196.17 617 reports
176.36.146.80 617 reports

Access this data via API

Get Ukraine threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/UA

View full API documentation

See how we classify and verify threats →

Check any IP from Ukraine

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS15895 Intelligence AS30860 Intelligence AS56812 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...