Malicious IPs in Saudi Arabia

IPv4 networks located in Saudi Arabia that are currently flagged for malicious activity, aggregated from multiple external and internal threat intelligence sources. Snapshot of (UTC), updated daily.

Flagged IPv4 networks
53
#45 of 176 countries
Per million allocated IPv4
4.71
#60 of 77 countries
Flagged IPv4 addresses
308
ranges count at most as a /24
Allocated IPv4 addresses
11,251,008
RIR delegation statistics

Saudi Arabia at a glance

Saudi Arabia had 53 flagged IPv4 networks in the snapshot of 2026-10-10, rank #45 of 176 countries by absolute count. Relative to its allocated IPv4 space that is 4.71 flagged networks per million addresses, rank #60 of 77, well below the median of 10.6 across all rated countries. The largest category is brute force sources with 45% of the flagged networks, followed by other malicious networks (30%). The three networks (ASNs) with the most flagged IPs hold 68% of them, led by Mobily-AS Etihad Etisalat, a joint stock company (AS35819). Another 7 flagged IPv6 networks are located in Saudi Arabia.

Malicious activity in Saudi Arabia by category

A network listed in several categories counts once, in the most specific one. Also flagged: 7 IPv6 networks.

  • Brute force sources in Saudi Arabia

    24 (45%)

    24 flagged networks, #49 of 159 countries for brute force sources. Sources of password guessing against SSH, mail, FTP and web logins. Brute Force Sources by Country

  • Other malicious networks in Saudi Arabia

    16 (30%)

    16 flagged networks, #37 of 147 countries for other malicious networks. Addresses and ranges reported as malicious without a more specific category. Other Malicious Networks by Country

  • Botnet hosts in Saudi Arabia

    12 (23%)

    12 flagged networks, #29 of 126 countries for botnet hosts. Infected hosts taking part in a botnet. Botnet Hosts by Country

  • Scanners in Saudi Arabia

    1 (2%)

    1 flagged network, #26 of 44 countries for scanners. Hosts scanning or probing services on the internet. Scanners by Country

Networks with the most flagged IPs in Saudi Arabia

Autonomous systems announcing the flagged networks located in Saudi Arabia.

#NetworkFlagged networks
1AS35819Mobily-AS Etihad Etisalat, a joint stock company15
2AS25019SAUDINETSTC-AS Saudi Telecom Company JSC15
3AS31898ORACLE-BMC-31898 - Oracle Corporation6
4AS39891ALJAWWALSTC-AS Saudi Telecom Company JSC5
5AS35753ITC Etihad Salam Telecom CJSC3
6AS43766MTC-KSA-AS Mobile Telecommunication Company Saudi Arabia Joint-Stock company3
7AS45102ALIBABA-CN-NET - Alibaba (US) Technology Co., Ltd.2
8AS8895ISU King Abdul Aziz City for Science and Technology1
9AS9009M247 M247 Europe SRL1
10AS154177LIGHT4-AS-AP - LIGHT NODE LIMITED1

Compare Saudi Arabia with other countries

Ranked by flagged networks per million allocated IPv4 addresses.

Countries ranked next to Saudi Arabia by rate

#CountryNetworksPer million
58Sweden1564.94
59South Africa1314.82
60Saudi Arabia534.71
61Portugal284.18
62Mexico1153.96
63Czechia383.96

Questions about Saudi Arabia

How many malicious IP addresses are there in Saudi Arabia?
On 2026-10-10, 53 IPv4 networks (/24 blocks) located in Saudi Arabia were flagged for malicious activity, with 308 listed IPv4 addresses and 7 IPv6 networks. Each /24 counts once, however many of its addresses are listed.
Which networks in Saudi Arabia host the most flagged IPs?
Mobily-AS Etihad Etisalat, a joint stock company (AS35819, 15 networks), SAUDINETSTC-AS Saudi Telecom Company JSC (AS25019, 15 networks), ORACLE-BMC-31898 - Oracle Corporation (AS31898, 6 networks). Large hosting providers appear because attackers rent their servers, not necessarily because of the operator.

Query this data per IP via the API

Look up threat categories, reputation score, ASN and geolocation for any address in Saudi Arabia or anywhere else with one API call.