Search IP addresses by ...

IP prefix
IPv4 prefix/subnet in CIDR format.
Hostname suffix
Suffix of the hostname associated with the IP address. Can be used to search all hosts under given (sub)domain.
ASN
Autonomous system number. Enter as "1234" or "AS1234”.
Country
Code of the country the IP address is probably located in (according to MaxMind database).
Source
Select IP addresses for which there are data (alerts, events, ...) from given primary data source(s).
OR
AND
Event category
Select IP addresses with Warden alerts of given category.
OR
AND
Blacklist
Select IP addresses listed on given blacklist(s).
OR
AND
Tag
Select IP addresses with given tag(s).
OR
AND

Threat category

Role
Select IP addresses with threat category records matching the selected role.
Category
Select IP addresses with threat category records matching the selected category.
OR
AND
Subcategory
Select IP addresses with threat category records matching the selected subcategory.
=
Confidence
Minimum category confidence.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses
IP addresses
Paste any text containing IPv4 addresses or prefixes in CIDR format. Search will return all addresses in NERD matching any of your addresses or prefixes.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses

Results (≥20≥20)

IP address Hostname ASN Country Events Rep.(?) Threat category Other properties Time added Last activity Links
176.53.159.196 -- AS154383
TR 45410162
+ 381035 DShield reports
+ 42 OTX pulses
0.994
src login protocol: ssh
port: 22, 2222
src scan
3 blacklists  22 2026-07-01 15:29:24 2026-09-03 12:01:36
2.57.122.238 -- AS48090
AS47890
RO 16574214
+ 317740 DShield reports
+ 18 OTX pulses
0.991
src login protocol: ssh
port: 22, 2222
src
src scan port: 22
13 blacklists  80scanner 2025-11-06 15:20:09 2026-09-03 11:42:06
185.246.128.133 -- AS42237
SE 77680152
+ 162703 DShield reports
0.987
src login protocol: ssh
port: 22, 2222
src scan
4 blacklists IP in hostname  135, 137, 445, 5985 2023-08-01 09:26:36 2026-09-03 12:02:53
94.154.35.215 -- AS214943
AS214976
AS202412
NL 137538152
+ 486713 DShield reports
0.986
src login protocol: ssh
port: 22, 2222
src scan
6 blacklists  137, 5985, 10001, 10004, 10007, ... 2026-01-26 15:00:07 2026-09-03 11:44:27
179.43.139.58 hostedby.privatelayer.com AS51852
CH 61807152
+ 369472 DShield reports
0.984
src login protocol: ssh
port: 22, 2222
src scan
4 blacklists  135, 137, 445, 5985, 10000, ... 2025-09-02 11:57:48 2026-09-03 12:03:10
194.180.49.37 -- AS201814
BG 260453
+ 2191021 DShield reports
+ 2 OTX pulses
0.983
src scan port: 22, 80, 443
src
25 blacklists 2026-08-04 03:10:51 2026-09-03 10:52:08
193.46.255.86 -- AS47890
RO 21256204
+ 99323 DShield reports
+ 4 OTX pulses
0.980
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
11 blacklists  22, 80, 2000eol-product, scanner 2026-03-11 22:22:32 2026-09-03 11:33:11
31.132.90.3 -- AS197556
KZ 27254153
+ 141259 DShield reports
+ 2 OTX pulses
0.979
src scan port: 22, 23, 80, 443, 2222, 2375
src
15 blacklists 2026-06-03 13:16:16 2026-09-03 12:01:38
176.32.193.16 -- AS197834
AM 57986234
+ 108206 DShield reports
+ 17 OTX pulses
0.975
src scan port: many
src login protocol: redis, ssh, telnet
port: 22, 23, 2222
src
10 blacklists 2026-03-12 10:40:05 2026-09-03 12:03:10
213.209.159.154 -- AS208137
TW 955094
+ 155833 DShield reports
+ 7 OTX pulses
0.973
src scan port: 80, 443
src
20 blacklists Residential proxy  80eol-product 2026-05-07 06:30:28 2026-09-03 10:31:51
2.57.121.112 dns112.personaliseplus.com AS47890
RO 14531163
+ 97470 DShield reports
+ 5 OTX pulses
0.970
src login protocol: ssh
port: 22, 2222
src scan port: 22
8 blacklists IP in hostname 2025-10-04 21:56:26 2026-09-03 11:58:50
192.248.150.180 192.248.150.180.vultrusercontent.com AS20473
GB 28530133
+ 93055 DShield reports
+ 6 OTX pulses
0.969
src scan port: many
src
src login protocol: rdp, ssh
port: 22, 2222
8 blacklists IP in hostname 2026-06-05 20:15:01 2026-09-03 11:51:07
45.91.64.6 scan.f6.security AS214664
RU 38113165
+ 84547 DShield reports
+ 3 OTX pulses
0.963
src scan port: many
src login protocol: ftp, mysql, redis, ssh
port: 21, 22, 2222, 3306
14 blacklists 2025-12-18 12:59:28 2026-09-03 12:00:39
77.90.185.20 -- AS215476
AS213790
IR 16327205
+ 289429 DShield reports
+ 3 OTX pulses
0.961
src login protocol: ssh
port: 22, 2222
src scan port: 22, 2022, 2222, 10022, 22222, 24442, 50000, 55555
dst malware_distribution
15 blacklists  22scanner 2026-07-05 00:40:46 2026-09-03 12:00:22
195.178.110.218 -- AS48090
BG 2105134
+ 123011 DShield reports
0.961
src
src scan port: 22
src login protocol: ssh
port: 22, 2222
11 blacklists  22, 80 2026-08-06 10:37:34 2026-09-03 09:47:25
2.57.122.53 -- AS48090
AS47890
RO 3220174
+ 75495 DShield reports
+ 1 OTX pulses
0.961
src scan port: 22
src
src login protocol: ssh
port: 22, 2222
9 blacklists  22, 80 2026-08-04 13:19:01 2026-09-03 11:05:51
80.94.92.55 -- AS48090
AS47890
RO 4615175
+ 222940 DShield reports
+ 9 OTX pulses
0.958
src login protocol: ssh
port: 22, 2222
src
src scan port: 22
9 blacklists  22scanner 2026-06-24 19:33:55 2026-09-03 11:53:37
207.90.244.25 -- AS174
US 32900115
+ 248636 DShield reports
0.957
src scan port: 445
src
src login protocol: ftp, ssh, telnet
port: 21, 22, 23, 2222
11 blacklists  22, 123, 500, 4500, 9002vpn 2025-04-17 23:19:22 2026-09-03 12:01:29
150.254.160.250 rutherfordium.man.poznan.pl AS9112
PL 26214 0.957
src scan
21 blacklists 2026-06-28 09:40:40 2026-08-31 12:41:41
185.177.72.17 -- AS211590
FR 133244
+ 502521 DShield reports
0.956
19 blacklists  22, 123, 10250devops 2026-04-09 09:35:26 2026-08-23 03:15:48