Search IP addresses by ...

IP prefix
IPv4 prefix/subnet in CIDR format.
Hostname suffix
Suffix of the hostname associated with the IP address. Can be used to search all hosts under given (sub)domain.
ASN
Autonomous system number. Enter as "1234" or "AS1234”.
Country
Code of the country the IP address is probably located in (according to MaxMind database).
Source
Select IP addresses for which there are data (alerts, events, ...) from given primary data source(s).
OR
AND
Event category
Select IP addresses with Warden alerts of given category.
OR
AND
Blacklist
Select IP addresses listed on given blacklist(s).
OR
AND
Tag
Select IP addresses with given tag(s).
OR
AND

Threat category

Role
Select IP addresses with threat category records matching the selected role.
Category
Select IP addresses with threat category records matching the selected category.
OR
AND
Subcategory
Select IP addresses with threat category records matching the selected subcategory.
=
Confidence
Minimum category confidence.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses
IP addresses
Paste any text containing IPv4 addresses or prefixes in CIDR format. Search will return all addresses in NERD matching any of your addresses or prefixes.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses

Results (≥20≥20)

IP address Hostname ASN Country Events Rep.(?) Threat category Other properties Time added Last activity Links
45.148.10.121 -- AS48090
NL 41450204
+ 912484 DShield reports
+ 49 OTX pulses
0.999
src login protocol: ssh
port: 22, 2222
src scan port: 22, 2222, 8022, 10022, 22222
src
12 blacklists  22scanner 2025-12-06 02:39:49 2026-06-09 15:50:08
87.251.64.176 -- AS200730
US 119323152
+ 735128 DShield reports
+ 35 OTX pulses
0.995
src login protocol: ssh
port: 22, 2222
src scan
src
4 blacklists  22 2026-04-21 16:30:41 2026-06-09 15:50:51
2.57.122.238 -- AS48090
AS47890
RO 20407204
+ 277411 DShield reports
+ 11 OTX pulses
0.994
src login protocol: ssh
port: 22, 2222
src
src scan port: 22
13 blacklists  80scanner 2025-11-06 15:20:09 2026-06-09 15:25:19
80.94.92.171 -- AS48090
AS47890
RO 23509173
+ 94180 DShield reports
+ 29 OTX pulses
0.992
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
13 blacklists  22 2025-11-19 15:20:59 2026-06-09 15:48:33
80.94.92.168 -- AS48090
AS47890
RO 35473182
+ 105672 DShield reports
+ 29 OTX pulses
0.988
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
9 blacklists  22scanner 2025-11-19 15:20:59 2026-06-09 15:48:33
185.156.73.233 -- AS210848
AS211736
ZA 4827174
+ 231165 DShield reports
+ 15 OTX pulses
0.982
src login protocol: ssh
port: 22, 2222
src scan
src
13 blacklists  22, 111 2025-05-15 03:41:41 2026-06-09 14:45:09
172.235.181.226 prod48client01.academyforinternetresearch.org AS63949
NL 1605174
+ 68410 DShield reports
0.978
src scan
src login protocol: http, ssh, telnet
port: 22, 23, 80, 2222
src
src exploit
18 blacklists  22cloud, cdn 2025-04-12 02:01:30 2026-06-09 15:41:22
139.162.186.99 139-162-186-99.ip.linodeusercontent.com AS63949
DE 1287073
+ 116308 DShield reports
0.977
src scan port: many
src login protocol: http, ssh, telnet
port: 22, 23, 80, 2222
src exploit
src
21 blacklists  22cloud 2025-04-12 02:01:32 2026-06-09 15:41:11
152.32.226.205 test1234.asia AS135377
HK 115498153
+ 22939 DShield reports
+ 1 OTX pulses
0.977
src scan port: 22, 23, 80, 443, 2222, 2375
src login protocol: ssh, telnet
port: 22, 23, 2222
src
src exploit protocol: http
18 blacklists  111 2026-05-12 09:36:46 2026-06-09 15:46:10
2.57.121.25 hosting25.tronicsat.com AS47890
RO 20007162
+ 218821 DShield reports
+ 27 OTX pulses
0.977
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
8 blacklists 2025-10-05 10:37:13 2026-06-09 15:50:08
2.57.121.112 dns112.personaliseplus.com AS47890
RO 20893153
+ 228741 DShield reports
+ 20 OTX pulses
0.977
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
9 blacklists 2025-10-04 21:56:26 2026-06-09 15:38:56
213.209.159.56 -- AS208137
TW 8027153
+ 75555 DShield reports
+ 2 OTX pulses
0.976
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
10 blacklists 2026-05-02 22:54:18 2026-06-09 15:47:56
213.209.159.158 -- AS208137
DE 17629184
+ 484185 DShield reports
+ 8 OTX pulses
0.974
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
13 blacklists 2025-12-29 18:58:08 2026-06-08 21:27:43
207.90.244.13 -- AS174
US 38830155
+ 288897 DShield reports
0.971
src scan
src
src login protocol: ftp, ssh, telnet, vnc
port: 21, 22, 2222
src exploit protocol: ftp
16 blacklists  22, 500, 9002vpn 2024-12-11 02:13:13 2026-06-09 15:51:19
176.32.193.16 -- AS197834
AM 48832214
+ 99466 DShield reports
+ 6 OTX pulses
0.969
src scan port: many
src login protocol: redis, ssh, telnet, vnc
port: 22, 23, 2222
src
15 blacklists 2026-03-12 10:40:05 2026-06-09 15:51:09
107.189.24.77 77.24.189.107.static.cloudzy.com AS14956
NL 9608153
+ 4196 DShield reports
+ 1 OTX pulses
0.969
src scan port: 22, 23, 80, 443, 2222, 2375
src login protocol: ssh, telnet
port: 22, 23, 2222
src
src exploit protocol: http
17 blacklists 2026-05-07 07:26:36 2026-06-09 15:26:27
207.90.244.3 -- AS174
US 39413165
+ 284447 DShield reports
0.968
src scan port: 445
src
src login protocol: ftp, ssh, telnet
port: 21, 22, 2222
16 blacklists  22, 500, 4500, 9002vpn 2022-12-08 21:05:49 2026-06-09 15:44:00
80.94.92.184 -- AS48090
AS47890
RO 15010193
+ 181634 DShield reports
+ 8 OTX pulses
0.968
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
13 blacklists  22scanner 2025-11-19 14:33:30 2026-06-09 15:48:11
176.65.139.66 -- AS51396
AS214472
DE 1139184
+ 38574 DShield reports
0.968
src scan port: 22, 23, 80, 5555, 8080
src
src login protocol: ssh, telnet
port: 22, 23
src exploit
12 blacklists 2026-04-23 05:00:31 2026-06-09 15:49:29
172.104.241.98 prod50client01.academyforinternetresearch.org AS63949
DE 1219984
+ 106454 DShield reports
0.967
src scan port: many
src login protocol: http, ssh, telnet, vnc
port: 22, 23, 80, 2222
src exploit
src
21 blacklists  22cloud 2025-04-12 02:31:32 2026-06-08 10:56:23