Search IP addresses by ...

IP prefix
IPv4 prefix/subnet in CIDR format.
Hostname suffix
Suffix of the hostname associated with the IP address. Can be used to search all hosts under given (sub)domain.
ASN
Autonomous system number. Enter as "1234" or "AS1234”.
Country
Code of the country the IP address is probably located in (according to MaxMind database).
Source
Select IP addresses for which there are data (alerts, events, ...) from given primary data source(s).
OR
AND
Event category
Select IP addresses with Warden alerts of given category.
OR
AND
Blacklist
Select IP addresses listed on given blacklist(s).
OR
AND
Tag
Select IP addresses with given tag(s).
OR
AND

Threat category

Role
Select IP addresses with threat category records matching the selected role.
Category
Select IP addresses with threat category records matching the selected category.
OR
AND
Subcategory
Select IP addresses with threat category records matching the selected subcategory.
=
Confidence
Minimum category confidence.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses
IP addresses
Paste any text containing IPv4 addresses or prefixes in CIDR format. Search will return all addresses in NERD matching any of your addresses or prefixes.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses

Results (≥20≥20)

IP address Hostname ASN Country Events Rep.(?) Threat category Other properties Time added Last activity Links
45.148.10.121 -- AS48090
NL 41598194
+ 912666 DShield reports
+ 49 OTX pulses
0.999
src login protocol: ssh
port: 22, 2222
src scan port: 22, 2222, 8022, 10022, 22222
src
12 blacklists  22scanner 2025-12-06 02:39:49 2026-06-11 18:38:29
2.57.122.238 -- AS48090
AS47890
RO 20641194
+ 277256 DShield reports
+ 11 OTX pulses
0.997
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
13 blacklists  80scanner 2025-11-06 15:20:09 2026-06-11 18:25:54
185.156.73.233 -- AS210848
AS211736
ZA 4849174
+ 223971 DShield reports
+ 15 OTX pulses
0.994
src login protocol: ssh
port: 22, 2222
src scan
src
13 blacklists  111 2025-05-15 03:41:41 2026-06-11 18:02:35
87.251.64.176 -- AS200730
US 124658152
+ 769154 DShield reports
+ 35 OTX pulses
0.994
src login protocol: ssh
port: 22, 2222
src scan
src
4 blacklists  22 2026-04-21 16:30:41 2026-06-11 18:41:50
80.94.92.171 -- AS48090
AS47890
RO 23628173
+ 92927 DShield reports
+ 29 OTX pulses
0.991
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
13 blacklists 2025-11-19 15:20:59 2026-06-11 18:34:53
80.94.92.168 -- AS48090
AS47890
RO 35485182
+ 104319 DShield reports
+ 29 OTX pulses
0.991
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
9 blacklists 2025-11-19 15:20:59 2026-06-11 18:42:39
213.209.159.158 -- AS208137
DE 17729174
+ 482078 DShield reports
+ 8 OTX pulses
0.983
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
13 blacklists 2025-12-29 18:58:08 2026-06-11 18:42:39
2.57.121.112 dns112.personaliseplus.com AS47890
RO 21232153
+ 229123 DShield reports
+ 20 OTX pulses
0.981
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
9 blacklists 2025-10-04 21:56:26 2026-06-11 18:40:15
213.209.159.56 -- AS208137
TW 8505153
+ 79099 DShield reports
+ 2 OTX pulses
0.981
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
10 blacklists 2026-05-02 22:54:18 2026-06-11 18:35:32
2.57.121.25 hosting25.tronicsat.com AS47890
RO 20177162
+ 220581 DShield reports
+ 27 OTX pulses
0.978
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
8 blacklists 2025-10-05 10:37:13 2026-06-11 18:40:15
45.148.10.147 -- AS48090
NL 7845142
+ 10208 DShield reports
+ 40 OTX pulses
0.976
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
12 blacklists 2026-01-21 16:55:29 2026-06-11 18:30:01
172.235.181.217 prod47client01.academyforinternetresearch.org AS63949
NL 1369294
+ 58412 DShield reports
0.974
src scan port: many
src login protocol: http, ssh, telnet
port: 22, 23, 80, 2222
src
src exploit
21 blacklists 2025-04-12 02:01:33 2026-06-11 18:41:09
172.235.168.35 172-235-168-35.ip.linodeusercontent.com AS63949
NL 24892114
+ 78131 DShield reports
0.973
src scan port: many
src login protocol: http, ssh, telnet
port: 22, 23, 80, 2222
src
src exploit
21 blacklists 2025-11-14 12:38:00 2026-06-11 18:41:10
45.148.10.151 -- AS48090
NL 7900142
+ 10309 DShield reports
+ 39 OTX pulses
0.972
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
12 blacklists 2026-01-21 16:55:29 2026-06-11 18:27:40
130.12.180.51 -- AS214943
AS202412
US 12244153
+ 383375 DShield reports
0.972
src login protocol: ssh
port: 22, 2222
dst malware_distribution
src botnet_drone
src scan
src
5 blacklists  22, 80, 443eol-product 2025-12-20 07:34:46 2026-06-11 17:21:58
176.32.193.16 -- AS197834
AM 50242224
+ 102110 DShield reports
+ 6 OTX pulses
0.969
src scan port: many
src login protocol: redis, ssh, telnet, vnc
port: 22, 23, 2222
src
14 blacklists 2026-03-12 10:40:05 2026-06-11 18:40:19
45.148.10.200 -- AS48090
NL 314152
+ 61121 DShield reports
+ 2 OTX pulses
0.968
src scan port: many
src
src login
src exploit protocol: http
14 blacklists 2026-05-27 20:08:57 2026-06-11 18:39:59
172.235.181.226 prod48client01.academyforinternetresearch.org AS63949
NL 1603774
+ 68410 DShield reports
0.967
src scan
src login protocol: http, ssh, telnet
port: 22, 23, 80, 2222
src exploit
src
18 blacklists  22cloud, cdn 2025-04-12 02:01:30 2026-06-11 18:41:10
207.90.244.13 -- AS174
US 38764145
+ 286583 DShield reports
0.967
src scan port: 135
src
src login protocol: ftp, ms-sql-s, ssh, telnet, vnc
port: 21, 22, 1433, 2222
src exploit protocol: ftp
15 blacklists  22, 500, 9002vpn 2024-12-11 02:13:13 2026-06-11 18:38:49
217.154.173.63 ip217-154-173-63.pbiaas.com AS8560
DE 4023123
+ 2597 DShield reports
+ 1 OTX pulses
0.966
src scan port: 22, 23, 80, 443, 2222, 2375
src login protocol: ssh, telnet
port: 22, 23, 2222
src
src exploit protocol: http
16 blacklists  22 2026-06-02 19:08:14 2026-06-10 16:25:13