Search IP addresses by ...

IP prefix
IPv4 prefix/subnet in CIDR format.
Hostname suffix
Suffix of the hostname associated with the IP address. Can be used to search all hosts under given (sub)domain.
ASN
Autonomous system number. Enter as "1234" or "AS1234”.
Country
Code of the country the IP address is probably located in (according to MaxMind database).
Source
Select IP addresses for which there are data (alerts, events, ...) from given primary data source(s).
OR
AND
Event category
Select IP addresses with Warden alerts of given category.
OR
AND
Blacklist
Select IP addresses listed on given blacklist(s).
OR
AND
Tag
Select IP addresses with given tag(s).
OR
AND

Threat category

Role
Select IP addresses with threat category records matching the selected role.
Category
Select IP addresses with threat category records matching the selected category.
OR
AND
Subcategory
Select IP addresses with threat category records matching the selected subcategory.
=
Confidence
Minimum category confidence.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses
IP addresses
Paste any text containing IPv4 addresses or prefixes in CIDR format. Search will return all addresses in NERD matching any of your addresses or prefixes.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses

Results (≥20≥20)

IP address Hostname ASN Country Events Rep.(?) Threat category Other properties Time added Last activity Links
45.148.10.121 -- AS48090
NL 41650194
+ 898510 DShield reports
+ 49 OTX pulses
0.998
src login protocol: ssh
port: 22, 2222
src scan port: 22, 2222, 8022, 10022, 22222
src
12 blacklists  22scanner 2025-12-06 02:39:49 2026-06-14 19:28:29
87.251.64.176 -- AS200730
US 132546152
+ 802110 DShield reports
+ 35 OTX pulses
0.994
src login protocol: ssh
port: 22, 2222
src scan
src
4 blacklists  22 2026-04-21 16:30:41 2026-06-14 19:38:35
185.156.73.233 -- AS210848
AS211736
ZA 5143174
+ 188568 DShield reports
+ 15 OTX pulses
0.993
src login protocol: ssh
port: 22, 2222
src scan
src
13 blacklists  111 2025-05-15 03:41:41 2026-06-14 08:38:43
2.57.122.238 -- AS48090
AS47890
RO 20713194
+ 275015 DShield reports
+ 11 OTX pulses
0.992
src login protocol: ssh
port: 22, 2222
src
src scan port: 22
13 blacklists  80scanner 2025-11-06 15:20:09 2026-06-14 19:15:10
80.94.92.171 -- AS48090
AS47890
RO 23570173
+ 91132 DShield reports
+ 29 OTX pulses
0.991
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
13 blacklists 2025-11-19 15:20:59 2026-06-14 19:24:00
80.94.92.168 -- AS48090
AS47890
RO 35054182
+ 101108 DShield reports
+ 29 OTX pulses
0.990
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
9 blacklists 2025-11-19 15:20:59 2026-06-14 19:40:59
213.209.159.56 -- AS208137
TW 9041153
+ 81015 DShield reports
+ 2 OTX pulses
0.989
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
10 blacklists 2026-05-02 22:54:18 2026-06-14 19:35:26
213.209.159.158 -- AS208137
DE 17720175
+ 467860 DShield reports
+ 8 OTX pulses
0.985
src login protocol: ssh
port: 22, 2222
src
src scan port: 22
dst malware_distribution
src botnet_drone
13 blacklists 2025-12-29 18:58:08 2026-06-14 19:40:09
2.57.121.25 hosting25.tronicsat.com AS47890
RO 20064162
+ 215760 DShield reports
+ 27 OTX pulses
0.984
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
8 blacklists 2025-10-05 10:37:13 2026-06-14 19:40:38
2.57.121.112 dns112.personaliseplus.com AS47890
RO 21202153
+ 228066 DShield reports
+ 20 OTX pulses
0.984
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
9 blacklists 2025-10-04 21:56:26 2026-06-14 18:54:05
130.12.180.51 -- AS214943
AS202412
US 12430153
+ 387669 DShield reports
0.972
src login protocol: ssh
port: 22, 2222
src botnet_drone
dst malware_distribution
src scan
src
5 blacklists  22, 80, 443eol-product 2025-12-20 07:34:46 2026-06-14 19:15:10
45.148.10.183 -- AS48090
NL 9247194
+ 423650 DShield reports
+ 2 OTX pulses
0.967
src
src login protocol: ssh
port: 22, 2222
src scan port: 22, 3389
14 blacklists  22, 80scanner 2026-04-06 23:21:44 2026-06-14 19:40:29
80.94.92.186 -- AS48090
AS47890
RO 13415183
+ 169313 DShield reports
+ 7 OTX pulses
0.964
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
12 blacklists  22scanner 2025-11-18 16:25:46 2026-06-14 19:35:04
80.94.92.184 -- AS48090
AS47890
RO 15003193
+ 174887 DShield reports
+ 8 OTX pulses
0.964
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
13 blacklists  22scanner 2025-11-19 14:33:30 2026-06-14 16:47:58
172.235.181.217 prod47client01.academyforinternetresearch.org AS63949
NL 1364594
+ 59500 DShield reports
0.959
src scan port: many
src login protocol: http, ssh, telnet
port: 22, 23, 80, 2222
src
src exploit
21 blacklists 2025-04-12 02:01:33 2026-06-14 19:31:05
176.32.193.16 -- AS197834
AM 52113224
+ 104822 DShield reports
+ 6 OTX pulses
0.958
src scan port: many
src
src login protocol: redis, ssh, telnet, vnc
port: 22, 23, 2222
14 blacklists 2026-03-12 10:40:05 2026-06-14 19:40:29
45.148.10.147 -- AS48090
NL 7864142
+ 10004 DShield reports
+ 40 OTX pulses
0.958
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
12 blacklists 2026-01-21 16:55:29 2026-06-14 19:23:07
80.94.92.182 -- AS48090
AS47890
RO 15208183
+ 174349 DShield reports
+ 9 OTX pulses
0.957
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
12 blacklists  22scanner 2025-11-18 16:26:32 2026-06-14 19:40:29
172.235.168.35 172-235-168-35.ip.linodeusercontent.com AS63949
NL 25074114
+ 78088 DShield reports
0.957
src scan port: many
src login protocol: http, ssh, telnet
port: 22, 23, 80, 2222
src
src exploit
21 blacklists 2025-11-14 12:38:00 2026-06-14 19:31:05
89.23.113.208 154851.ip-ptr.tech AS207713
RU 3226174
+ 1710 DShield reports
0.955
src scan port: 22, 23, 80, 443, 2222, 2375
src login protocol: ssh, telnet
port: 22, 23, 2222
src
src exploit protocol: http
13 blacklists 2026-05-23 22:12:10 2026-06-14 19:27:21