Search IP addresses by ...

IP prefix
IPv4 prefix/subnet in CIDR format.
Hostname suffix
Suffix of the hostname associated with the IP address. Can be used to search all hosts under given (sub)domain.
ASN
Autonomous system number. Enter as "1234" or "AS1234”.
Country
Code of the country the IP address is probably located in (according to MaxMind database).
Source
Select IP addresses for which there are data (alerts, events, ...) from given primary data source(s).
OR
AND
Event category
Select IP addresses with Warden alerts of given category.
OR
AND
Blacklist
Select IP addresses listed on given blacklist(s).
OR
AND
Tag
Select IP addresses with given tag(s).
OR
AND

Threat category

Role
Select IP addresses with threat category records matching the selected role.
Category
Select IP addresses with threat category records matching the selected category.
OR
AND
Subcategory
Select IP addresses with threat category records matching the selected subcategory.
=
Confidence
Minimum category confidence.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses
IP addresses
Paste any text containing IPv4 addresses or prefixes in CIDR format. Search will return all addresses in NERD matching any of your addresses or prefixes.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses

Results (≥20≥20)

IP address Hostname ASN Country Events Rep.(?) Threat category Other properties Time added Last activity Links
176.53.159.196 -- AS154383
TR 53891162
+ 487360 DShield reports
+ 47 OTX pulses
0.989
src login protocol: ssh
port: 22, 2222
src scan
1 blacklist  22 2026-07-01 15:29:24 2026-10-05 05:09:18
193.46.255.86 -- AS47890
RO 20391204
+ 132742 DShield reports
+ 1 OTX pulses
0.976
src login protocol: ssh
port: 22, 2222
src scan port: 22
4 blacklists  22, 2000scanner 2026-03-11 22:22:32 2026-10-05 05:11:11
185.246.128.133 -- AS42237
SE 90901142
+ 192645 DShield reports
0.970
src login protocol: ssh
port: 22, 2222
src scan
1 blacklist IP in hostname  135, 137, 445, 5985 2023-08-01 09:26:36 2026-10-05 04:59:11
2.57.122.238 -- AS48090
AS47890
RO 16891214
+ 374443 DShield reports
+ 17 OTX pulses
0.968
src —
src scan port: 22
src login protocol: ssh
port: 22, 2222
4 blacklists  80scanner 2025-11-06 15:20:09 2026-10-05 04:36:03
2.57.121.112 dns112.personaliseplus.com AS47890
RO 13323173
+ 119521 DShield reports
+ 3 OTX pulses
0.963
src login protocol: ssh
port: 22, 2222
src scan port: 22
4 blacklists IP in hostname  22scanner 2025-10-04 21:56:26 2026-10-05 05:09:18
179.43.139.58 hostedby.privatelayer.com AS51852
CH 51107142
+ 352575 DShield reports
0.951
src login protocol: ssh
port: 22, 2222
src scan
 445, 5985, 10000, 10001, 10010, ... 2025-09-02 11:57:48 2026-10-05 04:29:28
93.123.109.6 -- AS48090
AS401116
BG 506473
+ 107566 DShield reports
0.942
src —
src scan port: 22, 1723, 2222, 8022, 38322
src login protocol: ssh
port: 22, 2222
2 blacklists  22, 80, 443 2026-09-03 07:29:07 2026-10-05 04:37:48
94.154.43.223 -- AS219502
NL 14372154
+ 78509 DShield reports
0.923
src scan port: 22, 7681, 8080
src —
src login protocol: ssh
port: 22, 2222
3 blacklists  22 2026-09-07 08:56:39 2026-10-05 05:11:39
77.239.124.130 -- AS198364
NL 5428123
+ 93981 DShield reports
+ 5 OTX pulses
0.922
src login protocol: ssh
port: 22, 2222
src scan port: 22, 2222, 8022, 38322
src —
3 blacklists  22scanner 2026-08-25 14:07:17 2026-10-05 05:10:40
94.154.43.69 -- AS219502
NL 10717124
+ 48597 DShield reports
+ 1 MISP events
+ 1 OTX pulses
0.922
src scan port: 22, 23, 53, 123, 389, 2323, 8080
src login protocol: ssh
port: 22, 2222
src —
3 blacklists  22, 80, 5000scanner 2026-07-21 18:14:05 2026-10-05 04:41:32
2.57.121.25 hosting25.tronicsat.com AS47890
RO 14822172
+ 124707 DShield reports
+ 2 OTX pulses
0.911
src scan port: 22, 23, 80, 443, 554, 5554, 8554, 32764, 37215
src login protocol: ssh
port: 22, 2222
5 blacklists IP in hostname  22scanner 2025-10-05 10:37:13 2026-10-05 05:10:10
2.57.122.53 -- AS48090
AS47890
RO 6637194
+ 155768 DShield reports
+ 1 OTX pulses
0.904
src login protocol: ssh
port: 22, 2222
src scan port: 22, 5902
src —
3 blacklists  22, 80scanner 2026-08-04 13:19:01 2026-10-05 05:09:49
77.90.185.20 -- AS215476
AS213790
IR 26743205
+ 503019 DShield reports
+ 3 OTX pulses
0.900
src login protocol: ssh
port: 22, 2222
src scan port: 22, 222, 2022, 2222, 10022, 22022, 22222, 24442, 50000
7 blacklists  22scanner 2026-07-05 00:40:46 2026-10-05 05:08:27
185.218.86.25 -- AS218785
BG 1485952
+ 152345 DShield reports
0.900
src —
src scan port: 53, 80, 443, 3000
2 blacklists 2026-09-07 21:54:11 2026-10-05 05:08:39
45.135.193.198 45.135.193.198.ptr.pfcloud.network AS51396
DE 2066152
+ 114961 DShield reports
0.897
src scan port: many
src —
4 blacklists IP in hostname  22scanner 2026-08-23 16:39:18 2026-10-05 05:08:00
45.91.64.7 scan.f6.security AS214664
RU 29327235
+ 104874 DShield reports
+ 1 MISP events
+ 7 OTX pulses
0.895
src scan port: many
src exploit protocol: mysql
3 blacklists 2025-12-18 12:59:18 2026-10-05 05:07:29
89.248.172.12 asm.group-ib.com AS202425
NL 40784104
+ 81447 DShield reports
0.884
src scan port: many
4 blacklists 2026-07-27 10:06:20 2026-10-05 05:10:10
94.154.43.31 -- AS219502
UA 2635663
+ 91364 DShield reports
+ 1 OTX pulses
0.883
src scan port: many
4 blacklists  80scanner, eol-product 2026-06-28 19:19:38 2026-10-05 05:11:40
45.135.193.159 45.135.193.159.ptr.pfcloud.network AS51396
DE 1076462
+ 290045 DShield reports
0.881
src scan port: 23, 80, 2211, 6036, 6037, 9600, 17000, 17010, 17032
src —
3 blacklists IP in hostname 2026-09-06 09:15:21 2026-10-05 05:08:39
45.91.64.6 scan.f6.security AS214664
RU 38534215
+ 77745 DShield reports
+ 3 OTX pulses
0.880
src scan port: many
3 blacklists 2025-12-18 12:59:28 2026-10-05 05:10:00