Search IP addresses by ...

IP prefix
IPv4 prefix/subnet in CIDR format.
Hostname suffix
Suffix of the hostname associated with the IP address. Can be used to search all hosts under given (sub)domain.
ASN
Autonomous system number. Enter as "1234" or "AS1234”.
Country
Code of the country the IP address is probably located in (according to MaxMind database).
Source
Select IP addresses for which there are data (alerts, events, ...) from given primary data source(s).
OR
AND
Event category
Select IP addresses with Warden alerts of given category.
OR
AND
Blacklist
Select IP addresses listed on given blacklist(s).
OR
AND
Tag
Select IP addresses with given tag(s).
OR
AND

Threat category

Role
Select IP addresses with threat category records matching the selected role.
Category
Select IP addresses with threat category records matching the selected category.
OR
AND
Subcategory
Select IP addresses with threat category records matching the selected subcategory.
=
Confidence
Minimum category confidence.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses
IP addresses
Paste any text containing IPv4 addresses or prefixes in CIDR format. Search will return all addresses in NERD matching any of your addresses or prefixes.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses

Results (≥20≥20)

IP address Hostname ASN Country Events Rep.(?) Threat category Other properties Time added Last activity Links
45.148.10.121 -- AS48090
NL 35978174
+ 468694 DShield reports
+ 9 OTX pulses
1.000
src login protocol: ssh
port: 22
src scan port: 22, 2222, 8022, 51922
src
15 blacklists 2025-12-06 02:39:49 2026-02-14 18:34:22
2.57.121.25 hosting25.tronicsat.com AS47890
RO 10428163
+ 113524 DShield reports
+ 8 OTX pulses
0.999
src login protocol: ssh
src scan port: 22
10 blacklists 2025-10-05 10:37:13 2026-02-14 18:17:45
91.215.85.88 -- AS200593
RU 103536152
+ 1687282 DShield reports
0.998
src login protocol: ssh
port: 22
5 blacklists  135, 137, 5985, 50100 2025-11-14 08:31:47 2026-02-14 02:35:46
176.120.22.52 -- AS198953
RU 4249132
+ 92792 DShield reports
+ 13 OTX pulses
0.998
src login protocol: ssh
src scan port: many
6 blacklists 2026-01-16 11:03:58 2026-02-14 18:30:51
92.118.39.56 -- AS48090
AS47890
US 6875143
+ 336703 DShield reports
+ 5 OTX pulses
0.994
src scan port: 22
src login protocol: ssh
port: 22
14 blacklists  22scanner 2025-06-06 22:18:48 2026-02-14 18:12:03
80.94.92.168 -- AS48090
AS47890
RO 7608142
+ 95264 DShield reports
+ 4 OTX pulses
0.993
src login protocol: ssh
src scan port: 22
12 blacklists  22 2025-11-19 15:20:59 2026-02-14 18:30:51
80.94.92.171 -- AS48090
AS47890
RO 6564143
+ 226475 DShield reports
+ 5 OTX pulses
0.993
src login protocol: ssh
port: 22
src scan port: 22
15 blacklists  22scanner 2025-11-19 15:20:59 2026-02-14 18:33:09
2.57.122.238 -- AS48090
AS47890
RO 2803144
+ 182227 DShield reports
0.991
src login protocol: ssh
port: 22
src scan port: 22
src
16 blacklists  22, 80scanner 2025-11-06 15:20:09 2026-02-14 18:32:35
92.118.39.72 -- AS48090
AS47890
US 6286142
+ 346929 DShield reports
+ 121 OTX pulses
0.988
src login protocol: ssh
src scan port: 22
15 blacklists  22scanner 2025-01-05 11:23:47 2026-02-14 18:34:29
213.209.159.158 -- AS208137
DE 10262145
+ 89962 DShield reports
+ 2 OTX pulses
0.988
src login protocol: ssh
port: 22
src scan port: 22
src
16 blacklists  22scanner 2025-12-29 18:58:08 2026-02-14 18:32:38
147.139.164.196 -- AS45102
ID 2527113
+ 8876 DShield reports
+ 4 OTX pulses
0.985
src login protocol: ssh
src scan port: 22
src
5 blacklists  21, 22, 80, 443, 3306eol-product, database, self-signed, cloud 2024-10-17 09:08:32 2026-02-14 16:43:00
92.118.39.95 -- AS48090
AS47890
US 14611183
+ 164004 DShield reports
+ 4 OTX pulses
0.982
src scan port: 22
src login protocol: ssh
port: 22
16 blacklists 2025-04-16 06:10:40 2026-02-14 18:32:47
193.32.162.145 -- AS47890
RO 11049194
+ 159361 DShield reports
+ 1 OTX pulses
0.977
src login protocol: ssh
port: 22
src scan port: 22
16 blacklists  22scanner 2025-06-06 07:36:57 2026-02-14 16:18:55
94.154.35.215 -- AS214943
AS214976
AS202412
NL 1359692 0.976
src login protocol: ssh
port: 22
3 blacklists  135, 137, 139, 445, 5985, ... 2026-01-26 15:00:07 2026-02-14 18:17:48
179.43.133.154 hostedby.privatelayer.com AS51852
CH 21827102
+ 77326 DShield reports
0.975
src login protocol: ssh
port: 22
1 blacklist  135, 137, 445, 5985, 10000, ... 2025-09-02 11:59:39 2026-02-14 18:32:56
104.248.242.212 -- AS14061
DE 853103
+ 2884 DShield reports
+ 4 OTX pulses
0.972
src login protocol: ssh
src scan port: 22
src
4 blacklists  22cloud 2026-01-04 12:41:38 2026-02-14 17:55:32
2.57.121.112 dns112.personaliseplus.com AS47890
RO 12488163
+ 171057 DShield reports
+ 7 OTX pulses
0.970
src login protocol: ssh
src scan port: 22
12 blacklists 2025-10-04 21:56:26 2026-02-14 18:31:26
176.65.148.29 176.65.148.29.ptr.pfcloud.network AS51396
NL 850051
+ 149437 DShield reports
0.968
src scan port: 8332, 8545
4 blacklists  22, 80scanner 2026-01-08 22:28:08 2026-02-14 17:29:05
45.91.64.6 -- AS214664
RU 23829225
+ 46049 DShield reports
+ 8 OTX pulses
0.968
src login protocol: ftp, mysql, redis, ssh, telnet
port: 21, 3306
src scan port: many
src exploit protocol: ftp, mysql
src
13 blacklists 2025-12-18 12:59:28 2026-02-14 18:30:50
80.94.92.184 -- AS48090
AS47890
RO 7414163
+ 82289 DShield reports
+ 3 OTX pulses
0.968
src login protocol: ssh
port: 22
src scan port: 22
15 blacklists  22scanner 2025-11-19 14:33:30 2026-02-14 18:32:19