Search IP addresses by ...

IP prefix
IPv4 prefix/subnet in CIDR format.
Hostname suffix
Suffix of the hostname associated with the IP address. Can be used to search all hosts under given (sub)domain.
ASN
Autonomous system number. Enter as "1234" or "AS1234”.
Country
Code of the country the IP address is probably located in (according to MaxMind database).
Source
Select IP addresses for which there are data (alerts, events, ...) from given primary data source(s).
OR
AND
Event category
Select IP addresses with Warden alerts of given category.
OR
AND
Blacklist
Select IP addresses listed on given blacklist(s).
OR
AND
Tag
Select IP addresses with given tag(s).
OR
AND

Threat category

Role
Select IP addresses with threat category records matching the selected role.
Category
Select IP addresses with threat category records matching the selected category.
OR
AND
Subcategory
Select IP addresses with threat category records matching the selected subcategory.
=
Confidence
Minimum category confidence.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses
IP addresses
Paste any text containing IPv4 addresses or prefixes in CIDR format. Search will return all addresses in NERD matching any of your addresses or prefixes.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses

Results (≥20≥20)

IP address Hostname ASN Country Events Rep.(?) Threat category Other properties Time added Last activity Links
176.53.159.196 -- AS154383
TR 56619162
+ 498231 DShield reports
+ 47 OTX pulses
0.992
src login protocol: ssh
port: 22, 2222
src scan
3 blacklists  22 2026-07-01 15:29:24 2026-09-29 04:00:00
91.92.242.247 -- AS209800
AS214943
AS214976
AS202412
NL 24609112
+ 64191 DShield reports
0.985
src login protocol: ssh
port: 22, 2222
src scan
4 blacklists  22, 80 2026-09-16 17:45:23 2026-09-29 04:03:37
185.246.128.133 -- AS42237
SE 90275142
+ 190050 DShield reports
0.984
src login protocol: ssh
port: 22, 2222
src scan
4 blacklists IP in hostname  135, 137, 445, 5985 2023-08-01 09:26:36 2026-09-29 04:02:35
193.46.255.86 -- AS47890
RO 20839204
+ 129678 DShield reports
+ 1 OTX pulses
0.983
src login protocol: ssh
port: 22, 2222
src scan port: 22
7 blacklists  22, 80, 2000scanner, eol-product 2026-03-11 22:22:32 2026-09-29 03:54:22
2.57.122.238 -- AS48090
AS47890
RO 17087214
+ 374680 DShield reports
+ 20 OTX pulses
0.981
src login protocol: ssh
port: 22, 2222
src scan port: 22
src —
7 blacklists  80scanner 2025-11-06 15:20:09 2026-09-29 04:01:35
77.90.185.17 -- AS215476
AS213790
IR 3176122
+ 52658 DShield reports
+ 3 OTX pulses
0.966
src login protocol: ssh
port: 22, 2222
src scan
4 blacklists  22, 111 2026-09-04 19:46:47 2026-09-29 02:59:06
2.57.121.112 dns112.personaliseplus.com AS47890
RO 13379163
+ 114902 DShield reports
+ 4 OTX pulses
0.964
src login protocol: ssh
port: 22, 2222
src scan
7 blacklists IP in hostname  22scanner 2025-10-04 21:56:26 2026-09-29 03:43:59
172.104.233.215 172-104-233-215.ip.linodeusercontent.com AS63949
DE 189053
+ 8509 DShield reports
0.961
src login protocol: http, ssh, telnet
port: 23, 80
src scan port: many
src —
12 blacklists IP in hostname  22, 443, 8181self-signed, cloud 2026-09-17 19:56:54 2026-09-29 04:01:19
93.123.109.6 -- AS48090
AS401116
BG 370373
+ 82638 DShield reports
0.958
src —
src login protocol: ssh
port: 22, 2222
src scan port: 22, 2222, 8022, 38322
4 blacklists  22, 80, 443 2026-09-03 07:29:07 2026-09-29 03:49:21
77.239.124.130 -- AS198364
NL 4344123
+ 79257 DShield reports
+ 5 OTX pulses
0.955
src login protocol: ssh
port: 22, 2222
src scan port: 22, 2222, 8022, 38322
src —
6 blacklists  22, 443, 3333 2026-08-25 14:07:17 2026-09-29 01:53:12
45.148.10.5 -- AS48090
NL 236083
+ 20183 DShield reports
0.954
src scan port: 25, 80, 443, 465, 587
src login protocol: smtp, ssh
port: 22, 25, 2222
src —
12 blacklists  22scanner 2026-08-14 02:43:36 2026-09-29 03:38:29
192.248.150.180 192.248.150.180.vultrusercontent.com AS20473
GB 31461143
+ 114034 DShield reports
+ 10 OTX pulses
0.953
src scan port: many
src —
src login protocol: rdp, ssh
port: 22, 2222
7 blacklists IP in hostname 2026-06-05 20:15:01 2026-09-29 04:03:49
179.43.139.58 hostedby.privatelayer.com AS51852
CH 51527142
+ 353263 DShield reports
0.953
src login protocol: ssh
port: 22, 2222
src scan
3 blacklists  135, 137, 445, 5985, 10000, ... 2025-09-02 11:57:48 2026-09-29 03:33:30
102.220.161.139 -- AS197769
SI 29242
+ 2535 DShield reports
0.953
src scan port: 80, 443
18 blacklists 2026-09-14 05:02:57 2026-09-25 22:59:09
94.154.43.223 -- AS219502
NL 1184694
+ 66505 DShield reports
0.950
src scan port: 22, 80, 7860, 8080, 8081
src login protocol: ssh
port: 22, 2222
src —
10 blacklists  22 2026-09-07 08:56:39 2026-09-29 03:45:15
91.92.40.236 -- AS209630
AS197170
NL 1906173
+ 38961 DShield reports
0.947
src scan port: many
src —
9 blacklists  22, 80, 443, 3000, 5060, ... 2026-09-07 17:56:25 2026-09-29 04:03:59
45.148.10.95 -- AS48090
NL 117352
+ 40742 DShield reports
0.946
src scan port: many
15 blacklists  22scanner 2026-05-08 05:03:22 2026-09-25 14:02:03
193.32.162.84 -- AS47890
RO 4821174
+ 300479 DShield reports
+ 13 OTX pulses
0.944
src login protocol: ssh
port: 22, 2222
src —
src scan port: 22
11 blacklists  22scanner 2026-06-22 16:36:38 2026-09-29 04:02:03
45.91.64.7 scan.f6.security AS214664
RU 27673225
+ 99671 DShield reports
+ 1 MISP events
+ 7 OTX pulses
0.941
src scan port: many
src exploit protocol: mysql
6 blacklists 2025-12-18 12:59:18 2026-09-29 04:01:39
160.250.132.238 -- AS150895
AS153439
VN 14191123
+ 10043 DShield reports
0.938
src scan port: 22, 23, 80, 443, 2222, 2375
src login protocol: ssh, telnet
port: 22, 23
10 blacklists Residential proxy 2026-08-08 16:17:32 2026-09-29 03:56:00