Search IP addresses by ...

IP prefix
IPv4 prefix/subnet in CIDR format.
Hostname suffix
Suffix of the hostname associated with the IP address. Can be used to search all hosts under given (sub)domain.
ASN
Autonomous system number. Enter as "1234" or "AS1234”.
Country
Code of the country the IP address is probably located in (according to MaxMind database).
Source
Select IP addresses for which there are data (alerts, events, ...) from given primary data source(s).
OR
AND
Event category
Select IP addresses with Warden alerts of given category.
OR
AND
Blacklist
Select IP addresses listed on given blacklist(s).
OR
AND
Tag
Select IP addresses with given tag(s).
OR
AND

Threat category

Role
Select IP addresses with threat category records matching the selected role.
Category
Select IP addresses with threat category records matching the selected category.
OR
AND
Subcategory
Select IP addresses with threat category records matching the selected subcategory.
=
Confidence
Minimum category confidence.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses
IP addresses
Paste any text containing IPv4 addresses or prefixes in CIDR format. Search will return all addresses in NERD matching any of your addresses or prefixes.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses

Results (≥20≥20)

IP address Hostname ASN Country Events Rep.(?) Threat category Other properties Time added Last activity Links
45.148.10.121 -- AS48090
NL 44218224
+ 811747 DShield reports
+ 31 OTX pulses
0.998
src login protocol: ssh
port: 22, 2222
src scan port: 22, 2222, 8022, 10022, 22222
src
15 blacklists  22scanner 2025-12-06 02:39:49 2026-05-13 14:54:42
80.94.92.168 -- AS48090
AS47890
RO 36829202
+ 101568 DShield reports
+ 25 OTX pulses
0.997
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
12 blacklists 2025-11-19 15:20:59 2026-05-13 14:58:20
2.57.122.238 -- AS48090
AS47890
RO 18373214
+ 243757 DShield reports
+ 8 OTX pulses
0.996
src login protocol: ssh
port: 22, 2222
src
src scan port: 22
16 blacklists  80scanner 2025-11-06 15:20:09 2026-05-13 14:51:25
2.57.121.25 hosting25.tronicsat.com AS47890
RO 19385172
+ 196959 DShield reports
+ 25 OTX pulses
0.995
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
12 blacklists 2025-10-05 10:37:13 2026-05-13 14:52:19
2.57.121.112 dns112.personaliseplus.com AS47890
RO 19705172
+ 205535 DShield reports
+ 18 OTX pulses
0.995
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
13 blacklists 2025-10-04 21:56:26 2026-05-13 14:43:29
87.251.64.176 -- AS200730
US 50994142
+ 328799 DShield reports
+ 12 OTX pulses
0.991
src login protocol: ssh
port: 22, 2222
src scan
src
5 blacklists 2026-04-21 16:30:41 2026-05-13 15:00:45
193.46.255.86 -- AS47890
RO 10013163
+ 53977 DShield reports
+ 4 OTX pulses
0.991
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
8 blacklists  22, 80, 2000scanner, eol-product 2026-03-11 22:22:32 2026-05-13 14:11:50
139.162.186.99 139-162-186-99.ip.linodeusercontent.com AS63949
DE 1291563
+ 101176 DShield reports
0.989
src scan port: many
src login protocol: http, ssh, telnet
port: 22, 23, 80, 2222
src exploit protocol: http
src
27 blacklists  22cloud 2025-04-12 02:01:32 2026-05-13 14:51:08
80.94.92.184 -- AS48090
AS47890
RO 15098193
+ 168768 DShield reports
+ 7 OTX pulses
0.987
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
15 blacklists  22scanner 2025-11-19 14:33:30 2026-05-13 14:57:14
80.94.92.182 -- AS48090
AS47890
RO 15111193
+ 161734 DShield reports
+ 8 OTX pulses
0.986
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
15 blacklists  22scanner 2025-11-18 16:26:32 2026-05-13 14:04:19
89.248.167.131 mason.census.shodan.io AS202425
NL 50942114
+ 54999 DShield reports
+ 1 OTX pulses
0.983
src scan port: many
src login protocol: ftp, ssh, telnet, vnc
port: 21
src
src exploit protocol: http
25 blacklists  22, 9002scanner 2024-08-06 17:33:36 2026-05-13 14:59:29
80.94.92.186 -- AS48090
AS47890
RO 13402193
+ 161327 DShield reports
+ 7 OTX pulses
0.983
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
15 blacklists  22, 80scanner 2025-11-18 16:25:46 2026-05-13 14:13:18
204.76.203.6 204.76.203.6.ptr.pfcloud.network AS51396
NL 167352
+ 29716 DShield reports
0.980
src scan port: many
src
src exploit protocol: http
14 blacklists 2026-05-04 18:32:16 2026-05-12 13:45:47
207.90.244.13 -- AS174
US 38404155
+ 242728 DShield reports
0.980
src scan port: 21
src
src login protocol: ftp, ssh, telnet, vnc
port: 21, 22, 2222
src exploit protocol: ftp, http
20 blacklists  22, 500, 4500, 9002vpn 2024-12-11 02:13:13 2026-05-13 15:00:29
35.212.204.23 23.204.212.35.bc.googleusercontent.com AS15169
AS19527
AS43515
US 115552
+ 35891 DShield reports
0.980
src scan
src
src login protocol: vnc
5 blacklists 2026-04-24 03:55:58 2026-05-13 10:08:08
80.94.92.171 -- AS48090
AS47890
RO 23271183
+ 85654 DShield reports
+ 12 OTX pulses
0.979
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
15 blacklists  22 2025-11-19 15:20:59 2026-05-13 14:47:52
86.54.31.38 blue2.census.shodan.io AS174
CA 49149124
+ 58758 DShield reports
+ 3 OTX pulses
0.978
src scan port: many
src login protocol: ftp, ssh
port: 21, 22, 2222
src
src exploit protocol: http
22 blacklists  22, 9002scanner 2025-04-09 00:04:34 2026-05-13 15:00:29
213.209.159.56 -- AS208137
TW 2482143
+ 19623 DShield reports
0.978
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
9 blacklists 2026-05-02 22:54:18 2026-05-13 14:43:29
150.254.160.250 rutherfordium.man.poznan.pl AS9112
PL 18414 0.976
src scan port: 21
src exploit protocol: ftp, http, mysql
src login protocol: ftp, mysql, ssh
port: 21, 22, 2222, 3306
18 blacklists 2026-03-22 18:28:21 2026-05-10 15:09:26
176.32.193.16 -- AS197834
AM 31654214
+ 66551 DShield reports
+ 3 OTX pulses
0.975
src scan port: many
src login protocol: rdp, redis, ssh
port: 22, 2222
src
13 blacklists 2026-03-12 10:40:05 2026-05-13 15:00:09