Search IP addresses by ...

IP prefix
IPv4 prefix/subnet in CIDR format.
Hostname suffix
Suffix of the hostname associated with the IP address. Can be used to search all hosts under given (sub)domain.
ASN
Autonomous system number. Enter as "1234" or "AS1234”.
Country
Code of the country the IP address is probably located in (according to MaxMind database).
Source
Select IP addresses for which there are data (alerts, events, ...) from given primary data source(s).
OR
AND
Event category
Select IP addresses with Warden alerts of given category.
OR
AND
Blacklist
Select IP addresses listed on given blacklist(s).
OR
AND
Tag
Select IP addresses with given tag(s).
OR
AND

Threat category

Role
Select IP addresses with threat category records matching the selected role.
Category
Select IP addresses with threat category records matching the selected category.
OR
AND
Subcategory
Select IP addresses with threat category records matching the selected subcategory.
=
Confidence
Minimum category confidence.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses
IP addresses
Paste any text containing IPv4 addresses or prefixes in CIDR format. Search will return all addresses in NERD matching any of your addresses or prefixes.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses

Results (≥20≥20)

IP address Hostname ASN Country Events Rep.(?) Threat category Other properties Time added Last activity Links
176.53.159.196 -- AS154383
TR 23825152
+ 175101 DShield reports
+ 12 OTX pulses
0.996
src login protocol: ssh
port: 22, 2222
src scan
3 blacklists 2026-07-01 15:29:24 2026-07-24 07:31:08
195.178.110.137 -- AS48090
BG 6803194
+ 362008 DShield reports
+ 9 OTX pulses
0.994
src login protocol: ssh
port: 22, 2222
src scan port: many
src
12 blacklists 2026-06-30 14:05:39 2026-07-24 06:31:27
2.57.122.238 -- AS48090
AS47890
RO 16925224
+ 260372 DShield reports
+ 13 OTX pulses
0.990
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
13 blacklists  80scanner 2025-11-06 15:20:09 2026-07-24 06:36:03
193.46.255.86 -- AS47890
RO 19389224
+ 71464 DShield reports
+ 4 OTX pulses
0.988
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
11 blacklists  22, 80, 2000scanner 2026-03-11 22:22:32 2026-07-24 07:09:00
2.57.121.25 hosting25.tronicsat.com AS47890
RO 19774183
+ 147885 DShield reports
+ 13 OTX pulses
0.981
src login protocol: ssh
port: 22, 2222
src scan port: 22
8 blacklists  22scanner 2025-10-05 10:37:13 2026-07-24 07:24:13
176.32.193.16 -- AS197834
AM 56753244
+ 109553 DShield reports
+ 12 OTX pulses
0.976
src scan port: many
src
src login protocol: redis, ssh
port: 22, 2222
13 blacklists 2026-03-12 10:40:05 2026-07-24 07:29:49
2.57.121.112 dns112.personaliseplus.com AS47890
RO 18013173
+ 142897 DShield reports
+ 10 OTX pulses
0.976
src login protocol: ssh
port: 22, 2222
src scan port: 22
9 blacklists 2025-10-04 21:56:26 2026-07-24 07:21:59
45.63.4.69 45.63.4.69.vultrusercontent.com AS20473
US 13717133
+ 31654 DShield reports
+ 3 OTX pulses
0.971
src scan port: many
src
src login protocol: ssh
port: 22, 2222
9 blacklists 2026-06-05 19:52:10 2026-07-24 07:29:30
45.148.10.200 -- AS48090
NL 806652
+ 311801 DShield reports
+ 6 OTX pulses
0.969
src scan port: 80, 443, 8080
src
15 blacklists  22scanner 2026-05-27 20:08:57 2026-07-24 07:16:51
192.248.150.180 192.248.150.180.vultrusercontent.com AS20473
GB 13157133
+ 36105 DShield reports
+ 2 OTX pulses
0.969
src scan port: many
src
src login protocol: ssh
port: 22, 2222
8 blacklists 2026-06-05 20:15:01 2026-07-24 07:28:54
207.90.244.3 -- AS174
US 32401155
+ 206711 DShield reports
0.968
src scan port: 21
src
src login protocol: ftp, ssh, telnet
port: 21, 22, 23, 2222
16 blacklists  22, 500, 4500, 9002vpn 2022-12-08 21:05:49 2026-07-24 07:23:39
207.90.244.27 -- AS174
US 39516145
+ 278659 DShield reports
0.967
src scan
src
src login protocol: ftp, ssh, telnet
port: 21, 22, 23, 2222
16 blacklists  22, 123, 500, 4500, 9002vpn 2025-04-17 23:25:56 2026-07-24 07:27:09
150.254.160.250 rutherfordium.man.poznan.pl AS9112
PL 15514 0.964
src scan port: 21
src exploit protocol: ftp, http, mysql
21 blacklists 2026-06-28 09:40:40 2026-07-20 10:10:30
172.104.241.98 prod50client01.academyforinternetresearch.org AS63949
DE 1328274
+ 120458 DShield reports
0.964
src scan port: many
src login protocol: http, ssh, telnet
port: 23, 80
21 blacklists  22cloud 2025-04-12 02:31:32 2026-07-24 07:22:48
94.154.43.243 -- AS219502
UA 11806473
+ 368778 DShield reports
+ 2 OTX pulses
0.963
src scan port: many
src
src login protocol: telnet
port: 23
11 blacklists 2026-07-10 15:25:04 2026-07-24 06:01:19
207.90.244.25 -- AS174
US 36496105
+ 280204 DShield reports
0.963
src scan
src
src login protocol: ftp, ssh
port: 21, 22, 2222
15 blacklists  22, 123, 500, 4500, 9002vpn 2025-04-17 23:19:22 2026-07-24 07:30:16
77.90.185.20 -- AS215476
AS213790
IR 4414205
+ 45666 DShield reports
0.963
src login protocol: ssh, telnet
port: 22, 23, 2222
src scan port: 22, 23
src
dst malware_distribution
src botnet_drone
11 blacklists  445, 5985 2026-07-05 00:40:46 2026-07-24 07:27:19
172.104.241.92 prod49client01.academyforinternetresearch.org AS63949
DE 1122973
+ 62267 DShield reports
0.962
src scan port: many
src login protocol: http, ssh, telnet
port: 22, 23, 80, 2222
22 blacklists  22cloud 2025-04-12 02:01:30 2026-07-24 07:21:13
80.82.77.202 rnd.group-ib.com AS202425
NL 32309104
+ 58078 DShield reports
+ 1 OTX pulses
0.962
src scan port: many
10 blacklists 2023-08-17 16:11:05 2026-07-24 07:30:49
207.90.244.2 -- AS174
US 32681125
+ 207424 DShield reports
0.960
src scan
src
src login protocol: ftp, ssh, telnet
port: 21, 22, 23, 2222
15 blacklists  22, 500, 4500, 9002vpn 2022-12-08 05:10:54 2026-07-24 07:17:50