Search IP addresses by ...

IP prefix
IPv4 prefix/subnet in CIDR format.
Hostname suffix
Suffix of the hostname associated with the IP address. Can be used to search all hosts under given (sub)domain.
ASN
Autonomous system number. Enter as "1234" or "AS1234”.
Country
Code of the country the IP address is probably located in (according to MaxMind database).
Source
Select IP addresses for which there are data (alerts, events, ...) from given primary data source(s).
OR
AND
Event category
Select IP addresses with Warden alerts of given category.
OR
AND
Blacklist
Select IP addresses listed on given blacklist(s).
OR
AND
Tag
Select IP addresses with given tag(s).
OR
AND

Threat category

Role
Select IP addresses with threat category records matching the selected role.
Category
Select IP addresses with threat category records matching the selected category.
OR
AND
Subcategory
Select IP addresses with threat category records matching the selected subcategory.
=
Confidence
Minimum category confidence.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses
IP addresses
Paste any text containing IPv4 addresses or prefixes in CIDR format. Search will return all addresses in NERD matching any of your addresses or prefixes.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses

Results (≥20≥20)

IP address Hostname ASN Country Events Rep.(?) Threat category Other properties Time added Last activity Links
176.53.159.196 -- AS154383
TR 51045162
+ 470925 DShield reports
+ 47 OTX pulses
0.992
src login protocol: ssh
port: 22, 2222
src scan
3 blacklists  22 2026-07-01 15:29:24 2026-10-08 05:42:46
193.46.255.86 -- AS47890
RO 19594204
+ 135399 DShield reports
+ 1 OTX pulses
0.982
src login protocol: ssh
port: 22, 2222
src scan port: 22
src —
10 blacklists  22, 2000scanner 2026-03-11 22:22:32 2026-10-08 05:39:04
185.246.128.133 -- AS42237
SE 92557142
+ 196831 DShield reports
0.979
src login protocol: ssh
port: 22, 2222
src scan
3 blacklists IP in hostname  135, 137, 445, 5985 2023-08-01 09:26:36 2026-10-08 05:38:33
172.235.235.248 172-235-235-248.ip.linodeusercontent.com AS63949
IT 2723484
+ 123191 DShield reports
0.977
src login protocol: http, ssh, telnet
port: 22, 23, 80, 2222
src scan port: many
13 blacklists IP in hostname  22cdn, cloud 2025-11-14 12:38:01 2026-10-08 05:42:30
2.57.122.238 -- AS48090
AS47890
RO 16797214
+ 377999 DShield reports
+ 17 OTX pulses
0.976
src —
src login protocol: ssh
port: 22, 2222
src scan port: 22
7 blacklists  80scanner 2025-11-06 15:20:09 2026-10-08 05:38:33
179.43.139.58 hostedby.privatelayer.com AS51852
CH 51264142
+ 357110 DShield reports
0.971
src login protocol: ssh
port: 22, 2222
src scan
2 blacklists  139, 445, 5985, 10000, 10001, ... 2025-09-02 11:57:48 2026-10-08 05:40:17
195.178.110.232 -- AS48090
BG 5293154
+ 400913 DShield reports
+ 17 OTX pulses
0.966
src —
src login protocol: ssh
port: 22, 2222
src scan port: 22
11 blacklists  22scanner 2026-06-24 20:32:22 2026-10-08 05:43:11
45.138.12.51 -- AS218785
LT 103032
+ 44482 DShield reports
0.966
src scan port: 80, 443
src —
15 blacklists Residential proxy 2026-09-19 00:52:00 2026-10-08 04:54:06
94.154.43.196 -- AS219502
NL 7246363
+ 50125 DShield reports
0.965
src scan port: 23, 80, 443, 2323, 7860, 8082, 60001, 61616
src —
src login protocol: ssh, telnet
port: 23, 8080
9 blacklists  22scanner 2026-07-23 02:14:18 2026-10-08 05:42:39
150.254.160.250 rutherfordium.man.poznan.pl AS9112
PL 35714 0.964
src scan port: 21
19 blacklists 2026-06-28 09:40:40 2026-10-05 23:23:58
2.57.121.112 dns112.personaliseplus.com AS47890
RO 12937173
+ 123316 DShield reports
+ 2 OTX pulses
0.964
src login protocol: ssh
port: 22, 2222
src scan port: 22
7 blacklists IP in hostname  22scanner 2025-10-04 21:56:26 2026-10-08 05:40:17
45.148.10.5 -- AS48090
NL 415483
+ 26637 DShield reports
0.964
src scan port: 25, 80, 443, 465, 587
src —
src login protocol: smtp
port: 25
14 blacklists  22, 5201scanner 2026-08-14 02:43:36 2026-10-08 05:42:36
160.250.132.238 -- AS150895
AS153439
VN 25768133
+ 15870 DShield reports
0.963
src scan port: 22, 23, 80, 443, 2222, 2375
src login protocol: ssh, telnet
port: 22, 23, 2222
13 blacklists Residential proxy 2026-08-08 16:17:32 2026-10-08 05:15:12
79.124.58.82 ip-58-82.superbithost.com AS50360
BG 55442
+ 29918 DShield reports
0.963
src scan port: 80, 443, 8080, 8443
src —
15 blacklists IP in hostname 2026-10-01 02:38:18 2026-10-08 05:14:33
196.189.236.67 -- AS24757
ET 215093
+ 2007 DShield reports
0.963
src scan port: 22, 23, 80, 443, 2222, 2375
src login protocol: ssh, telnet
port: 22, 23, 2222
14 blacklists Residential proxy 2026-09-29 04:40:53 2026-10-08 05:15:06
93.123.109.6 -- AS48090
AS401116
BG 5800113
+ 121892 DShield reports
0.960
src —
src login protocol: ssh
port: 22, 2222
src scan port: 22, 1723, 2222, 8022, 38322
4 blacklists  22, 80, 443 2026-09-03 07:29:07 2026-10-08 04:43:22
2.57.122.53 -- AS48090
AS47890
RO 7756194
+ 185463 DShield reports
+ 1 OTX pulses
0.959
src login protocol: ssh
port: 22, 2222
src scan port: 22, 5902
src —
9 blacklists  22, 80scanner 2026-08-04 13:19:01 2026-10-08 05:42:10
195.178.110.228 -- AS48090
BG 4633144
+ 412709 DShield reports
+ 1 MISP events
+ 21 OTX pulses
0.959
src —
src scan port: 22
src login protocol: ssh
port: 22, 2222
11 blacklists  22scanner 2026-06-24 23:55:25 2026-10-08 02:00:48
77.239.124.130 -- AS198364
NL 6025123
+ 103489 DShield reports
+ 5 OTX pulses
0.957
src —
src scan port: 22, 2222, 8022, 38322
src login protocol: ssh
port: 22, 2222
6 blacklists  22scanner 2026-08-25 14:07:17 2026-10-08 04:16:19
77.90.185.20 -- AS215476
AS213790
IR 27011205
+ 528221 DShield reports
+ 3 OTX pulses
0.955
src login protocol: ssh
port: 22, 2222
src scan port: 22, 222, 2022, 2222, 10022, 22022, 22222, 24442, 50000
6 blacklists  22scanner 2026-07-05 00:40:46 2026-10-08 05:40:59