Search IP addresses by ...

IP prefix
IPv4 prefix/subnet in CIDR format.
Hostname suffix
Suffix of the hostname associated with the IP address. Can be used to search all hosts under given (sub)domain.
ASN
Autonomous system number. Enter as "1234" or "AS1234”.
Country
Code of the country the IP address is probably located in (according to MaxMind database).
Source
Select IP addresses for which there are data (alerts, events, ...) from given primary data source(s).
OR
AND
Event category
Select IP addresses with Warden alerts of given category.
OR
AND
Blacklist
Select IP addresses listed on given blacklist(s).
OR
AND
Tag
Select IP addresses with given tag(s).
OR
AND

Threat category

Role
Select IP addresses with threat category records matching the selected role.
Category
Select IP addresses with threat category records matching the selected category.
OR
AND
Subcategory
Select IP addresses with threat category records matching the selected subcategory.
=
Confidence
Minimum category confidence.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses
IP addresses
Paste any text containing IPv4 addresses or prefixes in CIDR format. Search will return all addresses in NERD matching any of your addresses or prefixes.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses

Results (≥20≥20)

IP address Hostname ASN Country Events Rep.(?) Threat category Other properties Time added Last activity Links
176.53.159.196 -- AS154383
TR 45937162
+ 385353 DShield reports
+ 42 OTX pulses
0.994
src login protocol: ssh
port: 22, 2222
src scan
3 blacklists  22 2026-07-01 15:29:24 2026-09-04 18:52:37
2.57.122.238 -- AS48090
AS47890
RO 16499214
+ 314946 DShield reports
+ 18 OTX pulses
0.992
src login protocol: ssh
port: 22, 2222
src
src scan port: 22
12 blacklists  80scanner 2025-11-06 15:20:09 2026-09-04 18:30:09
185.246.128.133 -- AS42237
SE 78412152
+ 162448 DShield reports
0.985
src login protocol: ssh
port: 22, 2222
src scan
4 blacklists IP in hostname  135, 137, 445, 5985 2023-08-01 09:26:36 2026-09-04 18:55:15
179.43.139.58 hostedby.privatelayer.com AS51852
CH 62211152
+ 370837 DShield reports
0.985
src login protocol: ssh
port: 22, 2222
src scan
4 blacklists  135, 137, 445, 5985, 10000, ... 2025-09-02 11:57:48 2026-09-04 18:51:20
94.154.35.215 -- AS214943
AS214976
AS202412
NL 137414152
+ 484879 DShield reports
0.983
src login protocol: ssh
port: 22, 2222
src scan
6 blacklists  137, 5985, 10001, 10004, 10007, ... 2026-01-26 15:00:07 2026-09-04 18:42:26
194.180.49.37 -- AS201814
BG 264953
+ 2195742 DShield reports
+ 2 OTX pulses
0.980
src scan port: 22, 80, 443
src
25 blacklists 2026-08-04 03:10:51 2026-09-04 11:36:46
2.57.121.112 dns112.personaliseplus.com AS47890
RO 14511163
+ 98770 DShield reports
+ 5 OTX pulses
0.974
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
8 blacklists IP in hostname 2025-10-04 21:56:26 2026-09-04 18:54:47
213.209.159.154 -- AS208137
TW 959094
+ 157683 DShield reports
+ 7 OTX pulses
0.973
src scan port: 80, 443
src
21 blacklists Residential proxy  80eol-product 2026-05-07 06:30:28 2026-09-04 16:27:08
193.46.255.86 -- AS47890
RO 21421204
+ 100616 DShield reports
+ 4 OTX pulses
0.972
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
11 blacklists  22, 80, 2000eol-product, scanner 2026-03-11 22:22:32 2026-09-04 18:54:16
45.91.64.6 scan.f6.security AS214664
RU 37963165
+ 82510 DShield reports
+ 3 OTX pulses
0.970
src scan port: many
src login protocol: ftp, mysql, redis, ssh
port: 21, 22, 2222, 3306
src
13 blacklists 2025-12-18 12:59:28 2026-09-04 18:54:49
192.248.150.180 192.248.150.180.vultrusercontent.com AS20473
GB 28893133
+ 94502 DShield reports
+ 6 OTX pulses
0.968
src scan port: many
src
src login protocol: rdp, ssh
port: 22, 2222
8 blacklists IP in hostname 2026-06-05 20:15:01 2026-09-04 12:53:49
176.32.193.16 -- AS197834
AM 58111234
+ 107979 DShield reports
+ 17 OTX pulses
0.967
src scan port: many
src login protocol: redis, ssh, telnet
port: 22, 23, 2222
src
10 blacklists 2026-03-12 10:40:05 2026-09-04 18:53:59
77.90.185.20 -- AS215476
AS213790
IR 16819205
+ 292095 DShield reports
+ 3 OTX pulses
0.965
src login protocol: ssh
port: 22, 2222
src scan port: 22, 2022, 2222, 10022, 22222, 24442, 50000, 55555
dst malware_distribution
16 blacklists  22scanner 2026-07-05 00:40:46 2026-09-04 18:51:48
31.132.90.3 -- AS197556
KZ 22320453
+ 142436 DShield reports
+ 2 OTX pulses
0.965
src scan port: 22, 23, 80, 443, 2222, 2375
src
15 blacklists 2026-06-03 13:16:16 2026-09-04 18:55:49
2.57.122.53 -- AS48090
AS47890
RO 3392174
+ 77197 DShield reports
+ 1 OTX pulses
0.960
src scan port: 22
src login protocol: ssh
port: 22, 2222
src
9 blacklists  22, 80 2026-08-04 13:19:01 2026-09-04 16:00:20
45.148.10.183 -- AS48090
NL 6892164
+ 192755 DShield reports
+ 3 OTX pulses
0.958
src
src scan port: 22, 80, 443
src login protocol: ssh
port: 22, 2222
12 blacklists  22, 80, 443, 1080, 3389eol-product, scanner 2026-04-06 23:21:44 2026-09-04 18:51:50
150.254.160.250 rutherfordium.man.poznan.pl AS9112
PL 26214 0.957
src scan
21 blacklists 2026-06-28 09:40:40 2026-08-31 12:41:41
45.77.61.56 45.77.61.56.vultrusercontent.com AS20473
FR 15519123
+ 49726 DShield reports
+ 10 OTX pulses
0.955
src scan port: many
src
src login protocol: ssh
port: 22, 2222
8 blacklists IP in hostname 2026-07-17 17:18:58 2026-09-04 18:30:19
87.120.104.29 -- AS211443
NO 97232
+ 156032 DShield reports
0.954
src scan port: 80, 443, 8080, 8443
src
17 blacklists Residential proxy  1337self-signed 2026-08-20 12:47:49 2026-09-04 18:49:06
195.178.110.218 -- AS48090
BG 2248134
+ 129194 DShield reports
0.951
src
src scan port: 22
src login protocol: ssh
port: 22, 2222
11 blacklists  22, 80 2026-08-06 10:37:34 2026-09-04 16:35:39