Search IP addresses by ...

IP prefix
IPv4 prefix/subnet in CIDR format.
Hostname suffix
Suffix of the hostname associated with the IP address. Can be used to search all hosts under given (sub)domain.
ASN
Autonomous system number. Enter as "1234" or "AS1234”.
Country
Code of the country the IP address is probably located in (according to MaxMind database).
Source
Select IP addresses for which there are data (alerts, events, ...) from given primary data source(s).
OR
AND
Event category
Select IP addresses with Warden alerts of given category.
OR
AND
Blacklist
Select IP addresses listed on given blacklist(s).
OR
AND
Tag
Select IP addresses with given tag(s).
OR
AND

Threat category

Role
Select IP addresses with threat category records matching the selected role.
Category
Select IP addresses with threat category records matching the selected category.
OR
AND
Subcategory
Select IP addresses with threat category records matching the selected subcategory.
=
Confidence
Minimum category confidence.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses
IP addresses
Paste any text containing IPv4 addresses or prefixes in CIDR format. Search will return all addresses in NERD matching any of your addresses or prefixes.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses

Results (≥20≥20)

IP address Hostname ASN Country Events Rep.(?) Threat category Other properties Time added Last activity Links
45.148.10.121 -- AS48090
NL 43867224
+ 821632 DShield reports
+ 31 OTX pulses
0.998
src login protocol: ssh
port: 22, 2222
src scan port: 22, 2222, 8022, 10022, 22222
src
15 blacklists  22scanner 2025-12-06 02:39:49 2026-05-14 11:36:30
80.94.92.168 -- AS48090
AS47890
RO 36784202
+ 102818 DShield reports
+ 25 OTX pulses
0.998
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
12 blacklists  22scanner 2025-11-19 15:20:59 2026-05-14 11:36:37
2.57.122.238 -- AS48090
AS47890
RO 18390214
+ 246902 DShield reports
+ 8 OTX pulses
0.995
src login protocol: ssh
port: 22, 2222
src
src scan port: 22
16 blacklists  80scanner 2025-11-06 15:20:09 2026-05-14 11:29:48
193.46.255.86 -- AS47890
RO 10096163
+ 54941 DShield reports
+ 4 OTX pulses
0.995
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
8 blacklists  22, 80, 2000scanner, eol-product 2026-03-11 22:22:32 2026-05-14 11:43:27
2.57.121.112 dns112.personaliseplus.com AS47890
RO 19663172
+ 208615 DShield reports
+ 18 OTX pulses
0.995
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
13 blacklists 2025-10-04 21:56:26 2026-05-14 11:45:11
2.57.121.25 hosting25.tronicsat.com AS47890
RO 19358172
+ 200065 DShield reports
+ 25 OTX pulses
0.994
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
12 blacklists 2025-10-05 10:37:13 2026-05-14 11:45:11
87.251.64.176 -- AS200730
US 53004142
+ 345004 DShield reports
+ 12 OTX pulses
0.994
src login protocol: ssh
port: 22, 2222
src scan
src
5 blacklists 2026-04-21 16:30:41 2026-05-14 11:46:26
80.94.92.171 -- AS48090
AS47890
RO 23280183
+ 86969 DShield reports
+ 12 OTX pulses
0.993
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
15 blacklists  22 2025-11-19 15:20:59 2026-05-14 11:44:39
80.94.92.184 -- AS48090
AS47890
RO 15252193
+ 170960 DShield reports
+ 7 OTX pulses
0.986
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
15 blacklists  22scanner 2025-11-19 14:33:30 2026-05-14 11:44:25
213.209.159.56 -- AS208137
TW 2662143
+ 22718 DShield reports
0.985
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
9 blacklists 2026-05-02 22:54:18 2026-05-14 11:29:13
207.90.244.10 -- AS174
US 38450155
+ 218253 DShield reports
0.984
src scan port: 21
src
src login protocol: ftp, ssh
port: 21, 22, 2222
src exploit protocol: ftp, http
18 blacklists  22, 500, 4500, 9002vpn 2023-06-22 02:59:30 2026-05-14 11:45:19
207.90.244.20 -- AS174
US 38903115
+ 241208 DShield reports
0.978
src scan
src
src login protocol: ftp, ssh
port: 21, 22, 2222
src exploit protocol: ftp, http
19 blacklists  22, 123, 500, 4500, 9002vpn 2025-04-17 23:01:18 2026-05-14 11:45:29
207.90.244.13 -- AS174
US 38345155
+ 246419 DShield reports
0.976
src scan port: 21
src
src login protocol: ftp, ssh, telnet, vnc
port: 21, 22, 2222
src exploit protocol: ftp, http
20 blacklists  22, 500, 4500, 9002vpn 2024-12-11 02:13:13 2026-05-14 11:45:09
207.90.244.22 -- AS174
US 38483145
+ 243208 DShield reports
0.975
src scan
src
src login protocol: ftp, ms-sql-s, ssh, telnet, vnc
port: 21, 22, 1433, 2222
src exploit protocol: ftp, http
19 blacklists  22, 123, 500, 4500, 9002vpn 2025-04-17 23:09:24 2026-05-14 11:45:09
176.32.193.16 -- AS197834
AM 32148214
+ 67846 DShield reports
+ 3 OTX pulses
0.974
src scan port: many
src login protocol: rdp, redis, ssh
port: 22, 2222
src
13 blacklists 2026-03-12 10:40:05 2026-05-14 11:45:09
207.90.244.21 -- AS174
US 38055125
+ 244065 DShield reports
0.974
src scan port: 21
src
src login protocol: ftp, ssh, telnet
port: 21, 22, 23, 2222
src exploit protocol: http
19 blacklists  22, 123, 500, 4500, 9002vpn 2025-06-20 19:12:40 2026-05-14 11:45:09
2.59.22.234 red3.census.shodan.io AS174
AT 31964104
+ 44943 DShield reports
0.973
src scan port: many
src
src login protocol: ftp, ssh
port: 21, 22, 2222
src exploit protocol: http
22 blacklists 2025-02-26 18:28:58 2026-05-14 11:44:09
45.91.64.6 scan.f6.security AS214664
RU 47849285
+ 86892 DShield reports
+ 10 OTX pulses
0.973
src scan port: many
src
src login protocol: ssh, telnet, vnc
port: 22, 23, 2222
20 blacklists 2025-12-18 12:59:28 2026-05-14 11:46:20
207.90.244.5 -- AS174
US 39332145
+ 237386 DShield reports
0.972
src scan
src
src login protocol: ftp, ssh, telnet, vnc
port: 21, 22, 2222
src exploit protocol: ftp, http
18 blacklists  22, 500, 4500, 9002vpn 2022-12-10 20:58:44 2026-05-14 11:45:19
45.148.10.157 -- AS48090
NL 7640142
+ 9286 DShield reports
+ 28 OTX pulses
0.971
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
14 blacklists 2026-01-21 16:55:29 2026-05-14 11:38:40