Search IP addresses by ...

IP prefix
IPv4 prefix/subnet in CIDR format.
Hostname suffix
Suffix of the hostname associated with the IP address. Can be used to search all hosts under given (sub)domain.
ASN
Autonomous system number. Enter as "1234" or "AS1234”.
Country
Code of the country the IP address is probably located in (according to MaxMind database).
Source
Select IP addresses for which there are data (alerts, events, ...) from given primary data source(s).
OR
AND
Event category
Select IP addresses with Warden alerts of given category.
OR
AND
Blacklist
Select IP addresses listed on given blacklist(s).
OR
AND
Tag
Select IP addresses with given tag(s).
OR
AND

Threat category

Role
Select IP addresses with threat category records matching the selected role.
Category
Select IP addresses with threat category records matching the selected category.
OR
AND
Subcategory
Select IP addresses with threat category records matching the selected subcategory.
=
Confidence
Minimum category confidence.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses
IP addresses
Paste any text containing IPv4 addresses or prefixes in CIDR format. Search will return all addresses in NERD matching any of your addresses or prefixes.

Sorting options

Sort by
Order
DESC
ASC
Max. number of addresses

Results (≥20≥20)

IP address Hostname ASN Country Events Rep.(?) Threat category Other properties Time added Last activity Links
45.148.10.121 -- AS48090
NL 41308194
+ 873891 DShield reports
+ 49 OTX pulses
0.999
src login protocol: ssh
port: 22, 2222
src scan port: 22, 2222, 8022, 10022, 22222
src
12 blacklists  22 2025-12-06 02:39:49 2026-06-20 18:14:30
87.251.64.176 -- AS200730
US 146589152
+ 887439 DShield reports
+ 35 OTX pulses
0.992
src login protocol: ssh
port: 22, 2222
src scan
src
4 blacklists  22 2026-04-21 16:30:41 2026-06-20 18:11:50
2.57.122.238 -- AS48090
AS47890
RO 20592194
+ 269437 DShield reports
+ 11 OTX pulses
0.986
src login protocol: ssh
port: 22, 2222
src
src scan port: 22
13 blacklists  80scanner 2025-11-06 15:20:09 2026-06-20 17:44:40
80.94.92.171 -- AS48090
AS47890
RO 23585173
+ 86344 DShield reports
+ 29 OTX pulses
0.985
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
13 blacklists 2025-11-19 15:20:59 2026-06-20 17:45:29
80.94.92.168 -- AS48090
AS47890
RO 34448172
+ 95758 DShield reports
+ 29 OTX pulses
0.983
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
10 blacklists 2025-11-19 15:20:59 2026-06-20 17:55:29
2.57.121.25 hosting25.tronicsat.com AS47890
RO 19545163
+ 201832 DShield reports
+ 27 OTX pulses
0.983
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
8 blacklists 2025-10-05 10:37:13 2026-06-20 17:59:47
2.57.121.112 dns112.personaliseplus.com AS47890
RO 20615153
+ 213510 DShield reports
+ 20 OTX pulses
0.981
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
9 blacklists 2025-10-04 21:56:26 2026-06-20 17:44:26
143.20.49.38 ip-38.49.20.143.in-addr.arpa AS150249
ID 35624383
+ 3849 DShield reports
0.977
src scan port: 22, 23, 80, 443, 2222, 2375
src login protocol: ssh, telnet
port: 22, 23, 2222
src
src exploit protocol: http
src botnet_drone malware_family: win.echelon, win.oni
18 blacklists 2026-06-06 03:38:44 2026-06-20 17:42:28
193.46.255.86 -- AS47890
RO 15062204
+ 69800 DShield reports
+ 4 OTX pulses
0.976
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
11 blacklists  22, 80, 2000scanner, eol-product 2026-03-11 22:22:32 2026-06-20 17:49:33
45.148.10.183 -- AS48090
NL 10170204
+ 442751 DShield reports
+ 2 OTX pulses
0.975
src
src login protocol: ssh
port: 22, 2222
src scan port: 22, 3389
14 blacklists  80 2026-04-06 23:21:44 2026-06-20 18:15:19
77.83.246.97 200635.ip-ptr.tech AS215540
PL 18311964
+ 1565 DShield reports
0.970
src scan port: 22, 23, 80, 443, 2222, 2375
src login protocol: ssh, telnet
port: 22, 23, 2222
src
src exploit protocol: http
17 blacklists  22 2026-06-09 19:30:23 2026-06-20 17:55:45
80.94.95.211 -- AS204428
RO 111022
+ 118270 DShield reports
+ 1 OTX pulses
0.966
src scan port: 80, 443
src
src login
src exploit
19 blacklists 2026-05-16 05:05:32 2026-06-20 17:14:58
176.112.128.143 dhcp-dynamic-176-112-128-143.broadband.nlink.ru AS56420
RU 288394
+ 3665 DShield reports
0.966
src scan port: 22, 23, 80, 443, 2222, 2375
src login protocol: ssh, telnet
port: 22, 23, 2222
src
src exploit protocol: http
13 blacklists 2026-06-08 01:30:30 2026-06-20 07:19:03
185.211.94.76 185-211-94-76.static.xelon.ch AS206123
CH 1246540133
+ 13607 DShield reports
+ 1 OTX pulses
0.966
src scan port: 22, 23, 80, 443, 2222, 2375
src login protocol: ssh, telnet
port: 22, 23, 2222
src
src exploit protocol: http
19 blacklists  22 2026-01-31 05:07:53 2026-06-20 17:54:06
213.209.159.56 -- AS208137
TW 9451153
+ 82766 DShield reports
+ 2 OTX pulses
0.965
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
10 blacklists 2026-05-02 22:54:18 2026-06-20 16:16:18
176.32.193.16 -- AS197834
AM 55795234
+ 111198 DShield reports
+ 6 OTX pulses
0.963
src scan port: many
src login protocol: ssh, telnet
port: 22, 23, 2222
src
14 blacklists 2026-03-12 10:40:05 2026-06-20 18:11:00
176.65.144.128 -- AS209413
DE 100132
+ 26127 DShield reports
0.963
src scan port: 80, 443
src
src exploit protocol: http
18 blacklists  22 2026-05-30 04:00:39 2026-06-20 17:33:51
31.132.90.3 -- AS197556
KZ 25089053
+ 11915 DShield reports
0.962
src scan port: 22, 23, 80, 443, 2222, 2375
src login protocol: ssh, telnet
port: 22, 23
src
src exploit protocol: http
15 blacklists 2026-06-03 13:16:16 2026-06-20 18:15:19
146.190.153.30 adeptus.census.shodan.io AS14061
US 27295145
+ 165498 DShield reports
0.959
src scan port: 21, 135
src
src login protocol: ftp, ssh, vnc
port: 21, 22, 2222
src exploit protocol: ftp
14 blacklists  22, 500, 9002vpn, cloud 2025-09-20 14:47:12 2026-06-20 18:11:58
80.94.92.186 -- AS48090
AS47890
RO 13251173
+ 161924 DShield reports
+ 7 OTX pulses
0.959
src login protocol: ssh
port: 22, 2222
src scan port: 22
src
12 blacklists  22scanner 2025-11-18 16:25:46 2026-06-20 18:12:48