Autonomous system
AS9009 M247
Hosting RIPE
Summary
M247 Europe SRL
hosting vps transit vpn
An Autonomous System of M247, a Manchester-headquartered hosting and network
provider (this entity is its Romania-based operation). Addresses here carry M247
hosting, colocation, transit, and a large amount of commercial VPN exit traffic.
What it's used for
- Dedicated servers, VPS, colocation, and IP transit across many global locations; also widely used as VPN infrastructure.
Notable
- One of the most commonly-seen commercial-VPN egress networks. An IP here identifies M247 as the host, not the tenant — a large share of this space is rented to VPN providers, so a hit on this ASN is very often a VPN exit rather than a server or a real end user.
- Long used as infrastructure for major consumer VPNs (e.g. NordVPN, HideMyAss) as well as smaller ones, which is why it turns up so frequently in IP lookups.
- M247 runs multiple ASNs — see sibling [AS9316](https://asn.ipinfo.app/AS9316)**.
Interesting
- M247 leases IP space and servers to many downstream VPN and hosting brands, so the geolocation of an M247 IP usually reflects the chosen exit city, not where the user actually is.
This description is AI-generated, best-effort context — not authoritative, and provided without any guarantee of accuracy. Source, and how to suggest an edit.
Address space
Summary
| Country | Name | Prefixes |
|---|---|---|
| RO | Romania | 2,977 |
Registry
Allocation record
- Registry
- RIPE
- Handle
AS9009- Registry name
- M247
- Registrant
- M247-EU-MNT
- Abuse contact
- abuse@m247.ro
- Registered
- 2011-04-11
- Last changed
- 2023-03-15
- Status
- active
Reputation
Classification and threat
Hosting Datacenter or cloud provider. Addresses are servers, not people.
51 IC3 indicators addresses in this network appear in FBI IC3 cybersecurity advisories.
| Prefix | Advisory | Published |
|---|---|---|
37.120.247.228 | Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite | 2026-07-23 |
135.136.1.133 | Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure | 2026-07-22 |
152.89.162.138 | "First VPN Service" Used by Ransomware Actors to Compromise Systems | 2026-05-21 |
152.89.162.139 | "First VPN Service" Used by Ransomware Actors to Compromise Systems | 2026-05-21 |
158.255.208.155 | "First VPN Service" Used by Ransomware Actors to Compromise Systems | 2026-05-21 |
185.247.71.106 | "First VPN Service" Used by Ransomware Actors to Compromise Systems | 2026-05-21 |
185.247.71.107 | "First VPN Service" Used by Ransomware Actors to Compromise Systems | 2026-05-21 |
185.253.98.242 | "First VPN Service" Used by Ransomware Actors to Compromise Systems | 2026-05-21 |
185.253.98.243 | "First VPN Service" Used by Ransomware Actors to Compromise Systems | 2026-05-21 |
193.239.86.18 | "First VPN Service" Used by Ransomware Actors to Compromise Systems | 2026-05-21 |
Showing the first 10 of 51.
Threat data is alpha. Absence of an indicator is not evidence of good behaviour, only of absence from this one feed.
Elsewhere