← Back to feed

AS9009 M247 Europe SRL

ASN Active medium
Why this campaign was detected
6 IPs from the same network (M247 Europe SRL, AS9009) were active during overlapping time periods. Temporal correlation across a shared autonomous system suggests infrastructure controlled by the same entity.
Primary ASN
AS9009 · M247 Europe SRL
Subnet
Country
🇨🇭 CH
Cloud Provider
Member Count
6 IPs
Below average
Total Events
1295
Below average by volume
Started / Ended
2026-02-23 21:44 — ongoing
Attack Types
http:scan ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Initial Access
Credential Access
Discovery
Command and Control
Member Actors
IP Address Behavior Confidence Flags Events Agents Attack Types Hostname Last Seen
37.120.213.13 credential_harvester 56% VPN1x OSINT 220 3 ssh:bruteforce 2026-08-18 23:48 evidence →
95.181.232.51 scanner 47% VPN1x OSINT 49 3 ssh:bruteforce 2026-08-26 10:11 evidence →
80.97.44.68 credential_harvester 41% VPN 543 1 ssh:bruteforce 2026-08-04 04:08 evidence →
85.121.245.246 credential_harvester 41% VPN 538 1 ssh:bruteforce 2026-08-02 21:39 evidence →
193.226.76.34 scanner 25% VPN 16 1 ssh:bruteforce 2026-08-08 18:59 evidence →
62.133.46.26 web_probe 23% VPN 2 2 http:scan 2026-08-04 22:41 evidence →
VPN Known VPN or proxy provider
DROP ASN on Spamhaus DROP list
Nx OSINT Corroborated by N external threat feeds
{# Cloudflare Web Analytics — cookieless, public pages only. The context processor withholds the token from authenticated requests. #}