IP Report
95.174.65.52
M247 Europe SRL · AS9009 · Christianshavn, Denmark
Score 45 of 100, in the low risk band. Bands run 0 to 19 minimal, 20 to 49 low, 50 to 79 medium, 80 to 100 high.
Its risk score of 45/100 is low-to-moderate: some signal is present, but on its own it would not justify blocking a visitor.
Detection signals
Not detected: Tor, Proxy, Crawler
Summary
95.174.65.52 is part of a VPN service's infrastructure. Visitors arriving from it are relaying their traffic through the service, so the address says where the tunnel ends, not where the person is.
The address is announced by M247 Europe SRL (AS9009) and geolocates to Christianshavn, Capital Region, Denmark.
Why this address scores 45
It falls within IP ranges operated by VPN providers, so the address conceals where its traffic really originates.
It sits in datacenter address space, where automated traffic vastly outnumbers human visitors.
Individually these are weak signals; together they lift the score to 45/100, which is enough to be worth noting but not enough to act on by itself.
Observation history
This address has been looked up through Predax once, on August 31, 2026.
Network & location
- ASN
- AS9009
- Country
- Denmark (DK)
- Provider
- M247 Europe SRL
- Region
- Capital Region
- CIDR
- 95.174.64.0/22
- City
- Christianshavn
- Network type
- hosting
- First seen
- 8/31/2026, 9:31:05 AM
- Last seen
- 8/31/2026, 9:31:05 AM
- Times seen
- 1
Network context
We have observed 1,066 addresses on M247 Europe SRL (AS9009); 100% of them carried a threat flag or a notable risk score when last checked.
That is a high concentration — on this network, an unfamiliar address deserves more caution than its individual score alone would suggest.
What to do with this
If you run a site and this address showed up
Blocking VPN and proxy addresses outright also blocks real customers who use privacy tools every day.
If a visitor from this address disputes a block, look at what they did — the request pattern — rather than where they came from. Unblocking a disputed VPN address is usually the right call unless the behaviour itself was abusive.
If you found this address in your logs
The real client behind this address is elsewhere; geolocation and per-IP identity are both misleading for it.
Expect many unrelated users to share this address over time. Rate limits keyed on it will throttle strangers together, so prefer account- or token-level limits for anything that matters.
Loading map...
Detection sources
- DatacenterVerified · 95%
Listed in a published datacenter range feed. Hosted in a cloud / datacenter range. Typical of automation, scrapers, and bots — not consumer browsers.
- VPNHigh · 85%
Commercial VPN provider's published ranges. Traffic from a VPN exit. Could be a privacy-conscious user, or an adversary using a VPN to evade rate limits — context matters.