Severe Risk
IP 147.185.132.100 is a high-risk address with a maximum threat score of 10 out of 10, linked to active hacking activity including unauthorized SSH access attempts detected across multiple automated honeypot sensors over an extended reporting period.
The IP has accumulated 200 total abuse reports with a 78 percent confidence rating, sourced exclusively from 20 automated honeypot sensors that captured attack connection activity. Geolocated in the United States and operating through Google Cloud Platform infrastructure (ASN AS396982), this address was first reported in September 2025 and remained active through June 2026, indicating persistent rather than opportunistic behavior. A Suricata detection signature flagged an SSH session in progress on an expected port, confirming targeted brute-force or credential-stuffing activity directed at exposed SSH services. The moderate activity frequency score of 3 out of 10 suggests the attacks occur in periodic waves rather than continuous bombardment, a pattern consistent with automated scanning campaigns that cycle through target ranges.
Hacking activity as documented in these reports represents unauthorized intrusion attempts against networked services, with SSH being a particularly high-value target due to its widespread use for remote server administration. An attacker successfully establishing an SSH session could gain command-line access to a vulnerable system, potentially escalating privileges, exfiltrating data, or deploying additional malicious tooling. The use of cloud provider infrastructure for this activity is a known tactic that allows threat actors to blend malicious traffic with legitimate cloud operations and rotate source addresses rapidly, making attribution and blocking more difficult for network defenders.
Network administrators should block this IP address at the perimeter firewall level and monitor inbound authentication logs for repeated failed SSH login attempts originating from this address range. Implementing rate-limiting on SSH authentication endpoints, enforcing key-based authentication in preference to password authentication, and deploying automated threat-response tools such as fail2ban significantly reduces exposure to the intrusion techniques this address has demonstrated. Organizations with exposed SSH services should additionally consider restricting access via VPN or IP allowlisting where operationally feasible to minimize attack surface.