Elevated Risk
IP address 147.185.132.141 is a high-risk address linked to sustained hacking activity and IoT-targeted exploitation attempts, with a threat level of 8/10 and 186 abuse reports filed over approximately seven months of observed malicious behavior. This Google Cloud Platform-hosted IP (AS396982) demonstrates consistent attack patterns scoring 6/10 on activity frequency, indicating persistent rather than opportunistic intrusion attempts.
Automated honeypot sensors across twenty distinct detection points recorded this activity between October 2025 and May 2026, generating 186 total reports dominated by hacking-related threat categories. The confidence score of 79% reflects substantial corroborating evidence from multiple independent sources, with recent reports continuing to flag both hacking intrusion attempts and IoT-targeted exploitation activity. Suricata alerts specifically document malformed TLS record types during connection attempts, a technique commonly employed during reconnaissance and vulnerability scanning against improperly configured services.
The dominant hacking activity represents automated attempts to gain unauthorized access to systems through exploit probing and intrusion techniques, while the concurrent IoT targeting activity indicates the address is being used to identify and compromise weakly secured connected devices such as cameras, routers, and other networked appliances. The TLS protocol anomalies suggest attackers are testing service responses or exploiting misconfigured endpoints that fail to enforce proper cryptographic handshake standards. Combined, these attack vectors create significant risk for any organization running exposed services or IoT infrastructure without proper network segmentation and security hardening.
Site operators should immediately block or rate-limit traffic from this address at the network perimeter, enforce strong certificate validation on all TLS endpoints, and implement intrusion detection rules to flag malformed TLS records and anomalous connection patterns. Deploying defensive tools such as fail2ban can automate temporary blocking of repeated probe attempts. Organizations with exposed IoT deployments should verify network segmentation, confirm all devices run current firmware, replace default credentials, and disable unnecessary protocols including UPnP to reduce attack surface.