Significant Threat
IP address 147.185.132.153 is a high-risk threat actor associated with sustained unauthorized access attempts, with 421 abuse reports filed against this single address and a threat level rating of 8 out of 10. This Google Cloud Platform host (AS396982) has been actively targeting remote administration services since August 2025, with the most recent community reports logged in June 2026, indicating persistent rather than transient malicious behavior.
Automated honeypot sensors across 20 distinct detection points logged the majority of this activity, generating a confidence score of 74 percent based on consistent attack-pattern signatures. The sustained activity frequency of 7 out of 10 across an approximately 11-month observation window suggests this is not opportunistic scanning but rather a determined, automated campaign. All 20 recent threat-category reports classify the activity as general hacking, with sensor alerts flagging active SSH sessions on commonly probed ports alongside malformed TLS record types consistent with reconnaissance or credential-guessing tooling.
The dominant attack pattern involves repeated attempts to establish unauthorized SSH sessions, a technique used to guess weak credentials or exploit misconfigured authentication on exposed Linux infrastructure. TLS protocol anomalies detected alongside these sessions often indicate threat actors using encrypted tunnels or modified clients to evade detection during initial compromise attempts. For organizations running publicly accessible SSH services, even a small number of successful brute-force attempts can result in complete server takeover, data exfiltration, or use of the compromised host as a pivot point for lateral movement within a network.
Administrators should block this IP address immediately at the network perimeter and implement rate-limiting on SSH authentication endpoints to reduce exposure to credential-guessing campaigns. Enforcing key-based authentication exclusively, disabling root login, and deploying defensive tools such as fail2ban to automatically ban repeated offenders significantly reduces the effectiveness of such attacks. Regular monitoring of authentication logs for patterns consistent with this IP address and similar sources remains essential for early detection of ongoing or subsequent campaigns targeting the same infrastructure.