High Risk
IP 147.185.132.165 is a high-risk address linked to sustained hacking activity, malware deployment, and targeted exploitation of IoT and ICS systems, with a maximum threat rating of 10/10 and 160 independent abuse reports spanning from August 2025 through June 2026. Operating from Google Cloud Platform (AS396982) within the United States, this IP has been flagged by 20 automated honeypot sensors detecting repeated intrusion attempts and active attack connections, indicating persistent malicious use of cloud infrastructure for hostile purposes over a nearly year-long period.
The volume and consistency of reports across multiple independent detection systems confirm a pattern of sustained, deliberate hostile activity rather than opportunistic scanning. Suricata signature alerts have identified SSH sessions established on non-standard ports, a common technique used to bypass standard port-based filtering and conceal remote access or command-and-control traffic. The combination of malware and exploit activity alongside explicit IoT and ICS targeting suggests this infrastructure supports multiple simultaneous attack campaigns aimed at both traditional enterprise systems and specialized operational technology environments. The Exploited Host classification in recent reports raises the possibility that this Google Cloud address may itself be running unauthorized tooling, leveraging the reputation of a major US cloud provider to evade initial reputation-based blocking.
The concrete risk to exposed organizations includes unauthorized access to servers, compromise of smart devices and industrial control systems, and potential use of compromised endpoints as pivots for deeper network intrusion. The SSH-on-unusual-port behavior indicates attempts to evade detection by security appliances that rely solely on port-based rules, while IoT/ICS targeting reflects interest in exploiting the historically weak security controls of connected devices and industrial systems.
Network defenders should block this IP immediately at perimeter firewalls and implement deep packet inspection capable of identifying SSH or encrypted tunnels on non-standard ports. Hardening exposed SSH services with fail2ban, key-based authentication, and strict connection monitoring significantly reduces the effectiveness of credential-based attacks. Isolating IoT and ICS devices on dedicated network segments, updating device firmware, replacing default credentials, and disabling unnecessary services further limits exposure to this class of threat. Organizations operating affected infrastructure should also consider submitting an abuse report to Google Cloud to contribute to broader remediation of this compromised or malicious cloud resource.