Critical Alert
IP 147.185.132.175 is a critical-risk address operating from Google Cloud Platform infrastructure that has accumulated 199 abuse reports documenting sustained hacking activity, with automated honeypot sensors flagging repeated attempts to establish unauthorized SSH sessions on unconventional network ports over a seven-month observation window.
Community-driven threat reports and automated honeypot detections together document 199 separate incidents linked to this address between October 2025 and May 2026, yielding a 10/10 threat score. All 20 of the most recent reports classify the activity as hacking, and the detection profile aligns with a pattern of non-standard SSH connection attempts detected by Suricata intrusion-prevention rules. The address originates from AS396982 (GOOGLE-CLOUD-PLATFORM) in the United States, a major cloud provider whose infrastructure is frequently repurposed by threat actors precisely because cloud-based sources often face fewer automatic blocklisting decisions from network defenders.
The dominant hacking classification, corroborated by the Suricata "SSH session in progress on Unusual Port" alert, indicates this host is actively probing target systems using Secure Shell on ports that deviate from the default TCP/22. Attackers employ this technique to bypass naive firewall rules that only monitor standard SSH ports, reduce detection by signature-based tools, and target management interfaces that administrators assume are hidden. The sustained report volume over seven months confirms this is not opportunistic scanning but persistent, deliberate intrusion-oriented activity capable of exploiting unpatched SSH daemons, weak credentials, or misconfigured access controls on exposed services.
Network defenders should immediately block this address at the perimeter firewall or via inbound access-control lists, and should review all authentication logs for matching source-IP entries to identify any successful compromise. Deploying fail2ban or equivalent dynamic blocklist tools that automatically mitigate repeated SSH connection attempts provides ongoing protection against this class of activity. Hardening SSH configurations to permit connections only on standard ports, enforcing key-based authentication in preference to passwords, and implementing rate-limiting on authentication endpoints substantially reduces the attack surface that this address is probing. Ongoing monitoring of honeypot telemetry and community threat feeds will help identify resurgence under related infrastructure.