Notable Threat
IP address 147.185.132.249, a GOOGLE-CLOUD-PLATFORM address operating within AS396982 in the United States, presents a critical threat level of 10/10 based on 197 abuse reports submitted by automated honeypot sensors over an eight-month observation window from October 2025 through June 2026. The dominant threat category is general hacking activity, accounting for the majority of recent reports, supplemented by IoT-targeted probes, VoIP fraud indicators and exploited-host signatures. With an activity frequency rated at 6/10 and a confidence score of 78%, this IP demonstrates persistent, multi-vector malicious behaviour that warrants immediate blocking or strict access controls for any exposed service.
The 197 total reports attributed to 147.185.132.249 were generated across 20 distinct automated honeypot sensors, indicating broad detection coverage rather than isolated flagging. Observed attack patterns include general connection attempts, IoT and ICS-targeted probing, VoIP fraud activity, Suricata TLS invalid record type alerts, and malware or exploit-related behaviour. The sustained eight-month reporting period from first appearance in October 2025 through the most recent alert in June 2026 suggests this is not a transient or opportunistic address but rather infrastructure actively used for ongoing intrusion efforts. Hosting on GOOGLE-CLOUD-PLATFORM means the IP originates from a major cloud provider commonly leveraged by threat actors for its reputation, scalability and geographic flexibility.
Hacking activity as the primary threat category encompasses a range of intrusion attempts, vulnerability exploitation and unauthorized access vectors targeting exposed services. The accompanying IoT-targeted reports indicate the operator is systematically scanning for weakly secured connected devices, a tactic frequently employed to build botnets or compromise operational-technology environments. The presence of TLS protocol anomalies suggests reconnaissance probing of encryption implementations, potentially seeking unpatched services or misconfigured endpoints. VoIP fraud indicators add a financial motive dimension, as compromised phone infrastructure can be exploited for premium-rate call generation. Collectively, these patterns represent a credible risk to any internet-facing system within range of this address.