Elevated Risk
IP 147.185.132.97 is a high-risk address operating from Google Cloud Platform infrastructure (AS396982) in the United States, assessed at an 8/10 threat level with 78% confidence based on 192 total abuse reports from automated honeypot sensors. The dominant threat profile centres on general hacking activity, accounting for the vast majority of recent reports, alongside isolated web application attack probes and VoIP fraud indicators.
The IP was first reported in September 2025 and most recently in June 2026, indicating approximately nine months of documented hostile activity with a moderate activity frequency rating of 3/10. Network inspection by honeypot sensors captured multiple Suricata alerts flagging broken acknowledgment packets and application layer protocol mismatches, classic indicators of reconnaissance and exploitation attempts against exposed services. Community reporting and sensor telemetry together generated reports from 20 distinct automated sources, lending reasonable confidence to the assessment despite the moderate activity cadence.
The hacking classification encompasses a broad spectrum of intrusion activity, including vulnerability exploitation, unauthorized access attempts, and scanning behaviour that precedes targeted attacks. The presence of stream-level packet anomalies suggests the actor may be testing firewall or intrusion detection response thresholds while probing for misconfigured or outdated services. Combined with web application probing activity targeting application-layer weaknesses, this IP poses a concrete risk to any exposed SSH, HTTP, or VoIP infrastructure.
Site operators should immediately block or rate-limit this address at the firewall or load balancer level and audit any services accessible from the internet for exposure. Implementing fail2ban or similar dynamic blocking tools can automate defensive responses to repeated connection attempts. Web application firewalls should be configured to flag and reject probing patterns consistent with the observed honeypot alerts. Organizations running VoIP infrastructure should enforce call authentication mechanisms and monitor for unauthorized call initiation patterns that align with fraud indicators.