Maximum Danger
IP 147.185.133.252 is a critical-risk address operating from Google Cloud Platform infrastructure within the United States, with a perfect 10/10 threat score and 263 abuse reports documenting sustained unauthorized access attempts over a seven-month window between December 2025 and June 2026.
The 263 total reports represent activity detected exclusively through automated honeypot sensors, with 20 distinct sources flagging the address across the observation period. The attack-pattern analysis reveals connections involving SSH session activity on non-standard ports, consistent with intrusion-detection signatures for covert remote access attempts. AS396982 (Google Cloud Platform) is a major public cloud provider frequently leveraged by threat actors precisely because cloud-hosted infrastructure often benefits from favorable reputation scores and reduced blocking by automated security systems. The activity frequency score of 5/10 indicates consistent, ongoing engagement rather than isolated probing, suggesting this address has been systematically employed against honeypot deployments worldwide.
The dominant threat category of hacking activity encompasses the full spectrum of intrusion attempts including vulnerability exploitation, unauthorized access attempts, and credential-based attacks. The Suricata alert flagging an SSH session in progress on an unusual port is particularly significant: it indicates that operators behind IP 147.185.133.252 are actively establishing remote-access sessions while deliberately avoiding standard SSH port 22 to evade basic firewall rules and signature-based detection. For any exposed service, this behaviour translates to a concrete risk of account compromise, data exfiltration, and potential use of the compromised endpoint as a pivot point for further attacks within a target network.
Site operators should immediately block IP 147.185.133.252 at the network perimeter using standard firewall rules or intrusion prevention systems. Enforcing certificate-based authentication and disabling password-based SSH login entirely eliminates the primary attack vector these sessions likely exploit. Implementing fail2ban or equivalent automated dynamic blocking can provide real-time response to repeated connection attempts from this address. Finally, restricting SSH access to known trusted IP ranges and monitoring authentication logs for unusual session patterns from this address will substantially reduce exposure.