Severe Risk
IP 147.185.133.49 is a critical-risk address operating from Google Cloud Platform infrastructure in the United States that has generated 377 abuse reports over approximately nine months, indicating sustained and aggressive hacking activity dominated by SSH intrusion attempts. The threat level of 10/10 combined with an activity frequency rating of 7/10 reflects persistent probing behaviour that automated honeypot sensors detected consistently between August 2025 and May 2026, making this one of the more active malicious sources observed in recent reporting periods.
All 377 reports trace back to automated honeypot sensors, confirming this as a systematic, automated campaign rather than isolated manual probing. The source network is AS396982 operated by Google Cloud Platform, a major cloud provider frequently abused by threat actors as a launchpad due to its reputation for legitimate traffic and broad IP ranges. The detection window spanning from August 2025 through May 2026 demonstrates that this malicious activity persisted over an extended period, suggesting either persistent access maintained by the operator or regularly rotated virtual instances within this cloud environment. The 72% confidence score reflects moderate certainty in the assessment, supported by the high volume of consistent reports.
The dominant hacking activity specifically involves detected SSH sessions established on non-standard ports, a technique commonly used to evade network monitoring focused on default SSH port 22. This pattern typically precedes credential brute-forcing attempts, exploitation of unpatched SSH services, or establishment of covert command-and-control channels. The detected attack connection activity aligns with this assessment, indicating the threat actor is actively attempting to compromise exposed SSH services rather than merely scanning for vulnerabilities. Organizations with publicly accessible SSH services face direct exposure to these intrusion methodologies.
Immediate defensive action is warranted. Site operators should implement firewall-level blocking of this IP address and deploy fail2ban or equivalent automated banning tools to mitigate repeated connection attempts. SSH hardening measures including disabling password authentication in favour of public key infrastructure, enforcing strong passphrase policies, and restricting authentication to known IP ranges substantially reduce attack surface. Maintaining current patches for SSH daemons and implementing network intrusion detection rules that flag anomalous SSH traffic patterns on unusual ports provides layered protection against the techniques observed originating from this source.