Severe Risk
IP 147.185.133.125 is a critical-risk address operating from Google Cloud Platform infrastructure in the United States, carrying a perfect 10/10 threat level derived from 632 total abuse reports and consistent engagement with automated honeypot sensors over approximately seven months of observed activity.
Automated honeypot sensors first detected this IP in October 2025, with sustained malicious activity continuing through May 2026. The 632 reports are entirely categorized as hacking-related intrusion attempts, with all attribution originating from honeypot sensors at a 70% confidence rating. The consistent activity frequency of 5/10 across the seven-month observation window indicates persistent rather than opportunistic behavior. The address routes through AS396982 (GOOGLE-CLOUD-PLATFORM), suggesting the actor is leveraging cloud-based infrastructure either for anonymity or as a stable pivot point for widespread scanning operations.
The dominant threat category—general hacking activity—encompasses unauthorized access attempts, exploitation probing of services, and vulnerability scanning against exposed entry points. With 632 confirmed connection attempts logged against honeypot infrastructure, this IP has almost certainly conducted parallel reconnaissance against production environments. The sustained nature of the activity strongly implies automated scanning tool usage, likely as part of credential stuffing, brute-force, or vulnerability exploitation campaigns targeting exposed SSH, RDP, HTTP interfaces, or other network-accessible services.
Site operators should immediately block this IP at the network perimeter or firewall level given its critical threat designation. Implementing fail2ban,CrowdSec, or similar dynamic deny-listing tools can automate blocking based on honeypot and log-derived signals. Multi-factor authentication should be enforced across all externally accessible authentication endpoints, and exposure of unnecessary services should be minimized through network segmentation. Continuous monitoring of authentication logs for patterns consistent with the observed intrusion attempts will help identify any successful compromise attempts.