Check an IP Address, Domain Name, Subnet, or ASN
213.159.56.51 has a threat confidence score of 64%. This IP address from Lithuania (AS21211, Penkiu kontinentu komunikaciju centras, Ltd.) has been observed in 12 honeypot sessions targeting TELNET protocols. Detected attack patterns include embedded device privileged shell acquisition and validation. First observed on January 22, 2026, most recently active March 22, 2026.
Represents a post-authentication command sequence targeting an embedded or appliance-style system in which the attacker transitions into a privileged execution mode, attempts to access an underlying system shell, probes available shell interpreters, and validates the resulting Linux environment. This behavior is characterized by privileged mode activation, multiple shell entry and fallback attempts, verification of network connectivity, confirmation of BusyBox-based userland availability, and inspection of the current process execution context via the /proc filesystem. The sequence indicates successful elevation from a restricted management interface into a functional Linux shell, typically preceding payload execution or persistence actions.