Check an IP Address, Domain Name, Subnet, or ASN
27.109.179.217 has a high threat confidence level of 67%, originating from Macao, on the Companhia de Telecomunicacoes de Macau SARL network (4609). It has been observed across 6 sessions targeting TELNET, with detected attack patterns including embedded device privileged shell acquisition and validation, First observed on January 23, 2026, most recently active February 9, 2026.
Represents a post-authentication command sequence targeting an embedded or appliance-style system in which the attacker transitions into a privileged execution mode, attempts to access an underlying system shell, probes available shell interpreters, and validates the resulting Linux environment. This behavior is characterized by privileged mode activation, multiple shell entry and fallback attempts, verification of network connectivity, confirmation of BusyBox-based userland availability, and inspection of the current process execution context via the /proc filesystem. The sequence indicates successful elevation from a restricted management interface into a functional Linux shell, typically preceding payload execution or persistence actions.