Check an IP Address, Domain Name, Subnet, or ASN
74.74.140.63 has a threat confidence score of 81%. This IP address from United States (AS11351, Charter Communications Inc) has been observed in 10 honeypot sessions and reported 1 times targeting TELNET protocols. Detected attack patterns include embedded device privileged shell acquisition and validation. First observed on January 22, 2026, most recently active March 17, 2026.
Represents a post-authentication command sequence targeting an embedded or appliance-style system in which the attacker transitions into a privileged execution mode, attempts to access an underlying system shell, probes available shell interpreters, and validates the resulting Linux environment. This behavior is characterized by privileged mode activation, multiple shell entry and fallback attempts, verification of network connectivity, confirmation of BusyBox-based userland availability, and inspection of the current process execution context via the /proc filesystem. The sequence indicates successful elevation from a restricted management interface into a functional Linux shell, typically preceding payload execution or persistence actions.
| Reporter | Date | Category | Protocol | Comment |
|---|---|---|---|---|
| User | Mar 17, 2026, 17:09 | Brute Force | TELNET | SikkerGuard: 2 blocked packets |