Check an IP Address, Domain Name, Subnet, or ASN
95.180.43.164 has a high threat confidence level of 64%, originating from Belgrade, Serbia, on the Serbia BroadBand-Srpske Kablovske mreze d.o.o. network (31042). It has been observed across 6 sessions targeting TELNET, with detected attack patterns including embedded device privileged shell acquisition and validation, First observed on January 22, 2026, most recently active March 1, 2026.
Represents a post-authentication command sequence targeting an embedded or appliance-style system in which the attacker transitions into a privileged execution mode, attempts to access an underlying system shell, probes available shell interpreters, and validates the resulting Linux environment. This behavior is characterized by privileged mode activation, multiple shell entry and fallback attempts, verification of network connectivity, confirmation of BusyBox-based userland availability, and inspection of the current process execution context via the /proc filesystem. The sequence indicates successful elevation from a restricted management interface into a functional Linux shell, typically preceding payload execution or persistence actions.