DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back to IP report

Log Explorer

Fact drill-down for 185.226.196.22
Risk 1 LOW Scope All time All-time facts 94 In-scope 94 Filtered 94 Seen 2024-12-072025-02-10
Active (none) Clear
Faceted filters (facts-based) exact core + snapshot + optional start/end
Annotation facets
HTTP facets
Snapshot facets
Custom time window (optional override)
Provide start/end to scope time explicitly (overrides days). Leave blank for all-time.
Tip: keep windows tight when you need speed, but the default is fact-complete.
Click a pill to apply it as a filter.

Annotated access events

Showing page 1 / 2 — total 94 rows
#1 2025-02-10 22:56:58 event 2837564 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/sugar_version.json
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#2 2025-02-10 22:56:46 event 2837562 GET 500 bytes 28847
ann base label observed
Request event observed
referer
http://139.59.53.236/Telerik.Web.UI.WebResource.axd?type=rau
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/Telerik.Web.UI.WebResource.axd?type=rau
referer
http://139.59.53.236/Telerik.Web.UI.WebResource.axd?type=rau
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#3 2025-02-10 22:56:43 event 2837559 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/favicon-32x32.png
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#4 2025-02-10 22:56:30 event 2837558 GET 500 bytes 28847
ann base label observed
Request event observed
referer
http://139.59.53.236/zabbix/favicon.ico
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/zabbix/favicon.ico
referer
http://139.59.53.236/zabbix/favicon.ico
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#5 2025-02-10 22:56:29 event 2837556 GET 500 bytes 28847
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/favicon.ico
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#6 2025-02-10 22:56:28 event 2837555 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/favicon.ico
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#7 2025-02-10 22:56:02 event 2837544 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/sitecore/shell/sitecore.version.xml
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#8 2025-02-10 22:55:49 event 2837543 GET 500 bytes 28847
ann base label observed
Request event observed
referer
http://139.59.53.236/cgi-bin/authLogin.cgi
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/cgi-bin/authLogin.cgi
referer
http://139.59.53.236/cgi-bin/authLogin.cgi
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#9 2025-02-10 22:55:28 event 2837537 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/partymgr/control/main
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#10 2025-02-10 22:55:17 event 2837534 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/showLogin.cc
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#11 2025-02-10 22:55:00 event 2837530 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/css/images/PTZOptics_powerby.png
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#12 2025-02-10 22:54:44 event 2837528 GET 500 bytes 28847
ann ref 6 label ref
Request External referer observed on an auth-like endpoint
referer
http://139.59.53.236/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
ref
rule
ref:external_referer_to_auth
conf
70.00
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
More (full fields + snapshot) expand
url
/api/session/properties
referer
http://139.59.53.236/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
External referer observed on an auth-like endpoint
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#13 2025-02-10 22:54:44 event 2837528 GET 500 bytes 28847
ann base label observed
Request event observed
referer
http://139.59.53.236/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/api/session/properties
referer
http://139.59.53.236/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#14 2025-02-10 22:54:44 event 2837528 GET 500 bytes 28847
ann cred 10 label cred
Request Auth request appears to use an automation-oriented user agent
referer
http://139.59.53.236/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
cred
rule
cred:scripted_user_agent
conf
70.00
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
More (full fields + snapshot) expand
url
/api/session/properties
referer
http://139.59.53.236/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
Auth request appears to use an automation-oriented user agent
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#15 2025-02-10 22:54:44 event 2837528 GET 500 bytes 28847
ann cred label cred
Request Auth endpoint request observed
referer
http://139.59.53.236/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
cred
rule
cred:auth_hit:auth_other
conf
55.00
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
More (full fields + snapshot) expand
url
/api/session/properties
referer
http://139.59.53.236/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
Auth endpoint request observed
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#16 2025-02-10 22:54:42 event 2837526 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/cgi-bin/main.pl
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#17 2025-02-10 22:54:28 event 2837525 GET 500 bytes 28847
ann base label observed
Request event observed
referer
http://139.59.53.236/OA_HTML/AppsLocalLogin.jsp
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/OA_HTML/AppsLocalLogin.jsp
referer
http://139.59.53.236/OA_HTML/AppsLocalLogin.jsp
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#18 2025-02-10 22:54:10 event 2837522 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/identity
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#19 2025-02-10 22:54:08 event 2837520 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/js/NewWindow_2_all.js
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#20 2025-02-10 22:53:17 event 2837508 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/solr/
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#21 2025-02-10 22:53:15 event 2837506 GET 301 bytes 169
ann base label observed
Request event observed
/
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#22 2025-02-10 22:52:57 event 2837501 GET 500 bytes 28847
ann base label observed
Request event observed
referer
http://139.59.53.236/index.jsp
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/index.jsp
referer
http://139.59.53.236/index.jsp
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#23 2025-02-10 22:52:56 event 2837500 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/index.jsp
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#24 2025-02-10 22:52:33 event 2837488 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/WebInterface/
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#25 2025-02-02 01:37:31 event 3219757 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/aspera/faspex/
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#26 2025-02-02 01:37:31 event 3219756 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/aspera/faspex/
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#27 2025-02-02 01:36:59 event 3219739 GET 404 bytes 8105
ann base label observed
Request event observed
referer
http://68.183.80.204/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/api/session/properties
referer
http://68.183.80.204/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#28 2025-02-02 01:36:59 event 3219738 GET 404 bytes 8105
ann base label observed
Request event observed
referer
http://68.183.80.204/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/api/session/properties
referer
http://68.183.80.204/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#29 2025-02-02 01:36:59 event 3219739 GET 404 bytes 8105
ann ref 6 label ref
Request External referer observed on an auth-like endpoint
referer
http://68.183.80.204/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
ref
rule
ref:external_referer_to_auth
conf
70.00
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
More (full fields + snapshot) expand
url
/api/session/properties
referer
http://68.183.80.204/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
External referer observed on an auth-like endpoint
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#30 2025-02-02 01:36:59 event 3219738 GET 404 bytes 8105
ann ref 6 label ref
Request External referer observed on an auth-like endpoint
referer
http://68.183.80.204/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
ref
rule
ref:external_referer_to_auth
conf
70.00
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
More (full fields + snapshot) expand
url
/api/session/properties
referer
http://68.183.80.204/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
External referer observed on an auth-like endpoint
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#31 2025-02-02 01:36:59 event 3219739 GET 404 bytes 8105
ann cred 10 label cred
Request Auth request appears to use an automation-oriented user agent
referer
http://68.183.80.204/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
cred
rule
cred:scripted_user_agent
conf
70.00
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
More (full fields + snapshot) expand
url
/api/session/properties
referer
http://68.183.80.204/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
Auth request appears to use an automation-oriented user agent
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#32 2025-02-02 01:36:59 event 3219739 GET 404 bytes 8105
ann cred label cred
Request Auth endpoint request observed
referer
http://68.183.80.204/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
cred
rule
cred:auth_hit:auth_other
conf
55.00
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
More (full fields + snapshot) expand
url
/api/session/properties
referer
http://68.183.80.204/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
Auth endpoint request observed
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#33 2025-02-02 01:36:59 event 3219738 GET 404 bytes 8105
ann cred 10 label cred
Request Auth request appears to use an automation-oriented user agent
referer
http://68.183.80.204/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
cred
rule
cred:scripted_user_agent
conf
70.00
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
More (full fields + snapshot) expand
url
/api/session/properties
referer
http://68.183.80.204/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
Auth request appears to use an automation-oriented user agent
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#34 2025-02-02 01:36:59 event 3219738 GET 404 bytes 8105
ann cred label cred
Request Auth endpoint request observed
referer
http://68.183.80.204/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
cred
rule
cred:auth_hit:auth_other
conf
55.00
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
More (full fields + snapshot) expand
url
/api/session/properties
referer
http://68.183.80.204/api/session/properties
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
Auth endpoint request observed
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#35 2025-02-02 01:36:51 event 3219728 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/status.php
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#36 2025-02-02 01:36:51 event 3219726 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/status.php
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#37 2025-02-02 01:36:51 event 3219728 GET 301 bytes 169
ann fwprobe 22 label fwprobe
Request pfSense/OPNsense admin UI probe
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
fwprobe
rule
fwprobe:pfsense:ui_probe
conf
80.00
details
Request path matched a known firewall/VPN/gateway management or portal surface.
More (full fields + snapshot) expand
url
/status.php
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
pfSense/OPNsense admin UI probe
details
Request path matched a known firewall/VPN/gateway management or portal surface.
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#38 2025-02-02 01:36:51 event 3219726 GET 301 bytes 169
ann fwprobe 22 label fwprobe
Request pfSense/OPNsense admin UI probe
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
fwprobe
rule
fwprobe:pfsense:ui_probe
conf
80.00
details
Request path matched a known firewall/VPN/gateway management or portal surface.
More (full fields + snapshot) expand
url
/status.php
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
pfSense/OPNsense admin UI probe
details
Request path matched a known firewall/VPN/gateway management or portal surface.
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#39 2025-02-02 01:36:41 event 3219722 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/owncloud/status.php
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#40 2025-02-02 01:36:41 event 3219721 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/owncloud/status.php
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#41 2025-02-02 01:36:06 event 3219706 GET 404 bytes 8109
ann base label observed
Request event observed
referer
http://68.183.80.204/wp-json
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/wp-json
referer
http://68.183.80.204/wp-json
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#42 2025-02-02 01:36:06 event 3219705 GET 404 bytes 8109
ann base label observed
Request event observed
referer
http://68.183.80.204/wp-json
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/wp-json
referer
http://68.183.80.204/wp-json
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#43 2025-02-02 01:35:55 event 3219700 GET 404 bytes 8110
ann base label observed
Request event observed
referer
http://68.183.80.204/license.txt
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/license.txt
referer
http://68.183.80.204/license.txt
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#44 2025-02-02 01:35:55 event 3219699 GET 404 bytes 8110
ann base label observed
Request event observed
referer
http://68.183.80.204/license.txt
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/license.txt
referer
http://68.183.80.204/license.txt
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#45 2025-02-02 01:35:53 event 3219698 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/license.txt
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#46 2025-02-02 01:35:53 event 3219696 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/license.txt
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#47 2025-02-02 01:35:52 event 3219694 GET 200 bytes 1300
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/static/img/favicon.ico
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#48 2025-02-02 01:35:52 event 3219693 GET 301
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/favicon.ico
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#49 2025-02-02 01:35:52 event 3219692 GET 200 bytes 1300
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/static/img/favicon.ico
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX
#50 2025-02-02 01:35:52 event 3219691 GET 301
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/favicon.ico
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36
summary
event observed
details
subnet
185.226.196.0/24
asn
21859 — Zenlayer Inc
geo
United States, California, Los Angeles
org
ICG 3 ZEN LAX