External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
More (full fields + snapshot)expand
url
/login
referer
http://139.59.53.236/login
UA
'Mozilla/5.0
summary
External referer observed on an auth-like endpoint
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
subnet
43.157.198.0/24
asn
132203 — Tencent Building, Kejizhongyi Avenue
geo
Indonesia, Jakarta, Jakarta
org
Tencent Cloud Computing
#182023-08-27 06:59:43event 143376GET404bytes 179
ann cred10label cred
RequestAuth request appears to use an automation-oriented user agent
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
More (full fields + snapshot)expand
url
/new/login
referer
http://139.59.53.236/new/login
UA
'Mozilla/5.0
summary
External referer observed on an auth-like endpoint
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
subnet
43.157.198.0/24
asn
132203 — Tencent Building, Kejizhongyi Avenue
geo
Indonesia, Jakarta, Jakarta
org
Tencent Cloud Computing
#372023-08-27 06:59:40event 143367GET404bytes 179
ann cred10label cred
RequestAuth request appears to use an automation-oriented user agent