Mozilla/5.0 (Macintosh; Intel Mac OS X 11_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36
Annotationfacts
label
ref
rule
ref:external_referer_to_auth
conf
70.00
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
More (full fields + snapshot)expand
url
/admin/login/?next=/admin/scripts/setup.php
referer
https://139.59.53.236:443/admin/scripts/setup.php
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 11_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36
summary
External referer observed on an auth-like endpoint
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
subnet
47.79.40.0/24
asn
45102 — Alibaba (US) Technology Co., Ltd.
geo
Japan, Tokyo, Tokyo
org
NORTHERN CABLE AND FIBER, LLC, Delta Centric LLC, Zenlayer Inc
#122025-06-21 23:35:04event 9050874HEAD200
ann ref6label ref
RequestExternal referer observed on an auth-like endpoint
Mozilla/5.0 (Macintosh; Intel Mac OS X 11_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36
Annotationfacts
label
ref
rule
ref:external_referer_to_auth
conf
70.00
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
More (full fields + snapshot)expand
url
/admin/login/?next=/admin/scripts/setup.php
referer
https://139.59.53.236:443/admin/scripts/setup.php
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 11_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36
summary
External referer observed on an auth-like endpoint
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
subnet
47.79.40.0/24
asn
45102 — Alibaba (US) Technology Co., Ltd.
geo
Japan, Tokyo, Tokyo
org
NORTHERN CABLE AND FIBER, LLC, Delta Centric LLC, Zenlayer Inc