← Back to IP report
Log Explorer
Fact drill-down for
109.121.136.24
Risk
17
LOW
Scope
All time
All-time facts
440
In-scope
440
Filtered
440
Seen
2025-05-28
→
2025-05-28
Freestyle query (contains)
Time (days, optional)
Page size
25
50
100
200
Apply
Reset (all-time)
Active
(none)
Clear
Faceted filters (facts-based)
exact core + snapshot + optional start/end
Annotation facets
Annotator (exact)
(any)
base — 297
cred — 72
scan_velocity — 36
sfp — 26
ref — 9
Severity (exact)
(any)
(none) — 334
10 — 37
22 — 29
6 — 9
8 — 9
24 — 6
18 — 3
20 — 3
16 — 3
26 — 3
14 — 2
12 — 2
Label (exact)
(any)
observed — 297
cred — 72
scan_velocity — 36
sensitive_file — 26
ref — 9
HTTP facets
Method (exact, case-insensitive)
(any)
GET — 440
HTTP status (exact)
(any)
301 — 203
404 — 175
200 — 47
302 — 15
Snapshot facets
Subnet (exact)
(any)
109.121.136.0/24 — 440
ASN (exact)
(any)
39396 — 440
Country / Region / City (exact)
(any country)
Bulgaria — 440
(any region)
Ruse — 440
(any city)
Rousse — 440
Org contains (ip_org or as_org_name)
Custom time window (optional override)
Provide start/end to scope time explicitly (overrides days). Leave blank for all-time.
Start
End
Tip: keep windows tight when you need speed, but the default is fact-complete.
Top annotators (facts, in-scope)
base
297
cred
72
scan_velocity
36
sfp
26
ref
9
Top labels (facts, in-scope)
observed
297
cred
72
scan_velocity
36
sensitive_file
26
ref
9
Click a pill to apply it as a filter.
Annotated access events
Showing page
1
/
9
— total
440
rows
← Prev
Next →
#
2025-05-28 03:39:20
event
7101587
GET
404
bytes
7948
ann
base
label
observed
Request
event observed
/mysql/web/index.php?lang=en
referer
http://139.59.53.236/mysql/web/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/mysql/web/index.php?lang=en
referer
http://139.59.53.236/mysql/web/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:20
event
7101585
GET
404
bytes
7948
ann
base
label
observed
Request
event observed
/mysql/web/index.php?lang=en
referer
http://139.59.53.236/mysql/web/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/mysql/web/index.php?lang=en
referer
http://139.59.53.236/mysql/web/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:19
event
7101583
GET
301
bytes
178
ann
base
label
observed
Request
event observed
/mysql/web/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/mysql/web/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:19
event
7101582
GET
404
bytes
7944
ann
base
label
observed
Request
event observed
/phpMyAdmin5.1/index.php?lang=en
referer
http://139.59.53.236/phpMyAdmin5.1/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/phpMyAdmin5.1/index.php?lang=en
referer
http://139.59.53.236/phpMyAdmin5.1/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:19
event
7101579
GET
301
bytes
178
ann
base
label
observed
Request
event observed
/mysql/web/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/mysql/web/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:19
event
7101578
GET
404
bytes
7944
ann
base
label
observed
Request
event observed
/phpMyAdmin5.1/index.php?lang=en
referer
http://139.59.53.236/phpMyAdmin5.1/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/phpMyAdmin5.1/index.php?lang=en
referer
http://139.59.53.236/phpMyAdmin5.1/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:18
event
7101575
GET
301
bytes
178
ann
base
label
observed
Request
event observed
/phpMyAdmin5.1/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/phpMyAdmin5.1/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:18
event
7101572
GET
404
bytes
7947
ann
base
label
observed
Request
event observed
/phpmyadmin2022/index.php?lang=en
referer
http://139.59.53.236/phpmyadmin2022/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/phpmyadmin2022/index.php?lang=en
referer
http://139.59.53.236/phpmyadmin2022/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:18
event
7101570
GET
301
bytes
178
ann
base
label
observed
Request
event observed
/phpMyAdmin5.1/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/phpMyAdmin5.1/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:18
event
7101567
GET
404
bytes
7947
ann
base
label
observed
Request
event observed
/phpmyadmin2022/index.php?lang=en
referer
http://139.59.53.236/phpmyadmin2022/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/phpmyadmin2022/index.php?lang=en
referer
http://139.59.53.236/phpmyadmin2022/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:16
event
7101564
GET
404
bytes
7947
ann
sfp
22
label
sensitive_file
Request
Probe for admin tooling/config artifacts
/administrator/phpmyadmin/index.php?lang=en
referer
http://139.59.53.236/administrator/phpmyadmin/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
sensitive_file
rule
sfp:file:admin_tools
conf
78.00
details
Request targeted admin tooling endpoints or dependency config artifacts. Snippet='/administrator/phpmyadmin/index.php?lang=en'
More (full fields + snapshot)
expand
url
/administrator/phpmyadmin/index.php?lang=en
referer
http://139.59.53.236/administrator/phpmyadmin/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Probe for admin tooling/config artifacts
details
Request targeted admin tooling endpoints or dependency config artifacts. Snippet='/administrator/phpmyadmin/index.php?lang=en'
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:16
event
7101561
GET
404
bytes
7947
ann
sfp
22
label
sensitive_file
Request
Probe for admin tooling/config artifacts
/administrator/phpmyadmin/index.php?lang=en
referer
http://139.59.53.236/administrator/phpmyadmin/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
sensitive_file
rule
sfp:file:admin_tools
conf
78.00
details
Request targeted admin tooling endpoints or dependency config artifacts. Snippet='/administrator/phpmyadmin/index.php?lang=en'
More (full fields + snapshot)
expand
url
/administrator/phpmyadmin/index.php?lang=en
referer
http://139.59.53.236/administrator/phpmyadmin/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Probe for admin tooling/config artifacts
details
Request targeted admin tooling endpoints or dependency config artifacts. Snippet='/administrator/phpmyadmin/index.php?lang=en'
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:16
event
7101565
GET
301
bytes
178
ann
base
label
observed
Request
event observed
/phpmyadmin2022/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/phpmyadmin2022/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:16
event
7101564
GET
404
bytes
7947
ann
base
label
observed
Request
event observed
/administrator/phpmyadmin/index.php?lang=en
referer
http://139.59.53.236/administrator/phpmyadmin/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/administrator/phpmyadmin/index.php?lang=en
referer
http://139.59.53.236/administrator/phpmyadmin/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:16
event
7101562
GET
301
bytes
178
ann
base
label
observed
Request
event observed
/phpmyadmin2022/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/phpmyadmin2022/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:16
event
7101561
GET
404
bytes
7947
ann
base
label
observed
Request
event observed
/administrator/phpmyadmin/index.php?lang=en
referer
http://139.59.53.236/administrator/phpmyadmin/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/administrator/phpmyadmin/index.php?lang=en
referer
http://139.59.53.236/administrator/phpmyadmin/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:16
event
7101564
GET
404
bytes
7947
ann
cred
10
label
cred
Request
Auth request appears to use an automation-oriented user agent
/administrator/phpmyadmin/index.php?lang=en
referer
http://139.59.53.236/administrator/phpmyadmin/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
cred
rule
cred:scripted_user_agent
conf
70.00
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
More (full fields + snapshot)
expand
url
/administrator/phpmyadmin/index.php?lang=en
referer
http://139.59.53.236/administrator/phpmyadmin/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Auth request appears to use an automation-oriented user agent
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:16
event
7101564
GET
404
bytes
7947
ann
cred
label
cred
Request
Auth endpoint request observed
/administrator/phpmyadmin/index.php?lang=en
referer
http://139.59.53.236/administrator/phpmyadmin/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
cred
rule
cred:auth_hit:admin_login
conf
55.00
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
More (full fields + snapshot)
expand
url
/administrator/phpmyadmin/index.php?lang=en
referer
http://139.59.53.236/administrator/phpmyadmin/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Auth endpoint request observed
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:16
event
7101561
GET
404
bytes
7947
ann
cred
10
label
cred
Request
Auth request appears to use an automation-oriented user agent
/administrator/phpmyadmin/index.php?lang=en
referer
http://139.59.53.236/administrator/phpmyadmin/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
cred
rule
cred:scripted_user_agent
conf
70.00
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
More (full fields + snapshot)
expand
url
/administrator/phpmyadmin/index.php?lang=en
referer
http://139.59.53.236/administrator/phpmyadmin/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Auth request appears to use an automation-oriented user agent
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:16
event
7101561
GET
404
bytes
7947
ann
cred
label
cred
Request
Auth endpoint request observed
/administrator/phpmyadmin/index.php?lang=en
referer
http://139.59.53.236/administrator/phpmyadmin/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
cred
rule
cred:auth_hit:admin_login
conf
55.00
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
More (full fields + snapshot)
expand
url
/administrator/phpmyadmin/index.php?lang=en
referer
http://139.59.53.236/administrator/phpmyadmin/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Auth endpoint request observed
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:15
event
7101555
GET
301
bytes
178
ann
sfp
22
label
sensitive_file
Request
Probe for admin tooling/config artifacts
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
sensitive_file
rule
sfp:file:admin_tools
conf
78.00
details
Request targeted admin tooling endpoints or dependency config artifacts. Snippet='/administrator/phpmyadmin/index.php?lang=en'
More (full fields + snapshot)
expand
url
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Probe for admin tooling/config artifacts
details
Request targeted admin tooling endpoints or dependency config artifacts. Snippet='/administrator/phpmyadmin/index.php?lang=en'
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:15
event
7101548
GET
301
bytes
178
ann
sfp
22
label
sensitive_file
Request
Probe for admin tooling/config artifacts
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
sensitive_file
rule
sfp:file:admin_tools
conf
78.00
details
Request targeted admin tooling endpoints or dependency config artifacts. Snippet='/administrator/phpmyadmin/index.php?lang=en'
More (full fields + snapshot)
expand
url
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Probe for admin tooling/config artifacts
details
Request targeted admin tooling endpoints or dependency config artifacts. Snippet='/administrator/phpmyadmin/index.php?lang=en'
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:15
event
7101555
GET
301
bytes
178
ann
base
label
observed
Request
event observed
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:15
event
7101554
GET
404
bytes
7943
ann
base
label
observed
Request
event observed
/db/phpMyAdmin-5/index.php?lang=en
referer
http://139.59.53.236/db/phpMyAdmin-5/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/db/phpMyAdmin-5/index.php?lang=en
referer
http://139.59.53.236/db/phpMyAdmin-5/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:15
event
7101548
GET
301
bytes
178
ann
base
label
observed
Request
event observed
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:15
event
7101547
GET
404
bytes
7943
ann
base
label
observed
Request
event observed
/db/phpMyAdmin-5/index.php?lang=en
referer
http://139.59.53.236/db/phpMyAdmin-5/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/db/phpMyAdmin-5/index.php?lang=en
referer
http://139.59.53.236/db/phpMyAdmin-5/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:15
event
7101555
GET
301
bytes
178
ann
cred
10
label
cred
Request
Auth redirect (301) on auth endpoint
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
cred
rule
cred:auth_redirect
conf
72.00
details
Redirect outcomes can participate in 'success-after-fails' patterns during aggregation.
More (full fields + snapshot)
expand
url
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Auth redirect (301) on auth endpoint
details
Redirect outcomes can participate in 'success-after-fails' patterns during aggregation.
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:15
event
7101555
GET
301
bytes
178
ann
cred
10
label
cred
Request
Auth request appears to use an automation-oriented user agent
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
cred
rule
cred:scripted_user_agent
conf
70.00
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
More (full fields + snapshot)
expand
url
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Auth request appears to use an automation-oriented user agent
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:15
event
7101555
GET
301
bytes
178
ann
cred
label
cred
Request
Auth endpoint request observed
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
cred
rule
cred:auth_hit:admin_login
conf
55.00
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
More (full fields + snapshot)
expand
url
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Auth endpoint request observed
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:15
event
7101548
GET
301
bytes
178
ann
cred
10
label
cred
Request
Auth redirect (301) on auth endpoint
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
cred
rule
cred:auth_redirect
conf
72.00
details
Redirect outcomes can participate in 'success-after-fails' patterns during aggregation.
More (full fields + snapshot)
expand
url
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Auth redirect (301) on auth endpoint
details
Redirect outcomes can participate in 'success-after-fails' patterns during aggregation.
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:15
event
7101548
GET
301
bytes
178
ann
cred
10
label
cred
Request
Auth request appears to use an automation-oriented user agent
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
cred
rule
cred:scripted_user_agent
conf
70.00
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
More (full fields + snapshot)
expand
url
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Auth request appears to use an automation-oriented user agent
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:15
event
7101548
GET
301
bytes
178
ann
cred
label
cred
Request
Auth endpoint request observed
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
cred
rule
cred:auth_hit:admin_login
conf
55.00
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
More (full fields + snapshot)
expand
url
/administrator/phpmyadmin/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Auth endpoint request observed
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:13
event
7101541
GET
301
bytes
178
ann
base
label
observed
Request
event observed
/db/phpMyAdmin-5/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/db/phpMyAdmin-5/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:13
event
7101540
GET
301
bytes
178
ann
base
label
observed
Request
event observed
/db/phpMyAdmin-5/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/db/phpMyAdmin-5/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:12
event
7101539
GET
404
bytes
7945
ann
base
label
observed
Request
event observed
/phpmyadmin6/index.php?lang=en
referer
http://139.59.53.236/phpmyadmin6/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/phpmyadmin6/index.php?lang=en
referer
http://139.59.53.236/phpmyadmin6/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:12
event
7101537
GET
404
bytes
7945
ann
base
label
observed
Request
event observed
/phpmyadmin6/index.php?lang=en
referer
http://139.59.53.236/phpmyadmin6/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/phpmyadmin6/index.php?lang=en
referer
http://139.59.53.236/phpmyadmin6/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:11
event
7101535
GET
301
bytes
178
ann
base
label
observed
Request
event observed
/phpmyadmin6/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/phpmyadmin6/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:11
event
7101533
GET
404
bytes
7945
ann
base
label
observed
Request
event observed
/administrator/web/index.php?lang=en
referer
http://139.59.53.236/administrator/web/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/administrator/web/index.php?lang=en
referer
http://139.59.53.236/administrator/web/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:11
event
7101531
GET
301
bytes
178
ann
base
label
observed
Request
event observed
/administrator/web/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/administrator/web/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:11
event
7101530
GET
301
bytes
178
ann
base
label
observed
Request
event observed
/phpmyadmin6/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/phpmyadmin6/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:11
event
7101528
GET
404
bytes
7945
ann
base
label
observed
Request
event observed
/administrator/web/index.php?lang=en
referer
http://139.59.53.236/administrator/web/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/administrator/web/index.php?lang=en
referer
http://139.59.53.236/administrator/web/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:11
event
7101526
GET
301
bytes
178
ann
base
label
observed
Request
event observed
/administrator/web/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/administrator/web/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
event observed
details
—
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:11
event
7101533
GET
404
bytes
7945
ann
cred
10
label
cred
Request
Auth request appears to use an automation-oriented user agent
/administrator/web/index.php?lang=en
referer
http://139.59.53.236/administrator/web/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
cred
rule
cred:scripted_user_agent
conf
70.00
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
More (full fields + snapshot)
expand
url
/administrator/web/index.php?lang=en
referer
http://139.59.53.236/administrator/web/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Auth request appears to use an automation-oriented user agent
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:11
event
7101533
GET
404
bytes
7945
ann
cred
label
cred
Request
Auth endpoint request observed
/administrator/web/index.php?lang=en
referer
http://139.59.53.236/administrator/web/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
cred
rule
cred:auth_hit:admin_login
conf
55.00
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
More (full fields + snapshot)
expand
url
/administrator/web/index.php?lang=en
referer
http://139.59.53.236/administrator/web/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Auth endpoint request observed
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:11
event
7101531
GET
301
bytes
178
ann
cred
10
label
cred
Request
Auth redirect (301) on auth endpoint
/administrator/web/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
cred
rule
cred:auth_redirect
conf
72.00
details
Redirect outcomes can participate in 'success-after-fails' patterns during aggregation.
More (full fields + snapshot)
expand
url
/administrator/web/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Auth redirect (301) on auth endpoint
details
Redirect outcomes can participate in 'success-after-fails' patterns during aggregation.
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:11
event
7101531
GET
301
bytes
178
ann
cred
10
label
cred
Request
Auth request appears to use an automation-oriented user agent
/administrator/web/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
cred
rule
cred:scripted_user_agent
conf
70.00
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
More (full fields + snapshot)
expand
url
/administrator/web/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Auth request appears to use an automation-oriented user agent
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:11
event
7101531
GET
301
bytes
178
ann
cred
label
cred
Request
Auth endpoint request observed
/administrator/web/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
cred
rule
cred:auth_hit:admin_login
conf
55.00
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
More (full fields + snapshot)
expand
url
/administrator/web/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Auth endpoint request observed
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:11
event
7101528
GET
404
bytes
7945
ann
cred
10
label
cred
Request
Auth request appears to use an automation-oriented user agent
/administrator/web/index.php?lang=en
referer
http://139.59.53.236/administrator/web/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
cred
rule
cred:scripted_user_agent
conf
70.00
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
More (full fields + snapshot)
expand
url
/administrator/web/index.php?lang=en
referer
http://139.59.53.236/administrator/web/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Auth request appears to use an automation-oriented user agent
details
Automation-ish UA strings are useful correlates when paired with failures or spraying patterns.
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:11
event
7101528
GET
404
bytes
7945
ann
cred
label
cred
Request
Auth endpoint request observed
/administrator/web/index.php?lang=en
referer
http://139.59.53.236/administrator/web/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
cred
rule
cred:auth_hit:admin_login
conf
55.00
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
More (full fields + snapshot)
expand
url
/administrator/web/index.php?lang=en
referer
http://139.59.53.236/administrator/web/index.php?lang=en
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Auth endpoint request observed
details
Row-level auth primitive for downstream aggregation (no velocity logic here).
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
#
2025-05-28 03:39:11
event
7101526
GET
301
bytes
178
ann
cred
10
label
cred
Request
Auth redirect (301) on auth endpoint
/administrator/web/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
Annotation
facts
label
cred
rule
cred:auth_redirect
conf
72.00
details
Redirect outcomes can participate in 'success-after-fails' patterns during aggregation.
More (full fields + snapshot)
expand
url
/administrator/web/index.php?lang=en
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
summary
Auth redirect (301) on auth endpoint
details
Redirect outcomes can participate in 'success-after-fails' patterns during aggregation.
subnet
109.121.136.0/24
asn
39396 — NBI Systems Ltd.
geo
Bulgaria, Ruse, Rousse
org
Nbis Ltd.
×
This is a custom alert message.
×
Confirm Action
Are you sure you want to proceed?