External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
More (full fields + snapshot)expand
url
/login
referer
http://139.59.53.236:80/login
UA
Go-http-client/1.1
summary
External referer observed on an auth-like endpoint
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
subnet
109.71.253.0/24
asn
44486 — synlinq.de
geo
Germany, Hesse, Gelnhausen
org
Rene Roeth trading as ROETH & BECK GbR
#2024-09-06 07:11:03event 1421917GET499
ann ref6label ref
RequestExternal referer observed on an auth-like endpoint
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
More (full fields + snapshot)expand
url
/login
referer
http://139.59.53.236:80/login
UA
Go-http-client/1.1
summary
External referer observed on an auth-like endpoint
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
subnet
109.71.253.0/24
asn
44486 — synlinq.de
geo
Germany, Hesse, Gelnhausen
org
Rene Roeth trading as ROETH & BECK GbR
#2024-09-06 07:11:03event 1421918GET499
ann cred10label cred
RequestAuth request appears to use an automation-oriented user agent