Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36
Annotationfacts
label
ref
rule
ref:external_referer_to_auth
conf
70.00
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
More (full fields + snapshot)expand
url
/api/sonicos/auth
referer
http://139.59.53.236:80/api/sonicos/auth
UA
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36
summary
External referer observed on an auth-like endpoint
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
subnet
157.230.7.0/24
asn
14061 — DigitalOcean, LLC
geo
United States, New Jersey, North Bergen
org
DigitalOcean, LLC
#2025-04-12 06:11:40event 6070688GET404bytes 7884
ann cred10label cred
RequestAuth request appears to use an automation-oriented user agent