Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0
Annotationfacts
label
ref
rule
ref:external_referer_to_auth
conf
70.00
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
More (full fields + snapshot)expand
url
/jenkins/login
referer
http://68.183.80.204:80/jenkins/login
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0
summary
External referer observed on an auth-like endpoint
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
subnet
165.8.13.0/24
asn
5713 — Telkom SA Ltd.
geo
South Africa, Gauteng, Pretoria
org
Saposnet1
#2024-01-10 20:03:49event 746202GET404bytes 3868
ann cred10label cred
RequestAuth request appears to use an automation-oriented user agent
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0
Annotationfacts
label
ref
rule
ref:external_referer_to_auth
conf
70.00
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
More (full fields + snapshot)expand
url
/login
referer
http://68.183.80.204:80/login
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0
summary
External referer observed on an auth-like endpoint
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
subnet
165.8.13.0/24
asn
5713 — Telkom SA Ltd.
geo
South Africa, Gauteng, Pretoria
org
Saposnet1
#2024-01-10 20:03:44event 746200GET404bytes 3869
ann cred10label cred
RequestAuth request appears to use an automation-oriented user agent