Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36
Annotationfacts
label
ref
rule
ref:external_referer_to_auth
conf
70.00
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
More (full fields + snapshot)expand
url
/accounts/login/
referer
https://syndu.com/
UA
Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36
summary
External referer observed on an auth-like endpoint
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36
Annotationfacts
label
ref
rule
ref:external_referer_to_auth
conf
70.00
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
More (full fields + snapshot)expand
url
/accounts/login/
referer
https://syndu.com/accounts/login/
UA
Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36
summary
External referer observed on an auth-like endpoint
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36
Annotationfacts
label
ref
rule
ref:external_referer_to_auth
conf
70.00
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
More (full fields + snapshot)expand
url
/accounts/login/
referer
https://syndu.com/accounts/login/
UA
Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36
summary
External referer observed on an auth-like endpoint
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36 Herring/95.1.8810.11
Annotationfacts
label
ref
rule
ref:external_referer_to_auth
conf
70.00
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
More (full fields + snapshot)expand
url
/accounts/login/
referer
https://syndu.com/
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36 Herring/95.1.8810.11
summary
External referer observed on an auth-like endpoint
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
subnet
188.234.54.0/24
asn
41668 — JSC ER-Telecom Holding
geo
Russia, Tatarstan Republic, Kazan'
org
CJSC "ER-Telecom Holding" Kazan Branch
#2023-09-18 04:02:59event 200736POST200bytes 4284
ann ref6label ref
RequestExternal referer observed on an auth-like endpoint
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36 Herring/95.1.8810.11
Annotationfacts
label
ref
rule
ref:external_referer_to_auth
conf
70.00
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
More (full fields + snapshot)expand
url
/accounts/login/
referer
https://syndu.com/accounts/login/
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36 Herring/95.1.8810.11
summary
External referer observed on an auth-like endpoint
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36 Herring/95.1.8810.11
Annotationfacts
label
ref
rule
ref:external_referer_to_auth
conf
70.00
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.
More (full fields + snapshot)expand
url
/accounts/login/
referer
https://syndu.com/accounts/login/
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36 Herring/95.1.8810.11
summary
External referer observed on an auth-like endpoint
details
External origins hitting login/auth endpoints can be a signal of phishing landing pages or malicious redirect chains. This is only emitted for auth-like paths.