Back to sessionsOpen in graphDeclared device characteristics contradict passive telemetry β strong indicator of spoofed device metadata.User traversed pages in an order inconsistent with typical flows for this account.IP belongs to a residential proxy network often used by fraud-for-hire operations.Previous authenticated session occurred in a geographically implausible window for a single user.Login attempts match a distributed credential-stuffing campaign seen across the network.User signed in from a device never previously bound to the account.Remote access tooling (AnyDesk, TeamViewer, Quick Assist) is active alongside the session.
unx_0a5csp4
82User: eβ’β’β’β’β’β’@yahoo.comπ§π·BR115.102.β’β’β’.β’β’β’AS3269 Telecom Italia
Final decision
BlockedΒ· 82 / 100
Driven primarily by:
- RAT tooling detected91
- Device spoofing81
- Impossible travel73
Fired signals
Each card explains what the signal means and why it fired.
Device
Device spoofing
81Behavior
Unusual navigation pattern
23Network
Residential proxy
58Identity
Impossible travel
73Credential stuffing pattern
67New device for account
25Malware
RAT tooling detected
91Risk breakdown
Contribution to the final score by category.
- Device81
- Behavior23
- Network58
- Identity165
- Malware91
Event timeline
Everything that happened during this session.
- Session start11:17:25 PMTor Β· AS3269 Telecom Italia
- iPhone Β· iPhone 15 Pro11:17:27 PMfp_00002fj
- RAT tooling detected11:17:46 PMseverity 91
- Device spoofing11:18:05 PMseverity 81
- Impossible travel11:18:23 PMseverity 73
- Credential stuffing pattern11:18:28 PMseverity 67
- Residential proxy11:18:49 PMseverity 58
- New device for account11:19:07 PMseverity 25
- Unusual navigation pattern11:19:25 PMseverity 23
- Requested /kyc11:19:35 PM
- Opened /transfer11:19:43 PM
- Requested /kyc11:19:53 PM
- Transfer attempt11:20:00 PM$1,410
- Blocked by unilinx11:18:27 PM