AZ
Back to sessions

unx_0d51g1y

83
User: l••••••@gmail.com🇪🇸ES166.70.•••.•••AS13335 Cloudflare
Open in graph
Final decision
Blocked· 83 / 100
Driven primarily by:
  • Known malware signature78
  • Process injection72
  • Residential proxy49

Fired signals

Each card explains what the signal means and why it fired.

Device
First-seen fingerprint
43
Device fingerprint has never been associated with this user or account before.
Network
Residential proxy
49
IP belongs to a residential proxy network often used by fraud-for-hire operations.
Identity
New device for account
30
User signed in from a device never previously bound to the account.
Malware
Known malware signature
78
A file hash on the endpoint matches an active malware family signature.
Process injection
72
EDR telemetry shows injected code running in the browser context.

Risk breakdown

Contribution to the final score by category.

  • Device43
  • Behavior0
  • Network49
  • Identity30
  • Malware150

Event timeline

Everything that happened during this session.

  1. Session start4:20:41 PM
    VPN · AS13335 Cloudflare
  2. Linux · Ubuntu 22.044:20:47 PM
    fp_00003uh
  3. Known malware signature4:21:01 PM
    severity 78
  4. Process injection4:21:08 PM
    severity 72
  5. Residential proxy4:21:13 PM
    severity 49
  6. First-seen fingerprint4:21:25 PM
    severity 43
  7. New device for account4:21:45 PM
    severity 30
  8. Opened /transfer4:21:52 PM
  9. Requested /kyc4:21:59 PM
  10. Transfer attempt4:22:03 PM
    $6,387
  11. Blocked by unilinx4:22:15 PM