Back to sessionsOpen in graphTraffic is routed via a Tor exit node — strong indicator of deliberate origin obfuscation.Login attempts match a distributed credential-stuffing campaign seen across the network.
unx_0fqx4h4
36User: c••••••••@yahoo.com🇪🇸ES166.70.•••.•••AS13335 Cloudflare
Final decision
Review· 36 / 100
Driven primarily by:
- Credential stuffing pattern74
- Tor exit node55
Fired signals
Each card explains what the signal means and why it fired.
Network
Tor exit node
55Identity
Credential stuffing pattern
74Risk breakdown
Contribution to the final score by category.
- Device0
- Behavior0
- Network55
- Identity74
- Malware0
Event timeline
Everything that happened during this session.
- Session start10:22:18 PMCellular · AS13335 Cloudflare
- Linux · Ubuntu 22.0410:22:20 PMfp_000055s
- Credential stuffing pattern10:22:46 PMseverity 74
- Tor exit node10:22:57 PMseverity 55
- Opened /transfer10:23:04 PM
- Requested /kyc10:23:19 PM
- Transfer attempt10:23:24 PM$4,561
- Sent to manual review10:23:00 PM