Back to sessionsOpen in graphDevice attributes match a known mobile emulator or virtualized environment signature.Integrity checks flagged a rooted Android or jailbroken iOS device — elevating malware and tampering risk.IP belongs to a residential proxy network often used by fraud-for-hire operations.Previous authenticated session occurred in a geographically implausible window for a single user.User signed in from a device never previously bound to the account.Remote access tooling (AnyDesk, TeamViewer, Quick Assist) is active alongside the session.
unx_0fzyi8v
95User: n••••••@gmail.com🇺🇸US84.231.•••.•••AS14061 DigitalOcean
Final decision
Blocked· 95 / 100
Driven primarily by:
- RAT tooling detected87
- Impossible travel80
- Emulator or virtual device75
Fired signals
Each card explains what the signal means and why it fired.
Device
Emulator or virtual device
75Rooted / jailbroken device
55Network
Residential proxy
48Identity
Impossible travel
80New device for account
36Malware
RAT tooling detected
87Risk breakdown
Contribution to the final score by category.
- Device130
- Behavior0
- Network48
- Identity116
- Malware87
Event timeline
Everything that happened during this session.
- Session start11:52:33 PMCorporate · AS14061 DigitalOcean
- Linux · Ubuntu 22.0411:52:36 PMfp_00004uv
- RAT tooling detected11:53:04 PMseverity 87
- Impossible travel11:53:07 PMseverity 80
- Emulator or virtual device11:53:20 PMseverity 75
- Rooted / jailbroken device11:53:40 PMseverity 55
- Residential proxy11:53:50 PMseverity 48
- New device for account11:54:07 PMseverity 36
- Requested /kyc11:54:12 PM
- Transfer attempt11:54:19 PM$3,964
- Blocked by unilinx11:53:16 PM