OK
reachable
Chrome 123 on / - caught by No cookies maintained across multiple requests, IP appears normal: 45.156.129.xxx, TLS connection appears normal
| Mode | Observations | Maturity | Shift from baseline | Last seen |
|---|---|---|---|---|
| bot-raw | 5506 | 5506 | 0.13 (priority, header order hash, sec ch ua platform) | 09:44:58 |
| signalr-negotiate | 499 | 499 | 0.20 (header order hash, header case pattern, accept encoding ordered) | 09:11:21 |
| navigation | 1602 | 1602 | 0.38 (sec ch ua brands ordered, accept, priority) | 03:48:08 |
| sub-resource | 530 | 530 | 0.30 (priority, header order hash, accept) | 14:43:58 |
| # | Path |
|---|---|
| 1 | / |
| 2 | /Telerik.Web.UI.WebResource.axd |
| 3 | /api/session/properties |
| 4 | /jasperserver-pro/login.html |
| 5 | /identity/jsLibs/IdmBrandingBar.js |
| 6 | /status.php |
| 7 | /Web/Auth |
| Time | Method | Path | Status | Prob | Conf | Risk Profile | Action | Time |
|---|---|---|---|---|---|---|---|---|
| 08:32:29 | GET | / | 400 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.2ms |
| 08:32:20 | GET | /Telerik.Web.UI.WebResource.axd | 404 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.5ms |
| 08:31:45 | GET | /api/session/properties | 404 | 90 % | 68 % | VeryHigh | Silent Throttle | 12.2ms |
| 08:30:53 | GET | /jasperserver-pro/login.html | 404 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.2ms |
| 08:30:01 | GET | /identity/jsLibs/IdmBrandingBar.js | 404 | 90 % | 68 % | VeryHigh | Silent Throttle | 13.1ms |
| 08:28:46 | GET | /status.php | 404 | 90 % | 68 % | VeryHigh | Silent Throttle | 11.3ms |
| 08:28:17 | GET | /Web/Auth | 404 | 90 % | 68 % | VeryHigh | Silent Throttle | 13.8ms |
Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/[phone] Safari/537.36
| Detector | Confidence Delta | Timing (ms) |
|---|---|---|
|
HeuristicLate
Heuristic model (late): 95 % bot likelihood (282 features)
|
+0.905 | 0.2 |
|
Heuristic
Heuristic model (early): 73 % bot likelihood (22 features)
|
+0.467 | 0.0 |
|
Behavioral
No cookies maintained across multiple requests
|
+0.250 | 0.1 |
|
Ip
IP appears normal: 45.156.129.xxx
|
-0.150 | 0.0 |
|
TlsFingerprint
TLS connection appears normal
|
-0.150 | 0.0 |
|
UserAgent
No bot marker in User-Agent (weak human lean; UA is easily spoofed)
|
-0.050 | 0.4 |
|
AI
AI analysis: borderline case, monitoring
|
+0.000 | 10.3 |
|
Header
Browser UA without Accept-Language; deployment norm is low language rate (41 % over 246 samples)
|
+0.000 | 0.0 |
|
AiScraper
No AI scraper signals detected
|
+0.000 | 0.0 |
|
VerifiedBot
No known bot UA pattern
|
+0.000 | 0.0 |
|
SecurityTool
No security tools detected in User-Agent
|
+0.000 | 0.0 |
|
RequestHydrator
Request signals hydrated to sink
|
+0.000 | 0.0 |
|
Http2Fingerprint
Using HTTP/1.1; environment norm is HTTP/1.1 (15 % HTTP/2 over 41 samples)
|
+0.000 | 0.0 |
|
Http3Fingerprint
Connection uses HTTP/1.1 (not HTTP/3)
|
+0.000 | 0.0 |
|
TcpIpFingerprint
Network fingerprint analysis complete (no anomalies detected)
|
+0.000 | 0.0 |
|
HeaderCorrelation
Single signature per header profile
|
+0.000 | 0.0 |
|
TransportProtocol
Transport protocol analysis complete
|
+0.000 | 0.0 |
|
FastPathReputation
No known patterns in reputation cache
|
+0.000 | 0.0 |
No sessions recorded yet.
Sessions are created when a visitor's activity gap exceeds 30 minutes.
reachable
ASP.NET pack enabled
91e6038ebacb4268a4bab17554356661
0 observations
Span + log activity for this fingerprint, ordered by timestamp.
OTel Mesh receiver online, but no observations seen for this fingerprint id (check W3C baggage propagation)
Block/Allow writes a scoped policy rule for this fingerprint — a policy action, applied via the live policy pipe. It is never a skip-detection bypass.
bCx10Hf4OkWt1gVoqwih7Q
|
Processing: 11ms
|
Country: US
|
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/[phone] Safari/537.36
|
First seen: 2026-07-26 08:28:17 UTC