OK
reachable
Applebot on /_content/Mostlyl... - caught by UA rotation: 13 different User-Agents with identical head..., Known bot pattern: Applebot, claimed Applebot but source IP not in Applebot's publishe...
| Mode | Observations | Maturity | Shift from baseline | Last seen |
|---|---|---|---|---|
| bot-raw | 9090 | 9090 | 0.04 (ua family, header case pattern, referer host family) | 11:24:13 |
| sub-resource | 795 | 795 | 0.40 (ua family, header case pattern, referer host family) | 10:29:59 |
| signalr-negotiate | 179 | 179 | 0.39 (ua family, header order hash, referer host family) | 10:26:36 |
| websocket-upgrade | 10 | 10 | 0.40 (x requested with, header case pattern, header order hash) | 20:32:09 |
| navigation | 14 | 14 | 0.46 (upgrade insecure requests, custom header signature, header order hash) | 12:11:32 |
| # | Path |
|---|---|
| 1 | /_content/Mostlylucid.BotDetection.UI/bot-detection-details.css |
| 2 | /threats |
| 3 | /docs |
| 4 | /favicon-16x16.png |
| 5 | /config.json |
| 6 | /wp-config.php |
| 7 | /env.js |
| 8 | /.env.old |
| Time | Method | Path | Status | Prob | Conf | Risk Profile | Action | Time |
|---|---|---|---|---|---|---|---|---|
| 09:55:22 | GET | /_content/Mostlylucid.BotDetection.UI/bot-detection-details.css | 200 | 100 % | 50 % | VeryHigh | rate-limit-search | 11.3ms |
| 09:55:22 | GET | /threats | 200 | 100 % | 50 % | VeryHigh | rate-limit-search | 23.8ms |
| 09:54:37 | GET | /docs | 200 | 100 % | 50 % | VeryHigh | rate-limit-search | 12.4ms |
| 09:54:37 | GET | /favicon-16x16.png | 200 | 100 % | 50 % | VeryHigh | rate-limit-search | 32.2ms |
| 09:49:36 | GET | /config.json | 404 | 100 % | 50 % | VeryHigh | rate-limit-search | 12.3ms |
| 09:49:35 | GET | /wp-config.php | 404 | 100 % | 50 % | VeryHigh | rate-limit-search | 15.1ms |
| 09:49:32 | GET | /env.js | 404 | 100 % | 50 % | VeryHigh | rate-limit-search | 12.5ms |
| 09:49:31 | GET | /.env.old | 404 | 100 % | 100 % | Low | rate-limit-search | 12.4ms |
Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)
| Detector | Confidence Delta | Timing (ms) |
|---|---|---|
|
HeuristicLate
Heuristic model (late): 99 % bot likelihood (315 features)
|
+0.974 | 0.2 |
|
HeaderCorrelation
UA rotation: 13 different User-Agents with identical header profile from same IP
|
+0.900 | 0.1 |
|
UserAgent
Known bot pattern: Applebot
|
+0.900 | 0.2 |
|
Heuristic
Heuristic model (early): 81 % bot likelihood (19 features)
|
+0.614 | 0.0 |
|
Behavioral
Suspicious request timing: Too regular interval: 0.03s ± 0.02s; No referrer on subsequent request; No cookies maintained across multiple requests
|
+0.700 | 0.2 |
|
GoodBotIpRange
claimed Applebot but source IP not in Applebot's published range
|
+0.550 | 0.0 |
|
Ip
IP appears normal: 185.213.175.xxx
|
-0.150 | 0.0 |
|
Header
Headers appear normal
|
-0.150 | 0.0 |
|
TlsFingerprint
TLS connection appears normal
|
-0.150 | 0.0 |
|
AI
AI analysis: borderline case, monitoring
|
+0.000 | 9.8 |
|
AiScraper
No AI scraper signals detected
|
+0.000 | 0.0 |
|
VerifiedBot
Applebot UA claim unverified: no published ranges and rDNS unavailable
|
+0.000 | 0.6 |
|
SecurityTool
No security tools detected in User-Agent
|
+0.000 | 0.0 |
|
PiiQueryString
Query string contains PII parameters: token
|
+0.000 | 0.0 |
|
RequestHydrator
Request signals hydrated to sink
|
+0.000 | 0.0 |
|
Http2Fingerprint
Using HTTP/1.1; environment norm is HTTP/1.1 (65 % HTTP/2 over 46 samples)
|
+0.000 | 0.0 |
|
Http3Fingerprint
Connection uses HTTP/1.1 (not HTTP/3)
|
+0.000 | 0.0 |
|
TcpIpFingerprint
Network fingerprint analysis complete (no anomalies detected)
|
+0.000 | 0.0 |
|
TransportProtocol
Transport protocol analysis complete
|
+0.000 | 0.0 |
|
FastPathReputation
No known patterns in reputation cache
|
+0.000 | 0.0 |
No sessions recorded yet.
Sessions are created when a visitor's activity gap exceeds 30 minutes.
reachable
ASP.NET pack enabled
32bb80482ffb48089559f74451ecff49
0 observations
Span + log activity for this fingerprint, ordered by timestamp.
OTel Mesh receiver online, but no observations seen for this fingerprint id (check W3C baggage propagation)
Block/Allow writes a scoped policy rule for this fingerprint — a policy action, applied via the live policy pipe. It is never a skip-detection bypass.
IV1BXX7Q3oBQvJfmV6khYQ
|
Processing: 11ms
|
Country: NL
|
UA: Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)
|
First seen: 2026-07-26 09:49:31 UTC