You: Bot 100.0% Low
← Dashboard / Signature Detail
UA

MJ12bot mj12bot.com

· MJ12bot 1.4.8 Bot
GoodBot
Policy: rate-limit-search
Probability
100 %
Confidence
95 %
Risk Profile
VeryHigh
Threat
None
Hit Count
27
Last Seen
24s ago

Analysis

MJ12bot mj12bot.com on /account/login - caught by Known bot pattern: MJ12bot, Highly repetitive: /account/login→/account/login (p=95 %), Request patterns appear normal

Detection Signals

  • Heuristic model (late): 90 % bot likelihood (323 features) 1.98
  • Known bot pattern: MJ12bot 1.35
  • Heuristic model (early): 59 % human likelihood (18 features) 0.37
  • Request patterns appear normal; Highly repetitive: /account/login→/account/login (p=95 %) 0.33
  • IP appears normal: 178.150.14.xxx 0.15
  • Headers appear normal 0.15
Network Locale Headers Tool Transport Session Quality
Drift vs
48.4%

Fingerprint Profile

TLS Version
TLSv1.3
HTTP Protocol
HTTP/2
Protocol Client
TLS_AES_256_GCM_SHA384
TCP OS Hint
Unavailable
Fingerprint Integrity
Suspect
UA Consistency
Flagged
Headless Indicator
Low
Datacenter IP
Clean

Browser modes same browser, different modes. One row per persisted mode

Mode Observations Maturity Shift from baseline Last seen
bot-raw 3127 3127 0.00 (header order hash, upgrade insecure requests, ua family) 11:09:04
sub-resource 3 3 0.42 (header order hash, ua family, header case pattern) 15:48:57
signalr-negotiate 1 1 0.49 (ua family, header order hash, referer host family) 15:48:44
navigation 7 7 0.50 (upgrade insecure requests, ua family, header order hash) 00:14:28
4 modes across 3138 observations. See composite browser-mode fingerprints.
Endpoints Visited (8) Click to expand · stats unavailable
# Path
1 /account/login
2 /docs/why-startup
3 /docs/why-single-site
4 /docs/why-enterprise
5 /docs/troubleshooting
6 /docs/gateway-mode-lifecycle
7 /docs/feedback-feature
8 /docs/cli-reference
Raw Requests (27) Click to expand
Time Method Path Status Prob Conf Risk Profile Action Time
01:07:42 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 11.4ms
01:07:41 GET /docs/why-startup 200 100 % 50 % VeryHigh rate-limit-search 11.4ms
01:07:39 GET /docs/why-single-site 200 100 % 50 % VeryHigh rate-limit-search 11.8ms
01:07:38 GET /docs/why-enterprise 200 100 % 50 % VeryHigh rate-limit-search 11.7ms
01:07:36 GET /docs/troubleshooting 200 100 % 50 % VeryHigh rate-limit-search 11.7ms
01:07:34 GET /docs/gateway-mode-lifecycle 200 100 % 50 % VeryHigh rate-limit-search 11.0ms
01:07:33 GET /docs/feedback-feature 200 100 % 50 % VeryHigh rate-limit-search 11.6ms
01:07:31 GET /docs/cli-reference 200 100 % 50 % VeryHigh rate-limit-search 12.4ms
01:07:28 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 12.2ms
01:07:25 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 11.7ms
01:07:21 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 12.2ms
01:07:18 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 12.3ms
01:07:13 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 12.3ms
01:07:09 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 11.9ms
01:07:06 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 11.9ms
01:07:01 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 11.9ms
01:06:58 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 13.1ms
01:06:54 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 11.7ms
01:06:50 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 12.6ms
01:06:46 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 11.9ms
01:06:41 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 11.7ms
01:06:38 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 12.2ms
01:06:35 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 11.6ms
01:06:32 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 11.5ms
01:06:26 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 11.5ms
01:06:21 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 11.7ms
01:06:18 GET /account/login 500 100 % 50 % VeryHigh rate-limit-search 522.7ms

Bot Probability & Confidence History

StyloBot Detection Overhead (ms)

User Agent

Mozilla/5.0 (compatible; MJ12bot/v1.4.8; http://mj12bot.com/)

Detector Contributions (20 detectors)

Detector Confidence Delta Timing (ms)
HeuristicLate
Heuristic model (late): 90 % bot likelihood (323 features)
+0.793 0.4
UserAgent
Known bot pattern: MJ12bot
+0.900 0.2
Heuristic
Heuristic model (early): 59 % human likelihood (18 features)
-0.184 0.1
Behavioral
Request patterns appear normal; Highly repetitive: /account/login→/account/login (p=95 %)
+0.250 0.4
Ip
IP appears normal: 178.150.14.xxx
-0.150 0.0
Header
Headers appear normal
-0.150 0.0
TlsFingerprint
TLS connection appears normal
-0.150 0.0
VerifiedBot
rDNS mismatch: UA claims mj12bot.com but rDNS is 250.14.150.178.triolan.net
+0.250 0.0
AI
AI analysis: borderline case, monitoring
+0.000 9.9
AiScraper
No AI scraper signals detected
+0.000 0.0
SecurityTool
No security tools detected in User-Agent
+0.000 0.0
PiiQueryString
Query string contains PII parameters: token
+0.000 0.0
ContentSequence
Document hit; sequence reset at /account/login
+0.000 0.1
RequestHydrator
Request signals hydrated to sink
+0.000 0.0
Http2Fingerprint
HTTP/2 analysis complete (no anomalies detected)
+0.000 0.0
Http3Fingerprint
Connection uses HTTP/2 (not HTTP/3)
+0.000 0.0
TcpIpFingerprint
Network fingerprint analysis complete (no anomalies detected)
+0.000 0.0
HeaderCorrelation
Single signature per header profile
+0.000 0.0
TransportProtocol
Transport protocol analysis complete
+0.000 0.0
FastPathReputation
No known patterns in reputation cache
+0.000 0.0

Signal Intelligence

h2

protocol h2

request

protocol HTTP/2
accept_encoding gzip, br

risk

justification Classified GoodBot (probability 1.00, confidence 0.50)
friendly_pin_trace skipped:no_corroboration (UA claims MJ12bot mj12bot.com as GoodBot)

tls

cipher TLS_AES_256_GCM_SHA384
Version TLSv1.3
version TLSv1.3

Policy applied

Hit history

No sessions recorded yet.

Sessions are created when a visitor's activity gap exceeds 30 minutes.

Effective policy
Loading effective policy…
ASP.NET Pack — Auth health
JWKS health
OK

reachable

Auth pipeline
JWKS reachable
License
Licensed

ASP.NET pack enabled

OTel Mesh — Traces

Fingerprint timeline

fbb975cff7f548979ac34955b2034d9a 0 observations

Span + log activity for this fingerprint, ordered by timestamp.

No timeline observations

OTel Mesh receiver online, but no observations seen for this fingerprint id (check W3C baggage propagation)

Operator actions

Operator actions

Block/Allow writes a scoped policy rule for this fingerprint — a policy action, applied via the live policy pipe. It is never a skip-detection bypass.

Signature: TjqfnDTqcNB3BHb7cttK1A | Processing: 11ms | Country: UA | UA: Mozilla/5.0 (compatible; MJ12bot/v1.4.8; http://mj12bot.com/) | First seen: 2026-07-20 01:06:18 UTC