← Dashboard / Signature Detail
DE

B0X6bPEDNQa Bandit

Bot
Scraper
Policy: Aggressive Throttle
Probability
90 %
Confidence
88 %
Risk Profile
VeryHigh
Threat
None
Hit Count
2
Last Seen
4h 10m ago
Network Locale Headers Tool Transport Session Quality
Drifted
Googlebot Mastodon Family
0.35 0.36

Fingerprint Profile

TLS Version
--
HTTP Protocol
--
Protocol Client
Detected
TCP OS Hint
+1.05
Fingerprint Integrity
-0.45
UA Consistency
-0.33
Headless Indicator
Low
Datacenter IP
Clean
Endpoints Visited (1) Click to expand
# Path
1 /
Raw Requests (2) Click to expand
Time Method Path Status Prob Conf Risk Profile Action Time
23:52:19 GET / 200 90 % 88 % VeryHigh Aggressive Throttle 119.0ms
23:52:05 GET / 200 0 % 100 % VeryLow Allow 0.0ms

Bot Probability & Confidence History

StyloBot Detection Overhead (ms)

Analysis

B0X6bPEDNQa Bandit on / - caught by Heuristic model (late): 100 % bot likelihood (236 features), [Reputation] UA pattern ConfirmedBad (score=0.94, support..., Previously identified as bot (UserAgent seen 85 times)

Detection Signals

  • Heuristic model (late): 100 % bot likelihood (236 features)
  • [Reputation] UA pattern ConfirmedBad (score=0.94, support=85)
  • Previously identified as bot (UserAgent seen 85 times)
  • Browser User-Agent without Accept-Language header
  • TLS connection appears normal

Detector Contributions (25 detectors)

Detector Confidence Delta Timing (ms)
HeuristicLate
Heuristic model (late): 100 % bot likelihood (236 features)
+1.000 0.2
ReputationBias
[Reputation] UA pattern ConfirmedBad (score=0.94, support=85)
+0.750 0.0
Inconsistency
Browser User-Agent without Accept-Language header; Chrome User-Agent without Client Hints
+0.700 0.0
FastPathReputation
Previously identified as bot (UserAgent seen 85 times)
+0.600 0.1
TlsFingerprint
TLS connection appears normal
-0.300 0.0
UserAgent
User-Agent appears normal
-0.250 0.2
Behavioral
Request patterns appear normal
-0.300 0.0
Ip
IP appears normal: 2a01:4f8:1...
-0.250 6.1
Header
Missing Accept header; Browser UA without Accept-Language; deployment norm is low language rate (9 % over 430 samples)
+0.150 0.0
VersionAge
Browser/OS versions appear current
-0.050 0.0
Heuristic
Heuristic model (early): 51 % bot likelihood (20 features)
+0.012 0.0
Intent
Session intent: unknown (threat=0.05, band=None)
+0.000 0.2
AiScraper
No AI scraper signals detected
+0.000 0.0
StreamAbuse
Stream abuse check - non-streaming request
+0.000 0.0
SecurityTool
No security tools detected in User-Agent
+0.000 0.0
SessionVector
Session tracking active (1 requests, 0 prior sessions)
+0.000 0.0
ClaimedIdentity
Chrome behavioral profile mismatch (consistency=0.34): missing Sec-Fetch headers (expected for this browser); no Accept-Language (browsers always send this); no text/html in Accept (expected for browser)
+0.350 0.0
ReactivePattern
No prior error events to analyze
+0.000 0.0
Http2Fingerprint
Using HTTP/1.1; environment norm is HTTP/1.1 (0 % HTTP/2 over 337 samples)
+0.000 0.0
Http3Fingerprint
Connection uses HTTP/1.1 (not HTTP/3)
+0.000 0.0
TcpIpFingerprint
Network fingerprint analysis complete (no anomalies detected)
+0.000 0.0
HeaderCorrelation
Single signature per header profile
+0.000 0.0
TransportProtocol
Transport protocol analysis complete
+0.000 0.0
BehavioralWaveform
Behavioral waveform analysis complete (insufficient history)
+0.000 0.0
MultiLayerCorrelation
Cross-signal consistency check complete (not enough data to compare)
+0.000 0.0

Signal Intelligence

behavioral

anomaly False

h2

is_http2 False
protocol HTTP/1.1
behind_proxy False
population_samples 337
population_http2_rate 0

h3

is_http3 False
protocol HTTP/1.1

header

count 14
has_accept False
sec_fetch_dest
sec_fetch_mode
sec_fetch_site
has_proxy_headers False
has_accept_encoding True
has_accept_language False
is_websocket_upgrade False
sec_fetch_same_origin False
population_accept_rate 0.752
is_service_worker_fetch False
population_accept_language_rate 0.091

heuristic

confidence 0.012
prediction bot
early_completed True
late_confidence 1
late_prediction bot

intent

analyzed True
category unknown
match_count 1
threat_band None
threat_score 0.05
similarity_score 1

ip

subnet 2a01:04f8:0172
is_ipv6 True
is_local False
is_datacenter False

referrer

domain www.google.com

reputation

can_abort True
bias_count 1
bias_applied True
fastpath_hit True
useragent.score 0.941
useragent.state ConfirmedBad
fast_abort_active True
useragent.support 84.812
fastpath.useragent.score 0.941
fastpath.useragent.state ConfirmedBad
fastpath.useragent.support 84.812
fastpath.useragent.pattern_id ua:81b197d8528f2ba4

request

protocol HTTP/1.1
accept_encoding gzip, br

risk

justification probability 0.90; confirmed bad actor
friendly_pin_trace not-applicable:botType=Scraper,yamlType=null,botName=null

tcp

connection_header keep-alive

tls

is_https True
available True

ua

family Chrome
is_bot False
family_version 143
Signature: _dgn0sgPU3ePugatxU1EBA | Processing: 119.0ms | Country: DE | First seen: 2026-06-12 23:52:05 UTC