Analysis of 14,784 requests from 4,584 unique clients identified 45 suspicious or malicious sources, including 5 impersonating known search-engine crawlers. Automated activity peaked around 16:00. The exact block list is under Recommended Actions.
| Claims to be | Source IP | User-Agent | Requests | Suspicion |
|---|---|---|---|---|
| MJ12bot | 192.0.2.59 | Mozilla/5.0 (compatible; MJ12bot/v1.4.8; http://mj12bot… | 12 | 1.00 |
| ClaudeBot | 192.0.2.222 | Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; comp… | 7 | 1.00 |
| Baiduspider | 192.0.2.107, 192.0.2.106 | Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.b… | 691 | 0.98 |
| FacebookBot | 192.0.2.253 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_1) AppleWe… | 3 | 0.77 |
| Meta-ExternalAgent | 203.0.113.2, 203.0.113.7, 203.0.113.13 | meta-externalagent/1.1 (+https://developers.facebook.co… | 8 | 0.51 |
Exact block list, ranked by composite suspicion (volume, page diversity, spoofing, and bot verification — not request count alone). IPs are precise /32 addresses where available. Actions: BLOCK = deny outright · RATE-LIMIT = throttle (rotating pools make single-IP blocks ineffective) · CHALLENGE = serve a CAPTCHA/JS challenge; legitimate users pass, automation fails. Peak = busiest hour of the day; Active = how long the source was active (⚠ ~24/7 = a persistent, not one-off, threat).
| IP | Action | Reason | Requests | Suspicion |
|---|---|---|---|---|
| 192.0.2.147 | BLOCK | High-volume automated source (1 UA) | 1,557 | 1.00 |
| 192.0.2.5 | BLOCK | High-volume automated source (3 UA) | 666 | 1.00 |
| 192.0.2.87 | BLOCK | High-volume automated source (1 UA) | 578 | 1.00 |
| 192.0.2.59 | BLOCK | Spoofs MJ12bot (failed bot verification) | 12 | 1.00 |
| 192.0.2.222 | BLOCK | Spoofs ClaudeBot (failed bot verification) | 7 | 1.00 |
| 192.0.2.107, 192.0.2.106 | BLOCK | Spoofs Baiduspider (failed bot verification) | 691 | 0.98 |
| 198.51.100.252 | RATE-LIMIT | UA-rotating source (204 UAs) — rate-limit /24 range | 284 | 0.97 |
| 198.51.100.19 | RATE-LIMIT | UA-rotating source (198 UAs) — rate-limit /24 range | 282 | 0.97 |
| 198.51.100.29 | RATE-LIMIT | UA-rotating source (197 UAs) — rate-limit /24 range | 279 | 0.97 |
| 198.51.100.170 | RATE-LIMIT | UA-rotating source (200 UAs) — rate-limit /24 range | 275 | 0.97 |
| 198.51.100.168 | RATE-LIMIT | UA-rotating source (200 UAs) — rate-limit /24 range | 274 | 0.97 |
| 198.51.100.46 | RATE-LIMIT | UA-rotating source (204 UAs) — rate-limit /24 range | 274 | 0.97 |
| 198.51.100.10 | RATE-LIMIT | UA-rotating source (213 UAs) — rate-limit /24 range | 271 | 0.97 |
| 198.51.100.206 | RATE-LIMIT | UA-rotating source (201 UAs) — rate-limit /24 range | 269 | 0.97 |
| 198.51.100.151 | RATE-LIMIT | UA-rotating source (201 UAs) — rate-limit /24 range | 263 | 0.97 |
| Action | User-Agent | Requests | Suspicion | Peak | Active |
|---|---|---|---|---|---|
| BLOCK | Mozilla/5.0 (Windows; U; Windows NT 6.1; zh-CN; r… | 578 | 1.00 | 16:00 | 26m |
| BLOCK | Mozilla/5.0 (Linux; Android 7.0;) AppleWebKit/537… | 231 | 1.00 | 16:00 | 2.6h |
| BLOCK | Mozilla/5.0 (compatible; Thinkbot/0.5.8; +In_the_… | 163 | 1.00 | 16:00 | 2.6h |
| BLOCK | Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/5… | 135 | 1.00 | 15:00 | 0m |
| BLOCK | Mozilla/5.0 (Windows NT 10.0; Win64; x64; trendic… | 106 | 1.00 | 16:00 | 2.0h |
| BLOCK | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWe… | 84 | 1.00 | 16:00 | 3m |
| BLOCK | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWe… | 64 | 1.00 | 15:00 | 55m |
| BLOCK | Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/5… | 37 | 1.00 | 15:00 | 0m |
| BLOCK | Mozilla/5.0 (Linux; Android 5.0; SM-G900P Build/L… | 13 | 1.00 | 17:00 | 0m |
| BLOCK | Mozilla/5.0 (iPhone; CPU iPhone OS 16_3 like Mac … | 12 | 1.00 | 15:00 | 1.2h |
Suspicious/automated requests per hour of day (red) against total site traffic (gray). The shaded band marks the peak attack window — the time rate limits should be hardened for.
Systematic URL traversal: 51 clients · Sequential content enumeration: 7 clients