AltiEvo
CONFIDENTIAL

Bot Traffic Analysis Report

Prepared for
DemoMart Online (Sample)
Report ID
BD-20260706-9752
Generated
2026-07-06 09:11:42
MEDIUM RISK

Analysis of 14,784 requests from 4,584 unique clients identified 45 suspicious or malicious sources, including 5 impersonating known search-engine crawlers. Automated activity peaked around 16:00. The exact block list is under Recommended Actions.

Section 01 · Executive Summary

Executive Summary

14,784
Total requests
4,584
Unique clients (User-Agents)
36
High-suspicion clients (0.8%)
15
Verified legitimate bots

Key Threat · 5 sources impersonating known crawlers

These sources claim to be legitimate crawlers, but failed forward-confirmed reverse-DNS identity verification. Blocking the listed addresses is recommended.
Claims to beSource IPUser-AgentRequestsSuspicion
MJ12bot192.0.2.59Mozilla/5.0 (compatible; MJ12bot/v1.4.8; http://mj12bot…121.00
ClaudeBot192.0.2.222Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; comp…71.00
Baiduspider192.0.2.107, 192.0.2.106Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.b…6910.98
FacebookBot192.0.2.253Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_1) AppleWe…30.77
Meta-ExternalAgent203.0.113.2, 203.0.113.7, 203.0.113.13meta-externalagent/1.1 (+https://developers.facebook.co…80.51
Section 02 · Recommended Actions

Recommended Actions

Exact block list, ranked by composite suspicion (volume, page diversity, spoofing, and bot verification — not request count alone). IPs are precise /32 addresses where available. Actions: BLOCK = deny outright · RATE-LIMIT = throttle (rotating pools make single-IP blocks ineffective) · CHALLENGE = serve a CAPTCHA/JS challenge; legitimate users pass, automation fails. Peak = busiest hour of the day; Active = how long the source was active (⚠ ~24/7 = a persistent, not one-off, threat).

Block these IPs (15)

IPActionReasonRequestsSuspicion
192.0.2.147BLOCKHigh-volume automated source (1 UA)1,5571.00
192.0.2.5BLOCKHigh-volume automated source (3 UA)6661.00
192.0.2.87BLOCKHigh-volume automated source (1 UA)5781.00
192.0.2.59BLOCKSpoofs MJ12bot (failed bot verification)121.00
192.0.2.222BLOCKSpoofs ClaudeBot (failed bot verification)71.00
192.0.2.107, 192.0.2.106BLOCKSpoofs Baiduspider (failed bot verification)6910.98
198.51.100.252RATE-LIMITUA-rotating source (204 UAs) — rate-limit /24 range2840.97
198.51.100.19RATE-LIMITUA-rotating source (198 UAs) — rate-limit /24 range2820.97
198.51.100.29RATE-LIMITUA-rotating source (197 UAs) — rate-limit /24 range2790.97
198.51.100.170RATE-LIMITUA-rotating source (200 UAs) — rate-limit /24 range2750.97
198.51.100.168RATE-LIMITUA-rotating source (200 UAs) — rate-limit /24 range2740.97
198.51.100.46RATE-LIMITUA-rotating source (204 UAs) — rate-limit /24 range2740.97
198.51.100.10RATE-LIMITUA-rotating source (213 UAs) — rate-limit /24 range2710.97
198.51.100.206RATE-LIMITUA-rotating source (201 UAs) — rate-limit /24 range2690.97
198.51.100.151RATE-LIMITUA-rotating source (201 UAs) — rate-limit /24 range2630.97

Block / rate-limit these User-Agents (10)

ActionUser-AgentRequestsSuspicionPeakActive
BLOCKMozilla/5.0 (Windows; U; Windows NT 6.1; zh-CN; r…5781.0016:0026m
BLOCKMozilla/5.0 (Linux; Android 7.0;) AppleWebKit/537…2311.0016:002.6h
BLOCKMozilla/5.0 (compatible; Thinkbot/0.5.8; +In_the_…1631.0016:002.6h
BLOCKMozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/5…1351.0015:000m
BLOCKMozilla/5.0 (Windows NT 10.0; Win64; x64; trendic…1061.0016:002.0h
BLOCKMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWe…841.0016:003m
BLOCKMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWe…641.0015:0055m
BLOCKMozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/5…371.0015:000m
BLOCKMozilla/5.0 (Linux; Android 5.0; SM-G900P Build/L…131.0017:000m
BLOCKMozilla/5.0 (iPhone; CPU iPhone OS 16_3 like Mac …121.0015:001.2h
Section 03 · Attack Timeline

Attack Timeline

Suspicious/automated requests per hour of day (red) against total site traffic (gray). The shaded band marks the peak attack window — the time rate limits should be hardened for.

Suspicious / automated traffic
All traffic
02,0004,0006,0008,00000:0004:0008:0012:0016:0020:00Peak 16:00 · 2,366 suspicious requests
Section 04 · Threat Breakdown

Threat Breakdown

Clients by suspicion score band

Critical (score ≥ 0.80)30High (0.60 – 0.79)15Medium (0.40 – 0.59)57

Most common suspicious traits

Unusually broad page coverage13Machine-regular request timing11All activity within one hour11Missing referer headers9Systematic URL traversal8Failed crawler identity check7Distributed across many IPs6High page volume5

Client classification

4,524 Normal / human traffic
45 Suspicious or malicious
15 Verified legitimate bots

Systematic URL traversal: 51 clients  ·  Sequential content enumeration: 7 clients

Section 05 · HTTP Overview

HTTP Response Overview

76.8%
Success 2xx
22.6%
Redirect 3xx
0.6%
Client error 4xx
0.0%
Server error 5xx

Status code distribution

200 OK11,351302 Found1,818308 Redirect847307 Redirect682404 Not Found86