You: Bot 100.0% Low
← Dashboard / Signature Detail
US

Spoofed-Amazonbot

· Amazonbot 0.1 Bot
GoodBot
Policy: rate-limit-search
Probability
96 %
Confidence
91 %
Risk Profile
VeryHigh
Threat
None
Hit Count
2
Last Seen
11s ago

Analysis

Spoofed-Amazonbot on /dashboard/signat... - caught by Known AI search bot: Amazonbot (Amazon), Known bot pattern: Amazonbot, Spoofed UA: claims to be Amazonbot but IP doesn't verify ...

Detection Signals

  • Heuristic model (late): 99 % bot likelihood (324 features) 2.47
  • Known AI search bot: Amazonbot (Amazon) 1.90
  • Heuristic model (early): 87 % bot likelihood (22 features) 1.48
  • Known bot pattern: Amazonbot 1.35
  • Spoofed UA: claims to be Amazonbot but IP doesn't verify via fcrdns 1.27
  • Datacenter IP detected: Cloud Provider 0.72
Network Locale Headers Tool Transport Session Quality
Drift vs
43.6%

Fingerprint Profile

TLS Version
TLSv1.3
HTTP Protocol
HTTP/1.1
Protocol Client
TLS_AES_256_GCM_SHA384
TCP OS Hint
Unavailable
Fingerprint Integrity
Suspect
UA Consistency
Flagged
Headless Indicator
Low
Datacenter IP
Clean

Browser modes same browser, different modes. One row per persisted mode

Mode Observations Maturity Shift from baseline Last seen
bot-raw 690 690 0.12 (priority, sec ch ua platform, ua family) 19:45:51
signalr-negotiate 92 92 0.41 (priority, sec ch ua platform, ua family) 17:23:33
sub-resource 138 138 0.34 (priority, sec ch ua platform, accept) 17:23:27
navigation 81 81 0.32 (upgrade insecure requests, accept, header order hash) 17:23:22
4 modes across 1001 observations. See composite browser-mode fingerprints.
Endpoints Visited (2) Click to expand · stats unavailable
# Path
1 /dashboard/signature/hsp3Bctm7ZRIjeYhnpAfJQ
2 /dashboard/entity/1b28031d64ff47ab
Raw Requests (2) Click to expand
Time Method Path Status Prob Conf Risk Profile Action Time
18:58:32 GET /dashboard/signature/hsp3Bctm7ZRIjeYhnpAfJQ 200 100 % 50 % VeryHigh rate-limit-search 12.5ms
18:58:31 GET /dashboard/entity/1b28031d64ff47ab 302 100 % 50 % VeryHigh rate-limit-search 95.2ms

Bot Probability & Confidence History

StyloBot Detection Overhead (ms)

User Agent

Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot) Chrome/[phone] Safari/537.36

Detector Contributions (18 detectors)

Detector Confidence Delta Timing (ms)
HeuristicLate
Heuristic model (late): 99 % bot likelihood (324 features)
+0.989 0.3
AiScraper
Known AI search bot: Amazonbot (Amazon)
+0.950 0.0
Heuristic
Heuristic model (early): 87 % bot likelihood (22 features)
+0.739 0.1
UserAgent
Known bot pattern: Amazonbot
+0.900 1.2
VerifiedBot
Spoofed UA: claims to be Amazonbot but IP doesn't verify via fcrdns
+0.850 0.3
Ip
Datacenter IP detected: Cloud Provider
+0.600 0.0
Header
Missing Accept header; Browser UA without Accept-Language; deployment norm is low language rate (61 % over 56 samples)
+0.557 0.1
Behavioral
Request patterns appear normal
-0.150 0.1
TlsFingerprint
TLS connection appears normal
-0.150 0.0
TcpIpFingerprint
Client closes connection after each request (bots often avoid persistent connections)
+0.100 0.0
Http2Fingerprint
Using HTTP/1.1 instead of HTTP/2 (HTTP/2 rate: 0 % over 4 samples)
+0.050 0.0
AI
AI analysis: borderline case, monitoring
+0.000 10.2
SecurityTool
No security tools detected in User-Agent
+0.000 0.1
RequestHydrator
Request signals hydrated to sink
+0.000 0.0
Http3Fingerprint
Connection uses HTTP/1.1 (not HTTP/3)
+0.000 0.0
HeaderCorrelation
Single signature per header profile
+0.000 0.0
TransportProtocol
Transport protocol analysis complete
+0.000 0.0
FastPathReputation
No known patterns in reputation cache
+0.000 0.0

Signal Intelligence

request

protocol HTTP/1.1
accept_encoding gzip,deflate

risk

justification Classified GoodBot (probability 1.00, confidence 0.50)
friendly_pin_trace skipped:no_corroboration (UA claims Spoofed-Amazonbot as GoodBot)

tls

cipher TLS_AES_256_GCM_SHA384
Version TLSv1.3
version TLSv1.3

Policy applied

Hit history

No sessions recorded yet.

Sessions are created when a visitor's activity gap exceeds 30 minutes.

Effective policy
Loading effective policy…
ASP.NET Pack — Auth health
JWKS health
OK

reachable

Auth pipeline
JWKS reachable
License
Licensed

ASP.NET pack enabled

OTel Mesh — Traces

Fingerprint timeline

8c442c124dab4de8a37ba33e2ed31a68 0 observations

Span + log activity for this fingerprint, ordered by timestamp.

No timeline observations

OTel Mesh receiver online, but no observations seen for this fingerprint id (check W3C baggage propagation)

Operator actions

Operator actions

Block/Allow writes a scoped policy rule for this fingerprint — a policy action, applied via the live policy pipe. It is never a skip-detection bypass.

Signature: H0RzzbEMJt1P83UrKszPlQ | Processing: 12ms | Country: US | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot) Chrome/[phone] Safari/537.36 | First seen: 2026-07-25 18:58:31 UTC