One source overwhelms the comparison.
The concentration is visible immediately: one IP accounts for the dominant request burst, route spread, connection count, and absence of verified human interaction.
I.T.S. TRAFFIC ANALYSIS · RECORDED SCENARIOS
Attack evidence does not have one shape. One scenario is dominated by a single source; another becomes visible only after separate IPs, locations, client signatures, and UTC time slots are correlated.
DIFFERENT SIGNAL SHAPES
The concentration is visible immediately: one IP accounts for the dominant request burst, route spread, connection count, and absence of verified human interaction.
Volume is removed from the foreground. The evidence appears through the relationship between public source IPs, countries, reported agents, probed routes, and neighboring UTC observations.
A second-level view reveals the arrival rhythm, the exact maximum, and the targeted routes without repeating the broader source comparison.
REQUESTS BY SOURCE IP
Both views use the same source IPs and exact request counts. Only the bar scale changes: linear preserves absolute concentration, while logarithmic expands lower-volume sources for comparison.
SOURCE DETAIL · SNAPSHOT
Public network sources only. City and country are approximate IP-derived locations; the User Agent is the value reported by the client.
| Source IP | Requests | Reported User Agent | City | Country | First observed (UTC) |
|---|
Snapshot captured August 1, 2026. A source appears here only after exceeding the repeated-probing criterion used for this analysis.
GEOGRAPHIC CORRELATION
Bubble area is proportional to recorded requests. Sources resolving to the same approximate location are aggregated so overlapping IPs remain visible.