Cheat Detector: Tue, Jun 9, 2026 02:06:41
Referer:
show internal spambully.com referer's
Page:
Time to download in seconds:
time between visit start and download start threshold.
IP Threshold:
Number of times the same ip can appear before it is suspicious.
Only show user who have a cheat score of or greater. (score ranges from -2 to 5.5)
Begin Date:   Time:
End Date:   Time:

Top 15 IP Summary

IP

Count

66.249.73.13118
66.249.73.13213
66.249.73.12810

Top 15 Hosts

ISP

Count

googlebot.com41
amazonbot.amazon9
seranking.com2
ovh.net2
googleusercontent.com1
103.143.138.2131
versanet.de1
43.173.179.131
43.173.181.1301

Top 15 Domain Suffixes

Suffix

Count

com44
amazon9
net2
2131
de1
1301
131

Visitors & Downloaders

Name

Percent

Not Curious Visitors100%
Fast Downloaders100%
Cheat: 3.00Visitors: 2

Cheat Rank
User Info
Curious
Visitor
Fast
Down-
load
Cou-
ntry
Lang-
uage
IP Address Host Referer
 (3): 5434834         0  de    149.202.53.222 (1)  ovh.net (2)  
 (3): 5434835         0  fr    57.129.81.227 (1)  ovh.net (2)  
Cheat Rank
User Info
Curious
Visitor
Fast
Down-
load
Cou-
ntry
Lang-
uage
IP Address Host Referer

Columns and Cheat Detection Explained

Cheat Rank User Info - This shows the userid which can be reviewed in more detail. The number at the beginning is the cheater rank which is a combination of all factors combined. The color goes from green to red depending on how many cheat factors are tripped.

Curious Visitor - This lets us know if a user browsed around the site or went straight for the download. If they just come to the site and go to the index, download, and exe only without browsing around this is tripped. While this doesn't really determine a cheater per se, it is positive if the user browsed around to screenshots, demo, features or other pages and will result in actually reducing a users cheat score if they do this.

Fast Download - If the user comes to our site and goes straight to the download within 5 seconds (configurable in options) of entering the site, this is not a good sign and suggests that this could be a robot auto downloading it. If you combine this with the fact that the user language on their computer is not english it compounds the suspiciousness of the visitor. This is only tripped if a user goes for a download. If they don't then it won't count negatively for the user even though it isn't positive for us necessarily, just because a user doesn't download our program we can't count that against them. The number in this field is the time in seconds that passed between the user coming to the site and downloading the program.

Country - The country field looks for if the user is from an english speaking country. If not the chances that user will buy from us are very little as we do only about 10%-12% of sales outside of english speaking counties. If we are unable to gather this info through any means we ding .5 point, because its suspicious but it could just be a user with some sort of extreme privacy enabled. Then again it could be a script hitting us as they are less likely to pass browser or js info.

Language - The language field looks for if the user's browser or computer is in english. If not the chances that user will buy from us are very little as we do only about 10% or less of sales outside of users who default language is not english. If we are unable to gather this info through any means we ding .5 point, because its suspicious but it could just be a user with some sort of extreme privacy enabled. Then again it could be a script hitting us as they are less likely to pass browser or js info.

IP Address - we look for often the same ip address appears. This simply lets us look if the same system is hitting our site a bunch which could be indicitive of bot traffic especially since a new visitor session is started each time which is indicative of bot traffic. A single user can have lots of hits and it will ot count negatively since its the same visitor. Here we are just looking at a large number of visitors all with the same ip. This is configurable in options.

Host - Here we look for the users ISP. If it is from a non english speaking country we ding it as this traffic is unlikely to buy from us. Also if we see a big increase in foreign traffic this is suspicious since we don't buy this type of traffic and generally aren't purchased from non english speaking countries. Also if we are unable to resolve the host we ding it .5 points as that is a bit weird and although it could be nothing it also could be indicative of anonymous proxies or other tricks to generate false traffic so we look at it a little suspiciously. US, UK, GB, AU, CA, NET, ORG, COM, GOV, EDU, and MIL addresses are all considered good, even though com net and org should be looked at for fluctuations if we see some influx of traffic from some non large com, net or org isp.

Referer - The referer section shows the base referer and tries to extract keywords, (though this is less than perfect.) Below that the original referer url is shown for that visitor. Nothing is analyzed to detect cheaters from the referer info.