dstiles - 9:35 pm on Mar 12, 2013 (gmt 0)
While I was writing that last message my server had two more synapse hits a few seconds apart to exactly the same product and page of one web site. The hits were from NL and GB dynamic IP ranges.
This type of behaviour strongly suggests either a botnet or a proxy net. I probed both IPs for open ports - this, for botnet or proxy, normally shows positive. In these two cases (and in several previous attempts) there were no open ports. It is possible that both users closed down their machines in the intervening 45 or so minutes but this is unexpected if so.
The appearance is still of a botnet but one that has no open ports - at least, not on the common range. Which suggests it is driven via port 80 or 21/22 (web browser and FTP fetch), more likely the former. Time to log the headers in detail.