It could be just reverse engineer how it works for one or few IPs and send all requests in the correct order mimicking what the server expects to see from a real claim.

For this test to be valid it would need to do much more than just that I think