Identification
Its full user-agent string, exactly as it arrives at the gate:
There is no operator to verify against. This name is what software calls itself when nobody gave it one.
How to block Masked visitor
Masked visitors look like browsers, so a user-agent rule cannot catch them. Rate limiting by IP address catches the worst of them without bothering people.
# A disguised visitor sends a normal browser user agent, # so there is nothing to match on. Rate-limit instead: # nginx limit_req_zone $binary_remote_addr zone=perip:10m rate=2r/s; limit_req zone=perip burst=20 nodelay;
A bot-management service or WAF can also score requests on behaviour.
Observed behaviour
Most active around 23:00. After dark, like a burglar.
Requested 47 disallowed pages out of 642 requests. Never read robots.txt.
Walked through the hidden /trap/ door. Last caught 2 h ago.
Where it comes from
Scripts and scanners run from wherever their owners rent a server. These are the networks behind the visits on file:
Networks and countries come from the visitor's IP address, looked up in a local copy of the DB-IP database. The addresses themselves are never stored.
Keeper's field notes
Questions site owners ask
Does Masked visitor respect robots.txt?
No. It has never requested robots.txt here, and it has fetched disallowed pages 47 times.
Will blocking Masked visitor hurt my search rankings?
No. Nothing respectable will miss it.
How often does Masked visitor visit?
Here, about 92 requests a day over the last week. Visits to your site depend on its size, how often it changes, and how many links point to it.