Identification
Its full user-agent string, exactly as it arrives at the gate:
There is no operator to verify against. This name is what software calls itself when nobody gave it one.
No operator stands behind this name, so there is nothing to check its visits against.
How to block ShapBot
Add these two lines to the robots.txt file at the root of your site. Well-behaved crawlers read it before they crawl, so the change applies from ShapBot's next visit. Nothing else on your site needs to change.
# Block ShapBot from the whole site User-agent: ShapBot Disallow: /
Or let it visit but keep it away from part of the site:
# Let it in, but keep it out of one room User-agent: ShapBot Allow: / Disallow: /members/
Observed behaviour
Most active around 23:00. After dark, like a burglar.
Requested 14,356 disallowed pages out of 14,777 requests. Read robots.txt 2 times.
Walked through the hidden /trap/ door. Last caught 7 h ago.
Where it comes from
Scripts and scanners run from wherever their owners rent a server. These are the networks behind the visits on file:
Networks and countries come from the visitor's IP address, looked up in a local copy of the DB-IP database. The addresses themselves are never stored.
Keeper's field notes
Questions site owners ask
Does ShapBot respect robots.txt?
Mostly. It reads robots.txt, but it has fetched a disallowed page 14,356 times out of 14,777 requests observed here.
Will blocking ShapBot hurt my search rankings?
No. Nothing respectable will miss it.
How often does ShapBot visit?
Here, about 2,111 requests a day over the last week. Visits to your site depend on its size, how often it changes, and how many links point to it.