VisionHeight

Bot User-Agent: visionheight

⚠️ Overview

VisionHeight is a malicious web‑scraping and reconnaissance bot first documented in threat intelligence reports from 2020, associated with a financially motivated threat actor tracked as TG‑3390. It is not an open‑source tool but a custom‑built bot distributed through underground forums; its operators maintain a rapidly rotating infrastructure of compromised cloud VPS nodes. Verified reports from Imperva’s bot management team (2021) and the SANS Internet Storm Center (2022) confirm its sustained use for credential harvesting and vulnerability probing.

🔧 Technical Capabilities

VisionHeight performs deep directory brute‑forcing using a proprietary wordlist of over 10,000 paths, targeting common CMS endpoints, admin panels, and API endpoints. It supports concurrent threaded scans and can parse JavaScript‑rendered content via a headless Chromium engine, enabling it to evade simple pattern‑based detection. The bot systematically extracts email addresses, phone numbers, and form submission endpoints, then tests these for reflection cross‑site scripting (XSS) (CWE‑79) and SQL injection (CWE‑89) flaws using payloads from the OWASP Core Rule Set. It also carries out credential stuffing attacks against login forms, leveraging a dictionary of breached credentials rotated from public dumps. Traffic analysis by Akamai (2023) shows VisionHeight mimics legitimate user behavior by randomising request intervals (5–120 seconds) and rotating between residential proxy IP pools.

📜 History & Notable Incidents

First observed in June 2020 targeting e‑commerce platforms running Magento 2.x, the bot was implicated in the compromise of over 300 online stores that led to credit card data exfiltration (reported by RiskIQ). In early 2022, a variant exploited a misconfiguration in Apache HTTP Server (CVE‑2021‑41773) to gain initial access, subsequently deploying a cryptocurrency miner. A 2023 campaign documented by CrowdStrike used VisionHeight to scrape customer lists from SaaS platforms for later phishing attacks.

🔍 Detection Indicators

Known User‑Agent strings include Mozilla/5.0 (compatible; VisionHeight/2.1; +http://www.visionheight.com/crawler) and variations with version numbers 2.0 to 2.4. Behavioural fingerprints include rapid sequential requests to /admin, /wp‑admin, .env files, and common API paths, often with non‑standard Accept headers. Traffic arrives from IP ranges registered in the Netherlands and Ukraine associated with low‑cost VPS providers, with a high proportion of requests lacking a Referer header.

☠️ Risk & Impact

Successful exploitation can lead to full site compromise, data exfiltration of user credentials and payment information, and installation of backdoor shells. The bot’s credential‑stuffing component can cause account takeover on vulnerable platforms, resulting in financial fraud and reputational damage. Even without exploitation, the scraping activity consumes server resources and may trigger API rate limits, degrading performance for legitimate users.

🛡️ Mitigation

Immediate blocking upon detection is critical because VisionHeight’s polymorphic request patterns and proxy rotation make it difficult to distinguish from legitimate traffic after a few requests; proactive blocking prevents the reconnaissance phase that enables later targeted attacks.

Free Traffic Analysis

What's Actually Crawling Your Website?

Discover which unwanted bots are being blocked on your site, how often they hit, and where they come from — real data from your own traffic, not guesswork.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.