Good catch.
You just traced the 0.001% that wanted to be found.
This scanner is the rare traffic in your logs that is transparent, rate-limited, and harmless - with published IPs, reverse DNS, and an opt-out that we honor.
The actors probing you for real don't have a page like this. No link to follow, no IP list, no opt-out - and they're already 2–8 weeks into building the infrastructure they'll attack you with. We watch them do it.
This trail ends here.
The ones that matter don't.
You just spent real analyst time attributing benign traffic. That work - and the 99% of unknown traffic that stays unattributed - is exactly what we automate.
Two ways to get us out of your logs
Email optout@visionheight.com and we'll add your network to our global exclusion list promptly. Our 0.001% disappears. The other 99% keeps scanning.
Pulse classifies benign scanners like ours automatically - no more manual triage like the one that brought you here - and identifies malicious infrastructure at origin, weeks before it's weaponized.
SEE IT IN ACTIONAbout Our Internet Scanning Activities
VisionHeight runs a controlled, ethical internet scanning program to collect publicly available service metadata across the public IPv4 space. We do this to help defenders identify exposed and abusable infrastructure earlier and reduce overall attack surface.
What we do
VisionHeight runs a controlled, ethical internet scanning program to collect publicly available service metadata across the public IPv4 space. Our scanners perform application-layer probes only, to gather banners, TLS certificates, protocol versions, and similar non-intrusive information. No authentication attempts, no data modification, and no exploitation are performed.
Why we scan the entire internet
We scan the entire public IPv4 address space, not only customer assets, because misconfigured or exposed services anywhere on the internet can be abused by attackers. These misconfigurations may be used as staging points, reflectors, relays, or pivot hosts in larger campaigns. Global visibility lets us find and report exposures early, support defenders with actionable intelligence, and reduce the overall attack surface.
Nature of the traffic you may see
Traffic consists of short-lived TCP connection attempts and minimal protocol handshakes or header requests. For example, HTTP probes retrieve response headers, and TLS scans perform initial handshakes to enumerate certificates. "Failed read" messages in some logs typically result from targets closing connections during these short probes; they do not indicate exploitation.
Our scanning IP addresses
All reverse DNS records for our scanning hosts point to scan.visionheight.com.
Operational safeguards and opt out
We operate scanners with conservative rate limits, and we maintain an exclusion list for organizations that request to be omitted. If you prefer not to receive scans from our infrastructure, or if you need technical details to validate the activity, contact us and we will add your network to our global exclusion list promptly.
Contact:optout@visionheight.com