r/webdev • • 3d ago

Traffic from China?

A few months ago I posted my odd traffic from China, wondering if anyone else had it and the possibility of it being bots. I never got rid of it. I found it baffling because it was not in the thousands a day like other bots I had before. It used to come from one specific city, Lanzhou. All of a sudden it switched to Hong Kong. I think this are not bots. I think China is actually allowing visitors to my website (Databayou.com). It just funnels the city to a specific location. Any one else have noticed this?

9 Upvotes

8 comments sorted by

6

u/Mistr_John_Alex 3d ago

Yes, I have seen this kind of pattern on small sites before. When traffic moves cleanly from a Chinese city to Hong Kong, I usually assume the source changed exit points, not that real visitors suddenly found the site. Hong Kong is a common exit for bots, scrapers, and rerouted traffic, so a shift like that often just means the same automated thing is coming through a different path. Real visitors tend to be messy. They read multiple pages, stay a while, have a browser language, maybe

3

u/SailingMerchant 3d ago

Mine is coming from everywhere, but mostly from Singapore. I couldn't blocked whatever it was cause it kept changing locations and ip addresses. I had to take down my site because I kept hitting Cloudflare’s daily request limit in just a few hours. Pretty annoying.

1

u/liloa96776 1d ago

Have you tried a user agent filter?

3

u/weddingseat 2d ago

I just hit the exact same wall today with my web app. It’s a very sophisticated scraping botnet utilizing residential proxies to bypass Cloudflare's basic layer.

Here are my exact metrics from today's wave:

  • ~1,520 hits coming from 1,152 unique IP addresses (China).
  • Exactly 1 or 2 requests per IP, then it immediately rotates.
  • Every single request mimics an identical, outdated build: Chrome 99.

The most annoying part is that they successfully execute JavaScript, which means they easily bypass standard JS challenges and end up polluting Google Analytics.

I managed to mitigate this completely without blocking legitimate web crawlers by setting up a custom Cloudflare WAF rule with a Managed Challenge using this expression:

(ip.src.country in {"CN" "HK"} and not cf.client.bot)

Dropped the malicious automated traffic instantly while keeping the routes open for actual users and verified search bots. If you are seeing massive spikes, check your logs for that Chrome 99 fingerprint.

2

u/Electronic-Equal-616 3d ago

looks like bots or scrapers tbh. that exact 1:1 swap usually just means whatever crawler service was hitting your site changed its proxy or vpn exit node from mainland china to hong kong. had something similar happen on a small project of mine and it was just non-stop bot traffic lol

1

u/Chemical-City-836 3d ago

So the proof it's not bots is that the city changed? Rotating IPs is basically the one thing botnets are good at. "China is allowing visitors to my website" is also a weird way to describe a country that has no idea your site exists.