Your Singapore traffic is one rented network
At the end of August, Singapore became the second country by pageviews on one of our sites. No conversions, no interaction, an average session under ten seconds. We took it apart down to the network level, and the whole spike turned out to be one farm renting Tencent address space. Blocking the country does nothing here: the exit addresses rotate, the datacenter stays.
What the logs show
Nine days of origin logs, the 43.172.0.0/14 family (AS132203, Tencent):
- 2,144 requests: 1,078 page loads and 1,057 tracker calls
- 1,451 unique IPs across 24 /24 subnets
- never more than 6 hits from one IP in all nine days
- referrer empty on 1,073 of the 1,078 page loads
- no CSS, no images, no fonts, ever
- 21 user agent strings, all Windows 10, Chrome 103 to 133
- a steady 170 to 230 pages a day, no weekend dip
The pairs are the interesting part. We matched every tracker call with the page load that came before it within ten seconds: the two IPs differed every time, the median gap was 3 seconds, and the user agent matched in 93% of pairs. One IP fetches the HTML, another one reports the pageview. A browser sends both from the same IP, and it does not wait three seconds.
Why the IP level shows nothing
Six hits from one IP over nine days crosses no limit anywhere. At IP level this reads as 1,451 different visitors. At /24 level it reads as 24 subnets behaving identically.
The stats for the same site over one week said it again:
| Singapore | US | |
|---|---|---|
| Sessions | 827 | 555 |
| Users | 824 | 480 |
| Engagement events | 10 | 488 |
| Bounce rate | 98% | 60% |
| Average duration | 9.6 s | 346 s |
The network level
Part of this traffic is visible in the request itself. The rest looks like an ordinary browser, and the only thing that gives it away is the network it arrives from.
How the list was built comes down to one question asked network by network: does anyone arriving from here ever interact with a page at all? Networks where the answer was effectively no went on the list. It is rechecked on a schedule, because the answer changes.
What this post leaves out, and why. We are not publishing the exact checks that catch the first wave, the thresholds behind the list, or the order they run in. Whoever operates this farm reads the same threads we do, and a precise recipe is a to-do list for their next release: add one header, randomise one delay, and the article that helped you costs you the detection. So what is here is the part that stays true after they have read it. The networks are named, because a datacenter cannot quietly stop being a datacenter. Our two mistakes are described in full, because those cost you traffic rather than them.
A list of datacenters also does more than any single signal inside a request. Renting a server is cheap. Changing your autonomous system means moving to another provider. Our list is 27 autonomous systems:
132203 Tencent 45090 Tencent
55960 AWS China 55990 Huawei Cloud
136907 Huawei International 45102 Alibaba US
212238 Datacamp 9009 M247
203020 HostRoyale 207990 HostRoyale
133499 HostRoyale 134450 HostRoyale
18779 EGIHosting 7979 Servers.com
62874 Web2Objects LLC 204646 web2objects GmbH
50077 SYN LTD 55470 Cyfuture India
40676 Psychz Networks 398781 Oculus Networks
202015 HZ Hosting 396319 Oxylabs
39855 Mod Mission Critical 47007 Colocation America
64286 LogicWeb 203346 Proper Support LLP
11798 Ace Data Centers
Six of the 27 are Chinese clouds, which is why the same list also answers the China half of the question. The farm we took apart here rented in Singapore, and we have not published our China measurements yet.
What not to do
The obvious move, blocking hosting as a class, is expensive. Over 4.5 days across five of our own sites we counted 3,939 pageviews. Hosting networks brought 241 of them, from 142 identities, and 92 of those identities spent real time on the page.
Those 92 are 10% of all 924 identities with any engagement in that window. A blanket hosting block would quietly delete one real person in ten from your reports, and you would never see which ones. Datacenters carry corporate proxies, VPNs, Cloudflare WARP and iCloud Private Relay.
We made two exceptions by hand:
- Tier-1 transit stays off the list even when the numbers look bad. GTT AS3257 met our criteria, but those IPs belong to somebody else's customers.
- Apple Private Relay egress ranges sit in a separate allowlist, because formally they are not residential either.
One more thing that cost us time: an older geo database placed that same Tencent range in Japan. Check the date on yours before you conclude anything about a country. And if you already know the network you want stopped at the door, that is what the blocklist is for.
What we do not do
The tempting path is to recognise a visitor from dozens of signals read out of their device. We did not take it. Article 5(3) of ePrivacy covers the access itself, not the storage, so reading canvas, WebGL or the font list without consent is a problem at the moment of reading, whatever happens to the result afterwards. We work with what the browser sends on its own, with behaviour over time, and with the network, on the server side. That is why our cookieless analytics has no fingerprint in it, and it is a fair question to put to every tool on your shortlist, including the alternatives we measured.
Limits of this study
- one of our sites over nine days, and five of our sites over 4.5 days
- logs rotate after 10 days, so we cannot look further back
- "behaves like a person" here means engagement time above zero. It is an approximation: someone who leaves at once has none either
- the list drifts. Datacamp and Huawei International sit close to the cut because both also host VPNs, so it has to be rechecked regularly
Ready to take control of your web analytics? Try Statable free for 30 days. No credit card required, full feature access, built for GDPR. Start your free trial or view a live demo.

