On September 24, 2016, while checking the site logs, I found a small amount of abnormal traffic. After investigation and analysis, I discovered that [wamae.win] was maliciously reverse-proxying (mirroring) my site and tampering with its pages.
I immediately sent an email to the domain owner’s mailbox to inform them, but received no reply.
[wamae.win] reverse-proxies (mirrors) my site and tampers with the page code: it removes the functional JavaScript and analytics code, removes the friendly-link section, removes the MIIT filing number and the public-security filing number from the footer, and injects its own JavaScript code. Its behavior is extremely malicious.
[wamae.win] uses Baidu Cloud Acceleration. Because it is not filed, all of [wamae.win]‘s IPs are overseas (outside mainland China). I have now added this domain to the blacklist.
Below are screenshot evidence and the domain’s Whois information:
【Whois】
Registrar: Todaynic.com, Inc.
Contact: lin lin
Contact email: very1314520@126.com
Created: July 7, 2016
Expires: July 7, 2017
【Discovery】
[very1314520@126.com] This email has registered many domains and also mirrors other people’s sites. For example: [www.waie.win] mirrors [www.dujh.wang], which is probably also an unsuspecting blogger — I have already contacted that blogger.
So far the following domains registered under this email have been found:
[arefueew.toplin]
[gaphim.toplin]
[motteittamedatsu.comlin]
[ninjimy.toplin]
[nneedo.toplin]
[tkuwohe.toplin]
[waie.winlin]
[wamae.winlin]
[womaehut.top]
[motteittamedatsu.com]
[preacherrabu.com]
[senakaoconsumecontribute.com]
[ticketrivers.com]
[mapan.bid]
【Screenshots】




