Bot-cloak decision request with spoofed Google referrer to index/white.php

Detects a specific bot-cloaking technique used by the Exvicy/ErrTraffic framework, where an actor makes requests to bot-decision endpoints (index.php/white.php) while providing a spoofed 'google.com' Referer header to a non-Google destination host. This technique is often used to facilitate the delivery of fraudulent content (e.g., fake Turnstile/ClickFix pages) while evading detection by security scanners and undesired geographic regions.