cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back to annotator catalog
Referrer abuse signal illustration
Annotator ref

Referrer abuse

Referrer patterns look manipulated, irrelevant, or inconsistent with normal navigation.

What This Annotator Watches

This explanation is derived from the live annotator implementation, not hand-waved catalog copy.
Focus
  • Redirect and referrer parameter abuse
  • External referers on auth-like endpoints
  • Open-redirect and base64-wrapped redirect chains
Logic
  • The annotator looks for manipulated referrer paths and redirect-style parameters.
  • It emits multiple small findings when one request carries several redirect hints.
  • Its value is explaining why referrer analytics or auth flows look tampered with.
How To Read It
Use this to separate natural navigation from traffic that is trying to spoof origin or bounce through your login surface.
Catalog Definition
Flags suspicious referrer behavior such as clearly fabricated referrers, referrers that do not match realistic navigation paths, or referrers used in repetitive spam-like ways. This annotator helps explain why referrer analytics may be untrustworthy and can also indicate low-effort automation or probing.

10 Most Recent Real Samples

Weekly cached from live annotated access events so the catalog stays fast.
Week
2026W13
Lookback
30 days
Total matched
13911
Latest sample
Mar 01, 2026 • 23:49
Top rules
ref:external_referer_to_auth · 10
Top requester orgs
Huawei Cloud · 10
Severity mix
6 · 10
Method mix
GET · 10
GET 200 6
Mar 01, 2026 • 23:49
/accounts/login/?next=/report_subnet/subnet/24.186.130.0/24/
External referer observed on an auth-like endpoint
IP 114.119.129.198 Subnet 114.119.129.0/24 Org Huawei Cloud Country Singapore Rule ref:external_referer_to_auth
GET 200 6
Mar 01, 2026 • 23:47
/accounts/login/?next=/report_ipaddress/ip/45.227.185.57/drill/
External referer observed on an auth-like endpoint
IP 114.119.131.28 Subnet 114.119.131.0/24 Org Huawei Cloud Country Singapore Rule ref:external_referer_to_auth
GET 200 6
Mar 01, 2026 • 23:44
/accounts/login/?next=/report_subnet/subnet/123.126.68.0/24/
External referer observed on an auth-like endpoint
IP 114.119.132.228 Subnet 114.119.132.0/24 Org Huawei Cloud Country Singapore Rule ref:external_referer_to_auth
GET 200 6
Mar 01, 2026 • 23:39
/accounts/login/?next=/report_ipaddress/ip/171.251.235.117/
External referer observed on an auth-like endpoint
IP 114.119.151.206 Subnet 114.119.151.0/24 Org Huawei Cloud Country Singapore Rule ref:external_referer_to_auth
GET 200 6
Mar 01, 2026 • 23:37
/accounts/login/?next=/report_subnet/subnet/189.38.177.0/24/
External referer observed on an auth-like endpoint
IP 114.119.129.176 Subnet 114.119.129.0/24 Org Huawei Cloud Country Singapore Rule ref:external_referer_to_auth
GET 200 6
Mar 01, 2026 • 23:37
/accounts/login/?next=/report_subnet/subnet/199.185.65.0/24/
External referer observed on an auth-like endpoint
IP 114.119.146.208 Subnet 114.119.146.0/24 Org Huawei Cloud Country Singapore Rule ref:external_referer_to_auth
GET 200 6
Mar 01, 2026 • 23:37
/accounts/login/?next=/report_subnet/subnet/74.67.9.0/24/
External referer observed on an auth-like endpoint
IP 114.119.137.230 Subnet 114.119.137.0/24 Org Huawei Cloud Country Singapore Rule ref:external_referer_to_auth
GET 200 6
Mar 01, 2026 • 23:37
/accounts/login/?next=/report_subnet/subnet/84.247.59.0/24/
External referer observed on an auth-like endpoint
IP 114.119.158.97 Subnet 114.119.158.0/24 Org Huawei Cloud Country Singapore Rule ref:external_referer_to_auth
GET 200 6
Mar 01, 2026 • 23:30
/accounts/login/?next=/report_subnet/subnet/180.74.65.0/24/
External referer observed on an auth-like endpoint
IP 114.119.132.89 Subnet 114.119.132.0/24 Org Huawei Cloud Country Singapore Rule ref:external_referer_to_auth
GET 200 6
Mar 01, 2026 • 23:29
/accounts/login/?next=/report_ipaddress/ip/187.39.84.145/
External referer observed on an auth-like endpoint
IP 114.119.166.88 Subnet 114.119.166.0/24 Org Huawei Cloud Country Singapore Rule ref:external_referer_to_auth