Today I noticed some strage hits (19 of them within 3 seconds) in my server logs.
Example:
173.252.127.19--[01/Nov/2024:06:56:26GET /404.php HTTP/1.1307205-Mozilla/5.0 (Windows NT 5.1; rv:11.0) Gecko Firefox/11.0 (via ggpht.com GoogleImageProxy)
As you can see, the hits were redirected to a special 404, because I only whitelist Google UAs coming from Google IPs.
What I don't uderstand is this Googe UA coming from a Meta IP.
173.252.96.0/19 belongs to Facebook Inc., while the UA is GoogleImageProxy. Could it be a spoofed UA used by a scraper Then wahat about the IP?
Could anyone please shed some light on this?
Thank you,
Asterickx