I downloaded my October 2020 Raw Access Log. I carefully went through it. The only thing I found that looked dicey was scrapy dot org which I have blocked. I again had a 30% clawback from Google. It's beyond me where "fradulent clicks" may be coming from, especially as many as Google claims.
What I found:
google dot com/bot.html
semrush dot com/bot.html
bing dot com/bingbot.htm
ahrefs dot com/robot/
aspiegel dot com/petalbot
opensiteexplorer dot org/dotbot (forwards to moz dot com/link-explorer)
pinterest dot com/bot.html
facebook dot com/externalhit_uatext.php
help dot baidu dot com/question?
mj12 bot dot com
comscore dot com
admantx dot com/service-fetcher.html (site undergoing maintenance)
grapeshot dot co.uk/crawler.php resolves to oracle.com
napoveda dot seznam.cz/en/seznambot-intro/
eyeota dot com
yandex dot com/bots
bombora dot com/bot
scrapy dot org (blocked)
megaindex dot com/crawler
I also found things like this without a URL. I have no idea what they are.
Jaunt/1.5
Mozilla/5.0 (Linux; Android 10; SM-G973U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.75 Mobile Safari/537.36