I see there was a thread here a couple years ago asking about one aspect of these MS Office hits, but I thought I'd throw this out there because of some recent activity. Sometimes I see hits where the UA is the following:
Microsoft Office Excel 201X
Microsoft Office PowerPoint 201X
Microsoft Office Word 201X
I presume that those hits indicate someone clicked on a link to my site from a Word document, Excel spreadsheet or power point presentation - ?
--------------
I saw one such hit yesterday from the same IP that at first appears as a normal browser hit, where the UA was:
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/73.0.3683.86 Safari/537.36
But then thrown in there were HEAD's where the UA was Microsoft Office Word 2014. Presumably that user was browsing the site, then decided to copy a link (to a pdf) into an Office document, and Office was checking the link (using HEAD) ?
And then I see a hit to the same pdf - from the same user (this is all the same IP, same browsing session) where the UA is this:
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; Tablet PC 2.0; Zoom 3.6.0; ms-office)
Tablet PC? Zoom? MS-Office? What is all that?
-----------------
Then there are these UA's:
Microsoft Office Mobile/15.0
Microsoft Office Existence Discovery
Microsoft Office Protocol Discovery
and I think I've seen Microsoft webdav?
For which I have no clue what is behind them...