Forum Moderators: open

SkypeUriPreview - links pasted into MS 365 Outlook

52.112.39.133

         

Bewenched

4:21 am on Jul 27, 2026 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



so i was hunting down a rogue bot in our logs and saw an IP address (not ours) trying to hit a page in our backend, it did force them out, but I figured out how it found that "link"

I had copied over a part number from out backend into a Microsoft 365 Outlook email, but had NOT sent it yet. It just happened to be the very same part number that I had copied and pasted into this email and their bot tried to hit it.

Mind you i had NOT sent the email, I'd copied it over and then right clicked the link and clicked remove URL. Which it did, however not BEFORE some BS bot tried to hit our admin page.

52.112.39.133 was the culprit

This is disturbing to say the least.

lucy24

10:33 pm on Jul 27, 2026 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I'm confused by the subject header. Is “SkypeUriPreview” the rogue bot in question? Wow, that’s a trip down memory lane. Haven’t see it since

:: side trip to archived logs ::

I'll be darned. Was going to say “years and years and years”--since before Zoom knocked Skype out of the running--but the UA does show itself now and then, in recent years always from 52.various i.e The Usual Suspects.

:: further exploration of archived logs ::

They seem to have undergone a sea change between mid-2018 (last seen from non-52 IPs) and mid-2021 (reappearing, now always from 52). Requests used to be page + favicon, but page-only since mid-2024. I guess I could flag them as bad_agent, but between the 52 and a certain consistent header deficit, no real point.