Forum Moderators: open

SkypeUriPreview - links pasted into MS 365 Outlook

52.112.39.133

         

Bewenched

4:21 am on Jul 27, 2026 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



so i was hunting down a rogue bot in our logs and saw an IP address (not ours) trying to hit a page in our backend, it did force them out, but I figured out how it found that "link"

I had copied over a part number from out backend into a Microsoft 365 Outlook email, but had NOT sent it yet. It just happened to be the very same part number that I had copied and pasted into this email and their bot tried to hit it.

Mind you i had NOT sent the email, I'd copied it over and then right clicked the link and clicked remove URL. Which it did, however not BEFORE some BS bot tried to hit our admin page.

52.112.39.133 was the culprit

This is disturbing to say the least.

lucy24

10:33 pm on Jul 27, 2026 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I'm confused by the subject header. Is “SkypeUriPreview” the rogue bot in question? Wow, that’s a trip down memory lane. Haven’t see it since

:: side trip to archived logs ::

I'll be darned. Was going to say “years and years and years”--since before Zoom knocked Skype out of the running--but the UA does show itself now and then, in recent years always from 52.various i.e The Usual Suspects.

:: further exploration of archived logs ::

They seem to have undergone a sea change between mid-2018 (last seen from non-52 IPs) and mid-2021 (reappearing, now always from 52). Requests used to be page + favicon, but page-only since mid-2024. I guess I could flag them as bad_agent, but between the 52 and a certain consistent header deficit, no real point.

Bewenched

4:21 am on Aug 6, 2026 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Well what it is, is if someone pastes a url into outlook BEFORE sending it, this bot comes to try to grab the page.

lucy24

4:31 pm on Aug 6, 2026 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



If it makes the request just once, always in response to human action, that doesn't seem especially distressing.

Jonesy

5:32 pm on Aug 15, 2026 (gmt 0)

10+ Year Member Top Contributors Of The Month



An interesting test would be to paste an invalid URL -- perhaps looking like a real URL typo -- into an Outlook email and see if you're given a "That does not look valid" pop-up or the somesuch, while composing the email. Just to see if Outlook thinks it's being 'helpful'. Curious am I.