Phishing Simulator report showing bots - what are they?

Brass Contributor

Hi we recently ran a phishing simulation and two results came back as:

162.125.34.244DropboxPreviewBot/1.0
52.114.75.71Mozilla/5.0 (Windows NT 6.1; WOW64) SkypeUriPreview Preview/0.5

Both of these are non UK (we are based in UK)

 

So it looks like they are bots/crawlers, but how are they associated with the email of two of our users, which say they clicked the link... I am no bot expert either but what is actually happening here?

 

Thanks

Neil

1 Reply

@neilcarden 

 

Mozilla/5.0 (Windows NT 6.1; WOW64) SkypeUriPreview Preview/0.5

 

Hi Neil,

 

I also encountered this useragent today and after testing found out that these are not due to the user click however because of automatic preview of url by application like skype/teams.

 

Its evident that dropbox one is also related to preview by said app.

 

Thanks

Nitin