I have seen many scan entries on nginx while sharing links on Teams recently. At first I thought its some type of brute force. Even abuseipdb reports categorize it as web attack.
I have seen many scan entries on nginx while sharing links on Teams recently. At first I thought its some type of brute force. Even abuseipdb reports categorize it as web attack.
I don’t know any of the technical details behind, but what I’ve noticed there’s at least couple things that seem to happen when you send a link in teams;
That link safety thing is probably quite intrusive when scanning the destination webpage
Some documentation to add to this: https://learn.microsoft.com/en-us/defender-office-365/safe-links-about
Basically its a URL wrapper that provides continuity for the user, so if they dont have a threat intel database entry for the site, they let the user go there. They scan in the background as hemko said above to determine maliciousness.
Worth mentioning they do it for email too if you have it enabled.