I have seen many scan entries on nginx while sharing links on Teams recently. At first I thought its some type of brute force. Even abuseipdb reports categorize it as web attack.

  • hemko@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    11
    ·
    1 day ago

    I don’t know any of the technical details behind, but what I’ve noticed there’s at least couple things that seem to happen when you send a link in teams;

    1. Microsoft defender scans that linked site and tries to figure out whether it may be “harmful”
    2. Attempts to scrape the site, render, screenshot it and embed a picture of the site contents to show to the recipient
    3. Replaces the link with defender link that forwards the user to the website

    That link safety thing is probably quite intrusive when scanning the destination webpage