I have seen many scan entries on nginx while sharing links on Teams recently. At first I thought its some type of brute force. Even abuseipdb reports categorize it as web attack.
I have seen many scan entries on nginx while sharing links on Teams recently. At first I thought its some type of brute force. Even abuseipdb reports categorize it as web attack.
Some documentation to add to this: https://learn.microsoft.com/en-us/defender-office-365/safe-links-about
Basically its a URL wrapper that provides continuity for the user, so if they dont have a threat intel database entry for the site, they let the user go there. They scan in the background as hemko said above to determine maliciousness.
Worth mentioning they do it for email too if you have it enabled.