I have seen many scan entries on nginx while sharing links on Teams recently. At first I thought its some type of brute force. Even abuseipdb reports categorize it as web attack.
I don’t know any of the technical details behind, but what I’ve noticed there’s at least couple things that seem to happen when you send a link in teams;
- Microsoft defender scans that linked site and tries to figure out whether it may be “harmful”
- Attempts to scrape the site, screenshot it and embed a picture of the site contents to show to the recipient
- Replaces the link with defender link that forwards the user to the website
That link safety thing is probably quite intrusive when scanning the destination webpage
Some documentation to add to this: https://learn.microsoft.com/en-us/defender-office-365/safe-links-about
Basically its a URL wrapper that provides continuity for the user, so if they dont have a threat intel database entry for the site, they let the user go there. They scan in the background as hemko said above to determine maliciousness.
Worth mentioning they do it for email too if you have it enabled.



