so i was hunting down a rogue bot in our logs and saw an IP address (not ours) trying to hit a page in our backend, it did force them out, but I figured out how it found that "link"
I had copied over a part number from out backend into a Microsoft 365 Outlook email, but had NOT sent it yet. It just happened to be the very same part number that I had copied and pasted into this email and their bot tried to hit it.
Mind you i had NOT sent the email, I'd copied it over and then right clicked the link and clicked remove URL. Which it did, however not BEFORE some BS bot tried to hit our admin page.
52.112.39.133 was the culprit
This is disturbing to say the least.