We had the same thing happen a few times and ended up creating an antimalware service that used Googles list of malware domains to check all user added outgoing links
In this case it would be tricky since the link is to google drive and we can’t block those. Also we’ve seen people work around url blocks by either using short links or by using html pages hosted for free to redirect using JS instead of an HTTP redirect. Always another mole to whack :,)