I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Most helpful
  1. Anonymous
    2018-03-07T19:13:15+00:00

    Microsoft Edge doesn’t have an option to block Java scripts, and the original Group Policy setting for Edge that allowed users to block Java scripts has now been “disappeared”.  But I think that what I saw this morning was really just a glitch with turning on uBlock Origin. It’s pretty clear that uBlock is having some UI issues – probably resulting mostly from Edge’s efforts to replicate the display of the uBlock interface – so things are pretty buggy so far. But once we enable the advanced mode for this extension; and once we’re able to open the advanced user interface, this is very impressive:

    With blocking turned off, the advanced user interface continues to monitor the connection of domains, and you can watch the list grow in real-time:

    uBlock Origin documentation:

    https://github.com/gorhill/uBlock/wiki

    One of my main concerns here was that we might not have the ability to block scripts with this extension, but it looks like this thing has got all the bases pretty well covered – and I think we’ll be able to block virtually anything once we get er tuned up. So this is definitely going to be a “keeper” for me, one way or the other.

    GreginMich

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-07T04:49:54+00:00

    I'd be interested to know what is actually being detected and quarantined, as well as where it's being detected.

    If it's being detected in the browser cache, it's highly possible that this is the result of the Edge browser's default setting to Use page prediction..., since this may cause the detected file to be downloaded before the user actually clicks on anything.

    It's apparent that there's some sort of script or other vulnerability that's initially starting the process, but it's not clear if the next stage is still under user control or not.  We just seem to be assuming that the fact that Defender is activated means the file has made a successful intrusion.

    Rob

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-03-01T18:23:38+00:00

    There’s always the happy thought that they might have patched things up and made everything better by now. But I spend lots of time navigating on the Edge Start page (these attacks only occur after navigating to a specific article), and after a weeklong lull had me believing that everything was all better, I was hit again. So the highly intermittent and sporadic nature of these attacks makes them very hard to reproduce – and consequently the “observational data” will probably have to come mostly from the first-hand accounts of people who’ve been hit by one of these attacks. The upside is that this attack vector won’t be very effective if it’s limited to these occasional sniper shots.

    GreginMich

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. Reza-Ameri 45,891 Reputation points Volunteer Moderator
    2018-03-01T14:57:29+00:00

    In Microsoft Edge, click on Setting which is ... on the top right corner , then Send feedback->Report unsafe website and report it. Whenever you see such message do this. Cancel or Close pop up, if it is stopping you from reporting the website.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2018-03-01T14:10:39+00:00

    Microsoft is doing what it can to make people aware that these scammers are impostors and fraudsters: 

    https://www.microsoft.com/en-us/wdsi/threats/support-scams

    https://blogs.microsoft.com/on-the-issues/2017/05/18/fight-tech-support-scams/

    https://cloudblogs.microsoft.com/microsoftsecure/2017/03/02/breaking-down-a-notably-sophisticated-tech-support-scam-m-o/?source=mmpc

    But these Tech Support Scam pop-ups are normally only seen on malicious sites or legitimate sites that have been “compromised” – and what I’m reporting here is that I’m seeing malware and Tech Support Scams on the Microsoft Edge Start page. Ideally, we could let Microsoft know what’s going on here – but the communication lines are always full of chatter, and static, and cutoffs – and the message never seems to get through. So I started this thread in the hope that we could monitor this situation, and see how many other people are being attacked by malware on the Edge Start page.

    Here’s the most recent report of this issue:

    https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/windows-defender-vs-fraudulent-adobe-update/68c9bdad-94ef-4125-a265-53881ae8eee5

    GreginMich

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments