I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Newest
  1. Rob Koch 26,080 Reputation points Volunteer Moderator
    2018-03-14T17:30:50+00:00

    My eye's aren't closed at all, I'm simply never going to experience these types of network delivered malvertising attacks because by using ad blocking I've cut them off before they can ever reach the browser, which is currently the only effective way to guarantee you'll never experience them.

    It's a nice thought that Microsoft or others with popular destination pages might mange to break a malvertising supply chain, but that takes time and until it happens you'll continue to experience these attacks if you're part of the malvertiser's target.  In case you hadn't seen it, some of the articles discussing that earlier Kovter attack mentioned that these used a number of filters including ISP, fingerprinting of the timezone, screen dimension, language (user/browser) history length of the current browser windows, and unique id creation via Mumour, to target users and evade analysis.

    The fact that MSN was affected is itself insignificant, since anyone using the primary ad network through which the underlying malicious network was fed could have been affected.  Remember that there isn't a single layer of these, it's actually multiple layers of networks feeding networks, so finding the true offender is a needle in a haystack and whack-a-mole problem.

    Just as with my own confusion with multiple settings and other changes to security I've made over time, you appear to have added confusion relating to Windows Defender configuration changes you've made as well.  How these may be affecting your specific configuration(s) is unknown and though these may have no effect on what you're observing, that's impossible to know without starting with a clean Windows installation.

    I don't deny that you've learned some potentially valuable details, I only feel that consumers require a simpler and thus more foolproof approach to protect themselves and especially others like children who use their PC in the home.

    Rob

    < EDIT > The question of the use of exploits or simply social engineering as appears in this case was being discussed years ago; Malvertising Could Replace Exploit Kits: Researchers.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-03-12T21:40:18+00:00

    Nothing new if you keep your eyes closed. Otherwise we have a malvertising issue on MSN webpages, and one that doesn’t leverage exploits according to the latest available analysis. And also a totally bizzare blocking behavior by both Windows Defender Antivirus and Windows Defender SmartScreen.

    GreginMich

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. Rob Koch 26,080 Reputation points Volunteer Moderator
    2018-03-12T21:18:57+00:00

    OK, that's something I didn't see you state in your testing above, but I suspect that since SmartScreen is now integrated within Windows 10 it may not truly be possible to fully disable it's operation, though I don't really care either.

    Breaking a malvertising chain has always been done by a major operation like Microsoft in cooperation with others, typically including international law enforcement.  With Microsoft providing the data required to identify the true perpetrators, as well as any C&C or other server resources when those are involved.  That's what Microsoft always does in these cases, while many run around dealing with peripheral effects as the investigation and data collection continues.

    That's why I always take the workaround direction and ignore the noise, since those who don't know how to protect themselves might actually get successfully attacked during the typical delay that occurs.

    As I stated above, nothing new other than a different type of detection for a new snippet of JavaScript likely relating to a new vulnerability.  We may learn something more about this tomorrow when the updates release.

    Rob

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2018-03-12T20:30:53+00:00

    Windows Defender SmartScreen is always turned off for this kind of testing, since it would otherwise block access to the eicar download. Could it have caused this issue had it been turned on? Most likely not.

    I don’t have time to argue that it’s possible to break a malvertising supply chain, but it happens quite frequently; and it should be a major concern for any website that wants a “safe site” reputation.

    OK, I just turned Windows Defender SmartScreen back on and retested; and now I have to correct myself. SmartScreen doesn’t block the eicar.com download – it merely allows the download of a 0 bytes eicar.com file:

    And then it leaves its message in place when I switch back to the forum site:

    GreginMich

    Was this answer helpful?

    0 comments No comments
  5. Rob Koch 26,080 Reputation points Volunteer Moderator
    2018-03-12T19:06:09+00:00

    You sure that issue with the apparent inconsistent operation of Defender during download isn't just the obvious race condition that's always existed when using SmartScreen along with Defender?

    This situation has always created interesting anomalies when the automatic operations performed by SmartScreen that hand off malicious file detection processes to Defender interact with those which happen seconds later as either the user's actions or Defender's automated filing system operations cause a potential second trigger.

    This means that in some cases, the earlier events related to SmartScreen have already snatched the file itself from the user or Defender before it can actually be seen, often leaving a zero-filled file placeholder that's either locked (quarantine) or empty (corrupted).

    This is nothing new and hasn't changed significantly since the early days of MSE, though there's likely been minor changes in the way these errors are displayed due to either filing system or other process changes to either SmartScreen or Defender themselves.  Since Defender has always seemed to be unaware that it's already processing the same file, I assume that's because it's specifically performing these operations in isolated processes, possibly to allow the most effective and fastest process to "win" regardless which one this might be.

    As for the compromised domains, we already knew (which that article confirms) that the creation and so pace of change for these had exceeded that for any existing manual system to keep up with a few years ago.  This implies that protection needs to be either proactive (ad blocking) or handle this by blocking the false pages within the browser itself, before the malware content can become an issue.

    How to identify a good page from a bad page is the problem with the latter, since it's typically a matter of the content, which is what this particular detection appears to be focused on as relates to the malicious JavaScript it contains.

    Rob

    Was this answer helpful?

    0 comments No comments