I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Newest
  1. Anonymous
    2018-03-12T18:23:04+00:00

    It looks like the downloaded FlashPlayer.hta file is actually just a benign fluke, and I’m hoping that it can’t be executed post detection – but we haven’t tried to execute the downloaded file, or to run the HTML app from the fake download page. And we also have several open threads where these fake update HTML apps aren’t being detected as malware on older versions of Windows – so I'm hoping that people have generally wised up to these fake updates and know enough to just close the page when it pops up.

    Earlier versions of the FlashPlayer.hta file were “double-downloaders” that first launched a PowerShell script to download and lunch an encrypted JavaScript file (intermediate payload). The intermediate payload then launched an encoded PowerShell script that used shellcode to download and launch a final payload. So this is potentially a complex threat.

    But since this thread was “escalated” by bhringer yesterday, we’ll need to concentrate on the dual issues of connecting to compromised domains on the supply side, and the issues with Defender’s processing of real-time detections on the delivery side (which now appears to be a general issue):

    https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/is-trojanjsflafisid-from-windows-10-defender-it/f0d42e70-7e7c-4d58-8941-6fd3ceb471d9

    GreginMich

    Was this answer helpful?

    0 comments No comments
  2. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-12T16:38:35+00:00

    Greg, I hadn't responded to your previous post because I was waiting for Tuesday's updates to learn how the Adobe Flash Player update now operates on Windows 7, but thought I should make a comment.

    The fact is that none of these Flash update screens have been valid for at least Windows 8.x or 10, and possibly Chrome as well for several years now, since Microsoft and Google began including the player within their own browsers.  I believe there's a similar type of silent update performed by the current version of the Windows 7 player since Internet Explorer 10 as well, which is what I need to confirm.

    So for at least these browser versions and operating systems, these particular update screens haven't been seen in years and should be easily recognizable as fake, operating simply as social engineering attempts to install malware.

    The deeper question that needs to be answered though, is whether the script involved can manage to install any malicious payload (what I'd actually meant by "malware" in my earlier post) regardless of whether a person accepts the installation.  If you've truly determined this is possible, then the rest of the analysis is worth the effort.

    I've often seen these and other similar fake update screens offered when testing my own protection by browsing dangerously, so that's the only reason I'm at all uncertain what various older browsers still display on Windows 7, as I haven't truly used that particular laptop for anything in over 3 years.

    From my point of view, though it's great to understand how Defender actually operates, far fewer will truly benefit from the results of this analysis than a simple set of explanations of what they should truly expect and accept.

    The issues of malvertising as a delivery method are completely separate as well and that's why breaking down these issues into their components is useful, since the potential workarounds and the reason for them become clear when these questions are addressed.  Though malvertising has grown, I'd been largely unaware because I'd suppressed most of this advertising myself when Microsoft first made tracking protection available, primarily due to the visual "noise" it creates on screen.

    Rob

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-03-12T15:50:30+00:00

    The FlashPlayer.hta file that can be downloaded from the fake Adobe Flash Player update was submitted to the WDSI File Submission site yesterday; and it came back clean. But this file now appears to be an aberration created by a more general issue with the way that Defender is processing detected files:

     

    If I download the eicar.com test file from the EICAR download page, the file is detected as soon as the link is clicked; and then again when I try to save the file to the desktop – with the message “This file contained a virus and was deleted”, which replaces the dialog's option buttons and prevents any further download attempts.

    But when I test the eicar.com drive-by download on the AMTSO Feature Settings Check for Desktop Solutions page, the behavior is inconsistent, and in some cases this page will actually download a fictional eicar.com file to the Downloads folder, or to the desktop. As with the FlashPlayer.hta file, this downloaded eicar.com file isn’t detected on download or with a context-menu scan. So these downloaded “malware” files appear to be nothing more than harmless artifacts that are being created by a glitch in the way Defender processes detections.

    https://www.amtso.org/feature-settings-check-for-desktop-solutions/

    GreginMich

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-03-10T21:24:34+00:00

    I would just like to share that I've been reading some of the news stories over at the MSN page and haven't seen this nasty Trojan once.

    I haven't seen it. But I suspect that the free AdBlocker Ultimate from the Microsoft Store that I installed when I reinstalled Windows over yesterday and today has been seeing a lot of SOMETHING:

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2018-03-09T23:22:34+00:00

    But this issue affects lots of browsers, Rob. Edge and Internet Explorer users see the Microsoft Edge/Internet Explorer browser template – but Chrome and Firefox each have their own distinct template for this Kovter Group malvertising campaign. Here’s the explanation:

    https://www.proofpoint.com/us/threat-insight/post/kovter-group-malvertising-campaign-exposes-millions-potential-malware-and-fraud

    I also discovered today that while Windows Defender detects and "quarantines" this threat, the FlashPlayer.hta file can still be downloaded from the page without being intercepted if you click on the “Save" button; and could potentially be executed by clicking on the "Run” button – so we really need to be careful with this one:

    GreginMich

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments