It looks like the downloaded FlashPlayer.hta file is actually just a benign fluke, and I’m hoping that it can’t be executed post detection – but we haven’t tried to execute the downloaded file, or to run the HTML app from the fake download page. And we also have several open threads where these fake update HTML apps aren’t being detected as malware on older versions of Windows – so I'm hoping that people have generally wised up to these fake updates and know enough to just close the page when it pops up.
Earlier versions of the FlashPlayer.hta file were “double-downloaders” that first launched a PowerShell script to download and lunch an encrypted JavaScript file (intermediate payload). The intermediate payload then launched an encoded PowerShell script that used shellcode to download and launch a final payload. So this is potentially a complex threat.
But since this thread was “escalated” by bhringer yesterday, we’ll need to concentrate on the dual issues of connecting to compromised domains on the supply side, and the issues with Defender’s processing of real-time detections on the delivery side (which now appears to be a general issue):
GreginMich