I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Newest
  1. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-09T21:25:52+00:00

    My original post above was written before I took the time to research and find the article which I later added via edit.  Since I didn't have time at that point, I simply added that article URL without correcting how this might affect the original post.

    The key information here relates to the new 'high-severity' exploit discovered by Google back in November and disclosed in late February once the 90-day and 14-day grace periods had passed.  Here's another article that provides a better synopsis and doesn't confuse the situation by including an unrelated set of exploits discovered and patched in February 2017.

    Windows 10 security Google exposes how malicious sites can exploit Microsoft Edge

    This is exactly the type of potential Edge vulnerability I'd guessed might exist based on what we've learned in this thread, while the common attack vector of the ad networks (e.g. Malvertising) is relatively unimportant, except as the possible workaround it might provide for those with the knowledge and initiative to proactively protect themselves in the future.  The utter futility of attempting to manage this avenue of attack itself is well known in the security community and has only minimal relation to the website being visited when such attacks occur, since the ads are often operated in a "pass-through" manner.

    What's more important to note here, is that if as I've guessed the Trojan:JS/Flafisi.D and it's family of detections are indeed related to this 'ACG bypass using UnmapViewOfFile' vulnerability in Microsoft Edge, then the core issue will likely be resolved once Microsoft releases their update, tentatively planned for this coming Black Tuesday March 13th.

    Since the dates the various Trojan:JS/Flafisi family detections were originally released began in early December 2017 and continue into mid-February, this seems a reasonable guess.

    So though as anyone who's ever installed an ad-blocker (or simply enabled the Tracking Protection and added an appropriate tracking list in Internet Explorer 11) already knows, their own encounters with malvertising attacks are minimal, for most this current burst of detections is likely to dissipate over the next few weeks.

    Like any such newly identified zero-day vulnerability, the incidence of attacks has merely spiked ahead of the release of the update and will of course be added into the malware 'kits' in the future, as another potentially unpatched vulnerability.  Nothing really new here except the vulnerability itself.

    Rob

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-03-08T23:44:22+00:00

    Most likely it’s the same, or similar to, the FlashPlayer.hta that was identified and dissected here almost a year ago:

    https://www.bleepingcomputer.com/news/security/skype-malvertising-campaign-pushes-fake-flash-player/

    Defender detects this HTML app as soon as it’s offered for download; and I’ve always just closed the page at that point – so I can’t say for sure what would happen if someone actually clicked on “Run” or “Save”. But I certainly wouldn’t presume that this detection doesn’t involve any real malware, since it has all the hallmarks of a signature-based detection. And I honestly can’t recall ever having seen a real-time detection that didn’t have the browser cache as the detection path, so I don’t think that’s really anything out of the ordinary.

    This is a no-blocker day for me here; and in the hour that I spent on the MSN news pages this morning, I had two detections for Trojan:JS/Flafisi.D and one more Tech Support Scam incident. One of the Trojan:JS/Flafisi.D detections was “invisible”, with no fake Adobe Flash Player update appearing in the browser.  The invisible detection seems to have been a status update for a detection that was originally made on 3/5/2018:

    Now, a status of “106” doesn’t appear in the documentation:

    ThreatStatusID

    Data type: uint8

    Access type: Read-only

    The Threat Status ID - Enumeration

    Unknown (0)

    Detected (1)

    Cleaned (2)

    Quarantined (3)

    Removed (4)

    Allowed (5)

    Blocked (6)

    CleanFailed (Blocked)

    QuarantineFailed (102)

    RemoveFailed (103)

    AllowFailed (104)

    Abondoned (105)

    BlockedFailed (107)

    But the status is indicated as “Abandoned” in the Full History details:

    And this is all getting just a little too spooky for my liking.

    GreginMich

    Was this answer helpful?

    5 people found this answer helpful.
    0 comments No comments
  3. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-08T18:36:07+00:00

    Looking back through this entire thread it seems to me that it's likely this recent variation of this particular detection, which was dated Feb 02, has probably found a new method of manipulating the Edge browser's JavaScript in a way that allows it to trigger such popups.

    Since from other threads I see that a typical detection is simply for the flashplayer.hta file in the browser cache, it's still questionable whether any true malware is involved.  In fact, as I recall the more typical operation of real-time detections by Microsoft had been to completely ignore the cache, since in most cases these items were blocked by the security features in the browser itself.

    So what I think we may be seeing here is the operation of a modified detection designed to head off this particular family or specific variant due to a deeper problem with whatever vulnerability within the browser it's exploiting to execute its payload.

    In other words, exactly as Microsoft has always done with their antimalware products, they're using Defender to block the operation of a new type of malware exploitation until they can build, test and deploy the actual patch to the Edge code, possibly a flaw in hta handling, that's truly causing the problem.  This is what's causing the increase in "noise" for Defender, a drastic change from it's more typically quiet operation.

    I say all of this due to the discussion of symptoms and apparent change in operation that Greg and others here have mentioned, while for others like myself there's been no change at all, since the attack vector of advertisements is something some of us have always known and blocked as a workaround.

    If I'm correct the timing of the last two variants of this detection on Feb 02, with the later addition of a PowerShell variant on Feb 14th, implies we may see an update released within the typical March Black Tuesday package that deals with this deeper issue.

    Rob

    Furthering the above speculation, here's a possible candidate that may explain why these un-characteristic detections within the cache were added, as well as why the documentation for them seems so sparse.

    Google discloses ‘high-severity’ exploit in Windows 10 before it’s patched

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2018-03-07T21:43:48+00:00

    Ya, it was easy to get the impression that Microsoft was banning JavaScript with the development of Microsoft Edge when in fact they were just building it into the core of their new browser. The Chakra JavaScript engine was specially engineered for Edge by Microsoft, and then later open sourced as ChakraCore:

    https://github.com/microsoft/ChakraCore

    But I guess there’s really no getting around the need for a scripting engine of some sort, and the best we can do here is simply learn how to manage things when the JavaScript is being misused. With a little bit of luck, though, I think we’ll be able to manage this particular issue by just blocking the bad domain(s).

    GreginMich

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2018-03-07T20:34:16+00:00

    Looks good! I wish someone had mentioned this because the whole selling point of Edge (to me, anyway) was that you weren't supposed to even be able to run JavaScript on the browser. Remember all the publicity about that back in the day?

    https://techhelpkb.com/java-and-microsoft-edge/

    Yet now, thanks to policy changes we're as vulnerable to this rubbish as ever. Perhaps more so even than with Explorer.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments