Thanks for that firsthand report, Charles. A firsthand experience is way more convincing than a thousand words. But with each of my 5 detections, this threat was actually blocked rather than quarantined – and since your detection sounds a little “anomalous”, you might want to run a Full Scan for a double-check, or maybe even check the current status of the threat with the Get-MpThreatDetection command, as I’ve illustrated here:
We have been seeing a few reports of issues with the removal of this threat:
While it looks like we’ve come out unscathed this time, we really do have to wonder if we’ll be so lucky with the next threat that gets delivered through this malware-site-redirect attack vector – which is why my original question was “what’s next”. Windows Defender is getting stronger every day, but no AV app is really capable of stopping everything out there. And we also have to wonder about how well people with weak or outdated AV protection (and/or unpatched vulnerabilities) will fare against these hit-and-run attacks. That’s why I’m not willing to accept the presence of these malware-site redirects as the “new normal” for trusted sites. Trusted sites shouldn’t pose any risk at all to their users.
GreginMich