I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Oldest
  1. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-09T21:25:52+00:00

    My original post above was written before I took the time to research and find the article which I later added via edit.  Since I didn't have time at that point, I simply added that article URL without correcting how this might affect the original post.

    The key information here relates to the new 'high-severity' exploit discovered by Google back in November and disclosed in late February once the 90-day and 14-day grace periods had passed.  Here's another article that provides a better synopsis and doesn't confuse the situation by including an unrelated set of exploits discovered and patched in February 2017.

    Windows 10 security Google exposes how malicious sites can exploit Microsoft Edge

    This is exactly the type of potential Edge vulnerability I'd guessed might exist based on what we've learned in this thread, while the common attack vector of the ad networks (e.g. Malvertising) is relatively unimportant, except as the possible workaround it might provide for those with the knowledge and initiative to proactively protect themselves in the future.  The utter futility of attempting to manage this avenue of attack itself is well known in the security community and has only minimal relation to the website being visited when such attacks occur, since the ads are often operated in a "pass-through" manner.

    What's more important to note here, is that if as I've guessed the Trojan:JS/Flafisi.D and it's family of detections are indeed related to this 'ACG bypass using UnmapViewOfFile' vulnerability in Microsoft Edge, then the core issue will likely be resolved once Microsoft releases their update, tentatively planned for this coming Black Tuesday March 13th.

    Since the dates the various Trojan:JS/Flafisi family detections were originally released began in early December 2017 and continue into mid-February, this seems a reasonable guess.

    So though as anyone who's ever installed an ad-blocker (or simply enabled the Tracking Protection and added an appropriate tracking list in Internet Explorer 11) already knows, their own encounters with malvertising attacks are minimal, for most this current burst of detections is likely to dissipate over the next few weeks.

    Like any such newly identified zero-day vulnerability, the incidence of attacks has merely spiked ahead of the release of the update and will of course be added into the malware 'kits' in the future, as another potentially unpatched vulnerability.  Nothing really new here except the vulnerability itself.

    Rob

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-03-09T23:22:34+00:00

    But this issue affects lots of browsers, Rob. Edge and Internet Explorer users see the Microsoft Edge/Internet Explorer browser template – but Chrome and Firefox each have their own distinct template for this Kovter Group malvertising campaign. Here’s the explanation:

    https://www.proofpoint.com/us/threat-insight/post/kovter-group-malvertising-campaign-exposes-millions-potential-malware-and-fraud

    I also discovered today that while Windows Defender detects and "quarantines" this threat, the FlashPlayer.hta file can still be downloaded from the page without being intercepted if you click on the “Save" button; and could potentially be executed by clicking on the "Run” button – so we really need to be careful with this one:

    GreginMich

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-03-10T21:24:34+00:00

    I would just like to share that I've been reading some of the news stories over at the MSN page and haven't seen this nasty Trojan once.

    I haven't seen it. But I suspect that the free AdBlocker Ultimate from the Microsoft Store that I installed when I reinstalled Windows over yesterday and today has been seeing a lot of SOMETHING:

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-03-12T15:50:30+00:00

    The FlashPlayer.hta file that can be downloaded from the fake Adobe Flash Player update was submitted to the WDSI File Submission site yesterday; and it came back clean. But this file now appears to be an aberration created by a more general issue with the way that Defender is processing detected files:

     

    If I download the eicar.com test file from the EICAR download page, the file is detected as soon as the link is clicked; and then again when I try to save the file to the desktop – with the message “This file contained a virus and was deleted”, which replaces the dialog's option buttons and prevents any further download attempts.

    But when I test the eicar.com drive-by download on the AMTSO Feature Settings Check for Desktop Solutions page, the behavior is inconsistent, and in some cases this page will actually download a fictional eicar.com file to the Downloads folder, or to the desktop. As with the FlashPlayer.hta file, this downloaded eicar.com file isn’t detected on download or with a context-menu scan. So these downloaded “malware” files appear to be nothing more than harmless artifacts that are being created by a glitch in the way Defender processes detections.

    https://www.amtso.org/feature-settings-check-for-desktop-solutions/

    GreginMich

    Was this answer helpful?

    0 comments No comments
  5. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-12T16:38:35+00:00

    Greg, I hadn't responded to your previous post because I was waiting for Tuesday's updates to learn how the Adobe Flash Player update now operates on Windows 7, but thought I should make a comment.

    The fact is that none of these Flash update screens have been valid for at least Windows 8.x or 10, and possibly Chrome as well for several years now, since Microsoft and Google began including the player within their own browsers.  I believe there's a similar type of silent update performed by the current version of the Windows 7 player since Internet Explorer 10 as well, which is what I need to confirm.

    So for at least these browser versions and operating systems, these particular update screens haven't been seen in years and should be easily recognizable as fake, operating simply as social engineering attempts to install malware.

    The deeper question that needs to be answered though, is whether the script involved can manage to install any malicious payload (what I'd actually meant by "malware" in my earlier post) regardless of whether a person accepts the installation.  If you've truly determined this is possible, then the rest of the analysis is worth the effort.

    I've often seen these and other similar fake update screens offered when testing my own protection by browsing dangerously, so that's the only reason I'm at all uncertain what various older browsers still display on Windows 7, as I haven't truly used that particular laptop for anything in over 3 years.

    From my point of view, though it's great to understand how Defender actually operates, far fewer will truly benefit from the results of this analysis than a simple set of explanations of what they should truly expect and accept.

    The issues of malvertising as a delivery method are completely separate as well and that's why breaking down these issues into their components is useful, since the potential workarounds and the reason for them become clear when these questions are addressed.  Though malvertising has grown, I'd been largely unaware because I'd suppressed most of this advertising myself when Microsoft first made tracking protection available, primarily due to the visual "noise" it creates on screen.

    Rob

    Was this answer helpful?

    0 comments No comments