I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Oldest
  1. Anonymous
    2018-03-12T18:23:04+00:00

    It looks like the downloaded FlashPlayer.hta file is actually just a benign fluke, and I’m hoping that it can’t be executed post detection – but we haven’t tried to execute the downloaded file, or to run the HTML app from the fake download page. And we also have several open threads where these fake update HTML apps aren’t being detected as malware on older versions of Windows – so I'm hoping that people have generally wised up to these fake updates and know enough to just close the page when it pops up.

    Earlier versions of the FlashPlayer.hta file were “double-downloaders” that first launched a PowerShell script to download and lunch an encrypted JavaScript file (intermediate payload). The intermediate payload then launched an encoded PowerShell script that used shellcode to download and launch a final payload. So this is potentially a complex threat.

    But since this thread was “escalated” by bhringer yesterday, we’ll need to concentrate on the dual issues of connecting to compromised domains on the supply side, and the issues with Defender’s processing of real-time detections on the delivery side (which now appears to be a general issue):

    https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/is-trojanjsflafisid-from-windows-10-defender-it/f0d42e70-7e7c-4d58-8941-6fd3ceb471d9

    GreginMich

    Was this answer helpful?

    0 comments No comments
  2. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-12T19:06:09+00:00

    You sure that issue with the apparent inconsistent operation of Defender during download isn't just the obvious race condition that's always existed when using SmartScreen along with Defender?

    This situation has always created interesting anomalies when the automatic operations performed by SmartScreen that hand off malicious file detection processes to Defender interact with those which happen seconds later as either the user's actions or Defender's automated filing system operations cause a potential second trigger.

    This means that in some cases, the earlier events related to SmartScreen have already snatched the file itself from the user or Defender before it can actually be seen, often leaving a zero-filled file placeholder that's either locked (quarantine) or empty (corrupted).

    This is nothing new and hasn't changed significantly since the early days of MSE, though there's likely been minor changes in the way these errors are displayed due to either filing system or other process changes to either SmartScreen or Defender themselves.  Since Defender has always seemed to be unaware that it's already processing the same file, I assume that's because it's specifically performing these operations in isolated processes, possibly to allow the most effective and fastest process to "win" regardless which one this might be.

    As for the compromised domains, we already knew (which that article confirms) that the creation and so pace of change for these had exceeded that for any existing manual system to keep up with a few years ago.  This implies that protection needs to be either proactive (ad blocking) or handle this by blocking the false pages within the browser itself, before the malware content can become an issue.

    How to identify a good page from a bad page is the problem with the latter, since it's typically a matter of the content, which is what this particular detection appears to be focused on as relates to the malicious JavaScript it contains.

    Rob

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-03-12T20:30:53+00:00

    Windows Defender SmartScreen is always turned off for this kind of testing, since it would otherwise block access to the eicar download. Could it have caused this issue had it been turned on? Most likely not.

    I don’t have time to argue that it’s possible to break a malvertising supply chain, but it happens quite frequently; and it should be a major concern for any website that wants a “safe site” reputation.

    OK, I just turned Windows Defender SmartScreen back on and retested; and now I have to correct myself. SmartScreen doesn’t block the eicar.com download – it merely allows the download of a 0 bytes eicar.com file:

    And then it leaves its message in place when I switch back to the forum site:

    GreginMich

    Was this answer helpful?

    0 comments No comments
  4. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-12T21:18:57+00:00

    OK, that's something I didn't see you state in your testing above, but I suspect that since SmartScreen is now integrated within Windows 10 it may not truly be possible to fully disable it's operation, though I don't really care either.

    Breaking a malvertising chain has always been done by a major operation like Microsoft in cooperation with others, typically including international law enforcement.  With Microsoft providing the data required to identify the true perpetrators, as well as any C&C or other server resources when those are involved.  That's what Microsoft always does in these cases, while many run around dealing with peripheral effects as the investigation and data collection continues.

    That's why I always take the workaround direction and ignore the noise, since those who don't know how to protect themselves might actually get successfully attacked during the typical delay that occurs.

    As I stated above, nothing new other than a different type of detection for a new snippet of JavaScript likely relating to a new vulnerability.  We may learn something more about this tomorrow when the updates release.

    Rob

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2018-03-12T21:40:18+00:00

    Nothing new if you keep your eyes closed. Otherwise we have a malvertising issue on MSN webpages, and one that doesn’t leverage exploits according to the latest available analysis. And also a totally bizzare blocking behavior by both Windows Defender Antivirus and Windows Defender SmartScreen.

    GreginMich

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments