I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Oldest
  1. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-14T17:30:50+00:00

    My eye's aren't closed at all, I'm simply never going to experience these types of network delivered malvertising attacks because by using ad blocking I've cut them off before they can ever reach the browser, which is currently the only effective way to guarantee you'll never experience them.

    It's a nice thought that Microsoft or others with popular destination pages might mange to break a malvertising supply chain, but that takes time and until it happens you'll continue to experience these attacks if you're part of the malvertiser's target.  In case you hadn't seen it, some of the articles discussing that earlier Kovter attack mentioned that these used a number of filters including ISP, fingerprinting of the timezone, screen dimension, language (user/browser) history length of the current browser windows, and unique id creation via Mumour, to target users and evade analysis.

    The fact that MSN was affected is itself insignificant, since anyone using the primary ad network through which the underlying malicious network was fed could have been affected.  Remember that there isn't a single layer of these, it's actually multiple layers of networks feeding networks, so finding the true offender is a needle in a haystack and whack-a-mole problem.

    Just as with my own confusion with multiple settings and other changes to security I've made over time, you appear to have added confusion relating to Windows Defender configuration changes you've made as well.  How these may be affecting your specific configuration(s) is unknown and though these may have no effect on what you're observing, that's impossible to know without starting with a clean Windows installation.

    I don't deny that you've learned some potentially valuable details, I only feel that consumers require a simpler and thus more foolproof approach to protect themselves and especially others like children who use their PC in the home.

    Rob

    < EDIT > The question of the use of exploits or simply social engineering as appears in this case was being discussed years ago; Malvertising Could Replace Exploit Kits: Researchers.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-03-14T21:09:26+00:00

    The fact that the millions of people who use the MSN news pages (without an ad-blocker) are being subjected to a malvertising campaign certainly isn’t insignificant to me, and it shouldn’t really be insignificant to Microsoft.

    Lots of issues will disappear with a clean install, and with default settings. But all of those issues that you can make go away by removing the factors introduced by the real-world use of Windows are part and parcel of the “Windows experience” – and they invariably need to be addressed. So it’s unfortunate that Microsoft seems to have adopted this same “we just don’t need to go there” attitude as their new paradigm. Here’s a good example of how this works: I’ve identified a serious issue with the Windows Defender Security Center app crashing with High Contrast mode settings, and this issue sadly affects anyone who uses the Ease of Access Center keyboard shortcut to turn on High Contrast (ALT + left SHIFT + PRINT SCREEN):

    https://social.technet.microsoft.com/Forums/en-US/b75d8052-4623-4634-869d-52042d5404cf/windows-defender-security-center-crashes-windows-10?forum=win10itprosecurity

    The issue has been confirmed; and was purportedly escalated by the TechNet moderator in the thread, but without any response.

    And the bug report for this issue has just been sitting on the shelf for several months now. To show their appreciation for my efforts, though, the report has now been attributed to “unknown”, along with all of my other Feedback Hub posts.

    https://aka.ms/Snh01f

    But hey, it’s an issue that only gets experienced by visually impaired Windows users, and if they would just fork over the cash for that laser surgery, they could use the normal screen settings just like the rest of us and there wouldn't be any issue at all. Sorry guys, but all of these issues are real – you just have to be willing to walk that long and lonely mile.

    [Edit: 3/15/2018]

    I just filed this bug report for the spurious "malware" files that can be downloaded on the Edge browser:

    https://aka.ms/Shi5dv

    The behavior is essentially the same in Internet Explorer, with the difference that the downloaded file is identified as “partial”:

     

    And we have the same inability to close the SmartScreen dialog after a file block, with its consequent persistence when moving to another page:

    [end Edit]

    GreginMich

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-03-17T19:44:11+00:00

    I’m just adding this link:

    https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/trojanjsflafisid/b70661cc-5b98-4e9b-9db4-f76d5b1bb69c

    Since this is the thread that appears at the top of the Bing search list for “Trojan:JS/Flafisi.D”, and it’s consequently getting most of the hits for this issue with malvertising on the MSN news pages.

    GreginMich

    Was this answer helpful?

    0 comments No comments
  4. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-18T01:39:15+00:00

    There's a description of at least one known campaign using this fake flashplayer social engineering attack to deliver the Ramnit Trojan, which sounds like a reasonable match to the Defender detection.  I found it on BroadAnalysis Twitter with the hashtags #FakeFlash, #FakeChrome and #Ramnit among others.

    I won't provide a link since the final page provides downloads, but there's enough above to find it easily.

    I noticed that Microsoft included several patches for Edge exploits including the one I mentioned above in this last Tuesday's updates, but supposedly none of these were being actively exploited, so I don't know if any of these were involved in this current campaign or not.  It may simply have been a flare-up of the social-engineering method, but it seems from the detection and aggressive deletion that it's not being handled in the typical quiet manner these had in the past.

    I suspect that I've been unable to duplicate due to the many aggressive settings I've made, several of which might appear to the attackers as if I'm a security researcher, which they often try to avoid.

    I have no concerns about such a campaign for anyone who's PC I've personally configured.  I wouldn't see this for several reasons along with avoiding the popular trash news websites, ad blocking, aggressive browser configuration such as disabling all default pages and extreme privacy settings.

    Why anyone accepts default settings I'll never understand, but then I've typically spent at least an hour configuring a newly installed Windows before general browsing begins for years now.  However, the only item I've changed from your more recent page of configuration items for commercial users is CFA and that was simply to see if it affected me negatively.  I won't make the stupid mistakes that typically result in successful encrypted ransomware attacks, even when browsing dangerously to test.

    Rob

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2018-03-18T16:02:13+00:00

    It’s a detection for Trojan:JS/Flafisi.D. If it were the Ramnit Trojan, it would most likely be detected as a Trojan:Win32/Ramnit variant.

    https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Win32/Ramnit

    The current Ramnit Trojan attack has a totally different look and feel, and it attempts to download flashplayer_33.9.22.js.

    But the point here is that a compromised advertising domain could potentially deliver any kind of threat, as the latest analysis of the FlashPlayer.hta file emphasizes:

    Conclusion

    The combination of large malvertising campaigns on very high-ranking websites with sophisticated social engineering schemes that convince users to infect themselves means that potential exposure to malware is quite high, reaching millions of web surfers. Once again, we see actors exploiting the human factor even as they adapt tools and approaches to a landscape in which traditional exploit kit attacks are less effective. While the payload in this case is ad fraud malware, it could just as easily have been ransomware, an information stealer, or any other malware. Regardless, threat actors are following the money and looking to more effective combinations of social engineering, targeting, and pre-filtering to infect new victims at scale.

    https://www.proofpoint.com/us/threat-insight/post/kovter-group-malvertising-campaign-exposes-millions-potential-malware-and-fraud

    So the payload is really irrelevant, and the point (once again) is that there’s an open malware channel on the MSN news pages.

    Some previous incidents of malvertising on the MSN news pages were identified by Malwarebytes:

    https://blog.malwarebytes.com/threat-analysis/2015/08/angler-exploit-kit-strikes-on-msn-com-via-malvertising-campaign/

    https://blog.malwarebytes.com/threat-analysis/2016/01/msn-home-page-drops-more-malware-via-malvertising/

    https://blog.malwarebytes.com/threat-analysis/2017/09/tech-support-scammers-abuse-native-ad-content-provider-taboola-serve-malvertising/ 

    Here’s an old news article that puts the issue in some historical perspective, and implicitly explains why this issue is still with us today.

    https://www.tomsguide.com/us/malvertising-what-it-is,news-19877.html

    The article wanted to point the finger of blame squarely at the ad networks with the implication that they would be able to manage the issue themselves with internal guidelines. And of course as soon as you absolve site administrators of the responsibility of monitoring the supply chain, and keeping malvertising off of their websites, you’ve really just managed to set the malvertising wheel in perpetual motion. Self-regulation quite obviously isn’t working here, and attempting to shift the blame to the ad networks has really just prolonged our misery. What a site serves up to the public is the responsibility of the site’s owners and administrators, and the content needs to be managed locally.

    This could presumably be done with a minimal investment by using automated monitoring, tracking, cutoff, and replacement of the compromised advertising domains that are delivering these threats to the host site. And the cost of internal management of advertising domains would most likely pale in comparison to what a high-profile site is going to lose in terms of advertising revenues (and reputation) if we have to manage this issue ourselves with ad-blockers. So let’s apply some of that great new “next-gen” technology to maintaining safe Microsoft sites.

    GreginMich

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments