I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Oldest
  1. Anonymous
    2018-05-01T22:01:39+00:00

    I'm just as frustrated at these issues as most of you are. My team has been working on trying to identify the culprit - we believe an ad is at play, but the ad creatives have been sneaky in hiding their tracks and we're sifting through terabytes of telemetry data that could potentially lead into finding the culprit. Once we do, we'll block it and go after the folks who designed it so we can prevent from happening. 

    I apologize for the delay in getting this resolved. It has proven trickier than I expected. For those who do get this often, the idea thing would be have fiddler running at the same time and save the trace for my team to review, but it's a hard to ask of anyone so I'm pursuing the route of telemetry data analysis instead.

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  3. Anonymous
    2018-05-02T04:17:03+00:00

    we understand your frustration as we are having to "control alt delete" to stop our pc's from screaming "YOUR PC IS INFECTED! Alert, Call this number, this site is stealing your info"...  I know its not infecting the PC but it locks up Edge.

    You shouldn't be trying to hunt down these sites, the Edge team should be fixing this and it should be a #1 priority so it can't happen like with Chrome/Firefox...  You should be banging on the door of the Edge team going FIX THIS NOW.

    This is why hundreds of thousands of people leave Edge and get firefox/Chrome everyday.

    If MS doesn't care about Edge then seriously cancel it and bundle Windows with Chrome.

    It doesn't even look like MS uses Edge... its sad really.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Rob Koch 26,080 Reputation points Volunteer Moderator
    2018-05-02T05:00:35+00:00

    Rodrigo,

    Is that the same telemetry data that the Windows Defender/Anti-Malware teams can provide, since I mentioned to Greg, the originator of this thread that he should suggest you contact them?

    They're obviously able to identify at least the incidents which invoke the Trojan identified in this thread, so I'd think that this might aid in narrowing those particular events down, though that also depends upon whether they can be traced back to the page which originally invoked the redirect.

    I would assume that these ads are not only being targeted at particular types of users, but also that the advertisers involved are using the same techniques that were identified by the Confiant security group in this article about the Ziconium group in January.  This allows them not only to filter for their targets, but also to avoid triggering the ads for security researchers and others trying to find them like your group.

    Uncovering 2017’s Largest Malvertising Operation – Confiant

    As a side note, I eventually realized that in my own case it's my relatively extreme privacy and other settings that allow me to avoid these completely.  Since I have the Advertising ID turned off and also normally use Internet Explorer with both tracking cookies blocked and IE Tracking protection enabled with the EasyPrivacy list, I'm an unlikely target for this type of attack.  My settings have less to do with malvertising than my own aversion to the noise that ads create, but apparently has the side effect of suppressing these type of targeted attacks as well.

    Rob

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2018-05-02T16:54:13+00:00

    It's not the same telemetry as Defender. What my team is looking at is to see the actual creative IDs that were served prior to the auto-redirect that happens. This comes from MSN owned telemetry, but digesting the historical browsed data in anonymous fashion is very expensive which is why I've been asking for some clues from users in the forms of new feedback entries.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments