Thanks, bhringer. I’ve reported multiple issues along the way in this thread, and my guess here is that
PaulSey... is responding to my reports about problems with the way that Windows Defender Antivirus and Windows Defender SmartScreen handle detections, and that the announcement at the Feedback Hub is actually announcing
corrections for the issues that I previously described in this report:
https://aka.ms/AA1abe5
There might also have been some confusion regarding the inability to detect my submission of the FlashPlayer.hta file as malware, which in hindsight might also be related to the issue described by Catalin Cimpanu:
Researchers noted a curious thing about this campaign. The downloaded files — the JavaScript and HTA files — wouldn't execute on a computer if the PC's IP address didn't pass the same ISP and geo filters. The purpose of this second check was to limit analysis from security researchers.
https://www.bleepingcomputer.com/news/security/malvertising-group-spreading-kovter-malware-via-fake-browser-updates/
But these issues are incidental to the malvertising issue that Rodrigo is trying to help us with here, and they’re also not being described accurately in the Feedback Hub announcement, so while I sincerely appreciate the efforts to fix Defender’s detections,
the malvertising issue is the main topic of this thread, and it takes precedence over any other issues.
My own experience with the MSN news pages has improved drastically in the last couple of days: The runaway resource utilization that I’ve been seeing on most news pages is gone, and I also haven’t seen any of the fake Adobe Flash Payer update screens
or Tech Support Scam pages for a couple of days now – but of course it’s still too soon to say for sure that everything is “all better”.
In fact, things are so quiet on the MSN news pages that in order to see the changes that
PaulSey... is talking about, I had to click on my link to the Yahoo Home page. I just opened up the article on the
Schneiderman case and waited for a couple of minutes – and sure enough, the fake Adobe Flash Player update screen popped up. But this time there wasn’t any immediate detection for Trojan:JS/Flafisi.D. So I proceeded to download the FlashPlayer.hta
file to my desktop, and at that point the file was detected as a virus and deleted.
In a second incident on another Yahoo news page, I noticed that the
FlashPlayer.hta download tab is now persistent, and that the download is still active even when I page back and then forward, and the page can no longer be found. And then once the download is attempted, the file is detected as a virus
and the "FlashPlayer.hta contained a virus and was deleted" message persists on subsequently visited pages:

So it looks like the detection was "fixed" in the sense that the threat isn't detected until the download is actually attempted – but there's obviously still some more work to be done on the issues that I originally pointed
out in this thread, and in my bug report. And once again, it's very important to understand that these issues with the way that Defender processes detections are in no way specific to Trojan:JS/Flafisi.D detections, and that they consequently don't have any
direct relevance to the malvertising issue that we’re discussing here. Malvertising simply refers to the appearance of ad-delivered malware pages on a host site.
Since the changes in Defender’s detection scheme apply generally, it’s easy to see how things have changed just by experimenting with the eicar.com test file; or with the test files provided on the AMTSO and Windows Defender Testground websites:
http://www.eicar.org/85-0-Download.html
https://www.amtso.org/security-features-check/
https://demo.wd.microsoft.com/
Also note that the test for Windows Defender’s Network Protection feature is now functional, even though the page doesn't display properly:
https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-exploit-guard/enable-network-protection
GreginMich