I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Oldest
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  3. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  4. Anonymous
    2018-05-26T11:48:22+00:00

    You say "Not really MikeST, the browser's doing exactly what it's supposed to, though Microsoft might possibly make it a bit easier to exit some of these within Edge."

    Firefox and Chome do not respond to this... So yes its an issue with the Microsoft Browser.

    Thats what MS needs to fix.

    Was this answer helpful?

    0 comments No comments
  5. Rob Koch 26,080 Reputation points Volunteer Moderator
    2018-05-26T12:53:30+00:00

    You say "Not really MikeST, the browser's doing exactly what it's supposed to, though Microsoft might possibly make it a bit easier to exit some of these within Edge."

    Firefox and Chome do not respond to this... So yes its an issue with the Microsoft Browser.

    Thats what MS needs to fix.

    You misunderstand the nature of the attacks MikeST, since they aren't contained on MSN itself, they're delivered instead via the ad networks.  What this means is that the ad networks examine the information provided by the browser in use and determine which ads to display based on information related to the browser, the specific article being accessed and the browsing history of the individual and machine accessing the page.

    For the MSN attacks this generally means that the Microsoft browsers are being targeted, since these were originally delivered with MSN as either the home page or Start page, so that's a key portion of the decision whether to display the malvertising ad in the first place.  If either the bowser or the individual and their machine aren't included within the ad profile chosen by the attackers, the popups simply won't display.

    A perfect example is my own situation, which though I'm apparently the perfect target using only Microsoft browsers when I  purposefully access the exact same articles as others here who've experienced these popups, I can't reproduce them since my Advertising ID has been disabled, effectively blocking the ability of the collection of any long-term information relating to the machine or myself associated with that ID.

    On the other hand, Chrome and Firefox had apparently been more specifically targeted within this earlier campaign back in October, where the popups displayed were keyed to those browsers as well.

    Malvertising Group Spreading Kovter Malware via Fake Browser Updates

    So the determination as to which specific browsers, machines and even individuals might see these popups has more to do with the targeting chosen by the malvertisers.

    Rob

    Was this answer helpful?

    0 comments No comments