I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Oldest
  1. Anonymous
    2018-03-07T19:13:15+00:00

    Microsoft Edge doesn’t have an option to block Java scripts, and the original Group Policy setting for Edge that allowed users to block Java scripts has now been “disappeared”.  But I think that what I saw this morning was really just a glitch with turning on uBlock Origin. It’s pretty clear that uBlock is having some UI issues – probably resulting mostly from Edge’s efforts to replicate the display of the uBlock interface – so things are pretty buggy so far. But once we enable the advanced mode for this extension; and once we’re able to open the advanced user interface, this is very impressive:

    With blocking turned off, the advanced user interface continues to monitor the connection of domains, and you can watch the list grow in real-time:

    uBlock Origin documentation:

    https://github.com/gorhill/uBlock/wiki

    One of my main concerns here was that we might not have the ability to block scripts with this extension, but it looks like this thing has got all the bases pretty well covered – and I think we’ll be able to block virtually anything once we get er tuned up. So this is definitely going to be a “keeper” for me, one way or the other.

    GreginMich

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-03-07T20:34:16+00:00

    Looks good! I wish someone had mentioned this because the whole selling point of Edge (to me, anyway) was that you weren't supposed to even be able to run JavaScript on the browser. Remember all the publicity about that back in the day?

    https://techhelpkb.com/java-and-microsoft-edge/

    Yet now, thanks to policy changes we're as vulnerable to this rubbish as ever. Perhaps more so even than with Explorer.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-03-07T21:43:48+00:00

    Ya, it was easy to get the impression that Microsoft was banning JavaScript with the development of Microsoft Edge when in fact they were just building it into the core of their new browser. The Chakra JavaScript engine was specially engineered for Edge by Microsoft, and then later open sourced as ChakraCore:

    https://github.com/microsoft/ChakraCore

    But I guess there’s really no getting around the need for a scripting engine of some sort, and the best we can do here is simply learn how to manage things when the JavaScript is being misused. With a little bit of luck, though, I think we’ll be able to manage this particular issue by just blocking the bad domain(s).

    GreginMich

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  4. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-08T18:36:07+00:00

    Looking back through this entire thread it seems to me that it's likely this recent variation of this particular detection, which was dated Feb 02, has probably found a new method of manipulating the Edge browser's JavaScript in a way that allows it to trigger such popups.

    Since from other threads I see that a typical detection is simply for the flashplayer.hta file in the browser cache, it's still questionable whether any true malware is involved.  In fact, as I recall the more typical operation of real-time detections by Microsoft had been to completely ignore the cache, since in most cases these items were blocked by the security features in the browser itself.

    So what I think we may be seeing here is the operation of a modified detection designed to head off this particular family or specific variant due to a deeper problem with whatever vulnerability within the browser it's exploiting to execute its payload.

    In other words, exactly as Microsoft has always done with their antimalware products, they're using Defender to block the operation of a new type of malware exploitation until they can build, test and deploy the actual patch to the Edge code, possibly a flaw in hta handling, that's truly causing the problem.  This is what's causing the increase in "noise" for Defender, a drastic change from it's more typically quiet operation.

    I say all of this due to the discussion of symptoms and apparent change in operation that Greg and others here have mentioned, while for others like myself there's been no change at all, since the attack vector of advertisements is something some of us have always known and blocked as a workaround.

    If I'm correct the timing of the last two variants of this detection on Feb 02, with the later addition of a PowerShell variant on Feb 14th, implies we may see an update released within the typical March Black Tuesday package that deals with this deeper issue.

    Rob

    Furthering the above speculation, here's a possible candidate that may explain why these un-characteristic detections within the cache were added, as well as why the documentation for them seems so sparse.

    Google discloses ‘high-severity’ exploit in Windows 10 before it’s patched

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2018-03-08T23:44:22+00:00

    Most likely it’s the same, or similar to, the FlashPlayer.hta that was identified and dissected here almost a year ago:

    https://www.bleepingcomputer.com/news/security/skype-malvertising-campaign-pushes-fake-flash-player/

    Defender detects this HTML app as soon as it’s offered for download; and I’ve always just closed the page at that point – so I can’t say for sure what would happen if someone actually clicked on “Run” or “Save”. But I certainly wouldn’t presume that this detection doesn’t involve any real malware, since it has all the hallmarks of a signature-based detection. And I honestly can’t recall ever having seen a real-time detection that didn’t have the browser cache as the detection path, so I don’t think that’s really anything out of the ordinary.

    This is a no-blocker day for me here; and in the hour that I spent on the MSN news pages this morning, I had two detections for Trojan:JS/Flafisi.D and one more Tech Support Scam incident. One of the Trojan:JS/Flafisi.D detections was “invisible”, with no fake Adobe Flash Player update appearing in the browser.  The invisible detection seems to have been a status update for a detection that was originally made on 3/5/2018:

    Now, a status of “106” doesn’t appear in the documentation:

    ThreatStatusID

    Data type: uint8

    Access type: Read-only

    The Threat Status ID - Enumeration

    Unknown (0)

    Detected (1)

    Cleaned (2)

    Quarantined (3)

    Removed (4)

    Allowed (5)

    Blocked (6)

    CleanFailed (Blocked)

    QuarantineFailed (102)

    RemoveFailed (103)

    AllowFailed (104)

    Abondoned (105)

    BlockedFailed (107)

    But the status is indicated as “Abandoned” in the Full History details:

    And this is all getting just a little too spooky for my liking.

    GreginMich

    Was this answer helpful?

    5 people found this answer helpful.
    0 comments No comments