I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page

Anonymous
2018-02-28T16:36:56+00:00

Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:

https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/im-seeing-trojanjsflafisid-detections-and-tech/8fbe8eaf-1af0-4e76-9ab0-57828f631a5f?page=7&messageId=3661a31c-2019-4808-a88b-283919038cc1

In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.

Invisible resource thieves: The increasing threat of cryptocurrency miners

https://cloudblogs.microsoft.com/microsoftsecure/2018/03/13/invisible-resource-thieves-the-increasing-threat-of-cryptocurrency-miners/

Especially important to report these occurrences or any other odd behaviors after using MSN website.

Moderator Edit: Provided update.

Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:

 This one was easy to handle because it was just the old-fashioned dialog loop based scam:

– but what’s coming next Microsoft?

GreginMich

[Original Title: Surprised again]

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

386 answers

Sort by: Most helpful
  1. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-09T21:25:52+00:00

    My original post above was written before I took the time to research and find the article which I later added via edit.  Since I didn't have time at that point, I simply added that article URL without correcting how this might affect the original post.

    The key information here relates to the new 'high-severity' exploit discovered by Google back in November and disclosed in late February once the 90-day and 14-day grace periods had passed.  Here's another article that provides a better synopsis and doesn't confuse the situation by including an unrelated set of exploits discovered and patched in February 2017.

    Windows 10 security Google exposes how malicious sites can exploit Microsoft Edge

    This is exactly the type of potential Edge vulnerability I'd guessed might exist based on what we've learned in this thread, while the common attack vector of the ad networks (e.g. Malvertising) is relatively unimportant, except as the possible workaround it might provide for those with the knowledge and initiative to proactively protect themselves in the future.  The utter futility of attempting to manage this avenue of attack itself is well known in the security community and has only minimal relation to the website being visited when such attacks occur, since the ads are often operated in a "pass-through" manner.

    What's more important to note here, is that if as I've guessed the Trojan:JS/Flafisi.D and it's family of detections are indeed related to this 'ACG bypass using UnmapViewOfFile' vulnerability in Microsoft Edge, then the core issue will likely be resolved once Microsoft releases their update, tentatively planned for this coming Black Tuesday March 13th.

    Since the dates the various Trojan:JS/Flafisi family detections were originally released began in early December 2017 and continue into mid-February, this seems a reasonable guess.

    So though as anyone who's ever installed an ad-blocker (or simply enabled the Tracking Protection and added an appropriate tracking list in Internet Explorer 11) already knows, their own encounters with malvertising attacks are minimal, for most this current burst of detections is likely to dissipate over the next few weeks.

    Like any such newly identified zero-day vulnerability, the incidence of attacks has merely spiked ahead of the release of the update and will of course be added into the malware 'kits' in the future, as another potentially unpatched vulnerability.  Nothing really new here except the vulnerability itself.

    Rob

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-03-07T20:34:16+00:00

    Looks good! I wish someone had mentioned this because the whole selling point of Edge (to me, anyway) was that you weren't supposed to even be able to run JavaScript on the browser. Remember all the publicity about that back in the day?

    https://techhelpkb.com/java-and-microsoft-edge/

    Yet now, thanks to policy changes we're as vulnerable to this rubbish as ever. Perhaps more so even than with Explorer.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-03-04T15:49:46+00:00

    Thanks guys, but the issues with these unannounced real-time site-development episodes (?) are putting everything on hold for me. I only have access to this site on one of the three machines that I normally use on a day-to-day basis, and I’m not sure that I’ll be able to hold on to that for long. So now I’m going to have to be monitoring the ability of the more seriously affected machines to recover from this chaos and try to figure out why it would be machine specific, and I won’t have the time to work specifically for a resolution of this malware-site redirect issue. Of course there's a possibility that these two issues might be intertwined, so I'll eventually be looking at this. 

    [Edit for Update 2:44 PM 3/4/2018]

    Nothing loads in the main page or profile now, but through some quirk of fate, when I search for “GreginMich” this thread is one of the 10 entries that show up in the search result. So thank you website gurus for providing me with this wormhole that allows me to reply to exactly one of the threads in your forum. This is another great confidence booster for me.

    [end Edit]

    [Edit 6:15 3/4/2018]

    I was just reading the story about Trump’s turnabout on talks with North Korea when this appeared:

    This was a slightly more sophisticated Tech Support Scam page, but it could still be broken with the Dialog Loop Protection checkbox.

    [end Edit]

    GreginMich

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-04T10:12:14+00:00

    bhringer has a good point Greg, while testing I tried to recall and reverse everything I had done that might protect me from such a drive-by attack, but had completely forgotten my own use of OpenDNS.

    Think of this service as a more dynamic extension of the manually managed IP blocklists that were popular at the time of Windows XP, instead embedded within the operation of the OpenDNS servers themselves.

    Though I use their free service for the entirely different purpose of DNS stability vs. the that of the notoriously flaky cable networks, I'm effectively protected by whatever site based anti-malware protection these servers might also provide.  This may help explain why I have been unable to reproduce these attacks and very possibly others, since my own Win10 PC has been completely silent in these respects unless I purposefully browse manually into areas where I fully expect to see such attacks.

    Obviously this doesn't resolve any of the deeper issues you've surfaced in this thread, but it may aid in understanding why certain individuals seem to encounter such attacks more often than others, despite the belief that it's caused by specific websites or advertising networks, which I've always felt is worth exploration.

    Rob

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Rob Koch 26,075 Reputation points Volunteer Moderator
    2018-03-01T19:38:26+00:00

    OK, that's helpful, since from past experience with the MSN home page I know that all of these articles are sourced from someone else, with Microsoft nothing but a façade that provides access to these and other MSN front ends.

    Yahoo, on the other hand, provides much of the news and other articles on their own sites.

    What this implies to me is that the attacks are likely coming from another site, through the advertising or other portions of the display that might be embedded within the supposed MSN sub-pages you're viewing.  It's still possible they're simply embedded within the ads delivered directly to the MSN generated pages, but that should result in them displaying on the main start page as well.

    It's also possible that the specific ads used to deliver these are tuned to the political affiliations or tendencies of those reading such articles.  As with phishing where the misspellings and other flaws are actually filters used by the spammers to weed out the more aware who'd be less likely to take the bait, displaying these popups only to those reading specific types of articles may provide a better response rate for the scammers.

    Rob

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments