It’s a detection for Trojan:JS/Flafisi.D. If it were the Ramnit Trojan, it would most likely be detected as a Trojan:Win32/Ramnit variant.
https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Win32/Ramnit
The current Ramnit Trojan attack has a totally different look and feel, and it attempts to download flashplayer_33.9.22.js.
But the point here is that a compromised advertising domain could potentially deliver any kind of threat, as the latest analysis of the FlashPlayer.hta file emphasizes:
Conclusion
The combination of large malvertising campaigns on very high-ranking websites with sophisticated social engineering schemes that convince users to infect themselves means that potential exposure to malware is quite high, reaching millions of web surfers. Once again, we see actors exploiting the human factor even as they adapt tools and approaches to a landscape in which traditional exploit kit attacks are less effective. While the payload in this case is ad fraud malware, it could just as easily have been ransomware, an information stealer, or any other malware. Regardless, threat actors are following the money and looking to more effective combinations of social engineering, targeting, and pre-filtering to infect new victims at scale.
So the payload is really irrelevant, and the point (once again) is that there’s an open malware channel on the MSN news pages.
Some previous incidents of malvertising on the MSN news pages were identified by Malwarebytes:
Here’s an old news article that puts the issue in some historical perspective, and implicitly explains why this issue is still with us today.
https://www.tomsguide.com/us/malvertising-what-it-is,news-19877.html
The article wanted to point the finger of blame squarely at the ad networks with the implication that they would be able to manage the issue themselves with internal guidelines. And of course as soon as you absolve site administrators of the responsibility of monitoring the supply chain, and keeping malvertising off of their websites, you’ve really just managed to set the malvertising wheel in perpetual motion. Self-regulation quite obviously isn’t working here, and attempting to shift the blame to the ad networks has really just prolonged our misery. What a site serves up to the public is the responsibility of the site’s owners and administrators, and the content needs to be managed locally.
This could presumably be done with a minimal investment by using automated monitoring, tracking, cutoff, and replacement of the compromised advertising domains that are delivering these threats to the host site. And the cost of internal management of advertising domains would most likely pale in comparison to what a high-profile site is going to lose in terms of advertising revenues (and reputation) if we have to manage this issue ourselves with ad-blockers. So let’s apply some of that great new “next-gen” technology to maintaining safe Microsoft sites.
GreginMich