Apr 20 2023 01:24 AM
Had 67 detections of Trojan:HTML/Phish.JS9 over 2 days from C:\Users\***\AppData\Local\Microsoft\Windows\INetCache\IE\6JGSCFQJ\authorize[1].htm. Have tried to "collect file" but am being constantly advised that it can take up to 3 days. I have used Hunting to try to find where the file originated but there is nothing in email or web traffic that links it. My instinct is that this is a false positive. How do I speed the process of collection or actually track where the file originated?
Apr 20 2023 05:31 PM
I am seeing the same thing over the last couple of days. We got a copy of the file authorize.htm and looks just like a regular O365 logon. Seems that MS might be flagging their own login pages as phishing. Raised a support ticket to get confirmation that it's a false positive.
Apr 21 2023 08:26 AM
Apr 23 2023 07:08 PM
Apr 28 2023 04:25 AM