Forum Discussion

Deleted's avatar
Deleted
Jan 22, 2021

Defender needs to be udpated

Hello,

 

I did a typo of translategoogle.com that should have been translate.google.com and for some reason, this site seems to have multiple types of redirects. It one times redirects t o a site that has a unsafe website that is blocked. But there is more redirects that bypass that that have a fake Microsoft webpage in the background with tons of warning of "Micorsoft Defender" and tons of poups and talking. Ahhhh

Defender needs to be updated to be able to detect these. 

 

Thank you,

 

Shawn

 

PS: Sorry was in a rush and sorry for typos. Also sorry if this is the wrong place to put this was the best I could think of

 
 
  • braedachau's avatar
    braedachau
    Brass Contributor

    Deleted 

     

    So the problem being that you got redirected to this site.

     

    https://pshscanning.xyz/mcf/index.php

     

    And then got hit with a whole lot of garbage about being infected with at least 5 viruses.

    Did you report the site?  Although the redirect is the primary problem

     

    I believe you have just discovered a brand new phishing malware site, but I will let you know if my machine sets off a Sentinel or MDATP alert about an hour from now.

     

    I sure as hell did as this would of got my sons for sure.

     

    • HotCakeX's avatar
      HotCakeX
      MVP

      braedachau 

       

      redirection or showing fake banners isn't phishing in its core, but if they try to get you download something, and if it's malicious, Windows Defender (assuming if it's configured correctly and none of its modules turned off) will come in play and prevent the damage.

       

      Windows Defender is pretty decent

      just a demo of someone tested it against malware (totally ignore the "maximum protection", you don't need any 3rd party tool to configure it for maximum security"

      https://youtu.be/ep_25HIArXc

       

    • Deleted's avatar
      Deleted
      Thanks for all the cool links and info.
      .
      Though Norton and other security extensions did block that website since it was phishing.

      The thing is that multiple Microsoft Agents and Microsoft Edge Insiders both agree it was a phishing site and to report it.

      Well showing banners and stuff fake and asking you to call a number is kinda phishing since people may get convinced.

      Yes I do agree that Microsoft Edge defender is the best but not everything is 100 % accurate.

      Thanks,

      Shawn
      • HotCakeX's avatar
        HotCakeX
        MVP
        Yes I also agree it could be phishing, but I want us to be prepared for the "unknown", every minute someone can setup a phishing site and by the time someone reports that and it gets added to a blacklist, many victims can fall for it.
        plus, going through and checking in a blacklist database could potentially slow down the browsing if it's too large and not enough resources are dedicated to it.

Resources