I am attempting to troubleshoot an issue with users receiving Microsoft Defender phishing hoax popups on user endpoints. The issue seems to happen when users are doing normal web browsing.
I’ve found the source of the popups seems to be domains such as “cashnetimageprodp.z13.web.core.windows.net” that have a CNAME record such as “web.blz21prdstr19a.store.core.windows.net”. These domains suggest Azure File or blob storage.
Is this a cached DNS issue? DNS poisoning? An error with DNS config over VPN? An Azure blob storage config issue? Does anyone have insight into how this is happening? Are they are changes in Azure I can make to prevent these popups?
shmoopies_world is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.