A non-malicious actor doesn't know, so telling them the exact URL at least tells them where the compromised asset might be.
A non-malicious actor who needs the URL isn't monitoring or responding to the incident properly. Threat actors do take advantage of this and simulate a fake cleanup. Actually they exclude certain ips and asns on phishing kits so that visiting the url gives you a 404 or a webhosts "cleanup" page.
If I put malware at xyz.com/mybadpage and MS starts flagging xyz.com, how on earth do I "maximize campaign life" by being told xyz.com/mybadpage has malware?
You can capitalise on this multiple ways. You can remove the first two and hope they remove the flag. You can design your next attack better so it is more like mybadpage3. Etc
(Not that I think MS should enumerate malicious URL's, unless $Site_Owner is paying for scanning service. A "we noticed malware at $URL" is generally 95% of the possible value of such disclosures.)
Mybadpage1.com
Mybadpage2.com
Mybadpage3.com
msscanninghoneypot1.com
msscanninghoneypot2.com
msscanninghoneypot3.com
You're pigeonholing a bad actor's actions into good actor behavior, it doesn't work like that...
edit: missed that multiple replies cover this
1. It's detected (because Microsoft told everyone)
2. What was detected and where it was (because they put it there)
Good Actors only know 1.
So by telling someone 2 they are giving bad actors no new information, and good actors valuable information.
2, MS only knows some information that shows the site is malicious, it cannot tell if it is a compromise or just a malicious site unless it perhaps looks at reputation but even then the site owner should be able to tell new or malicious files on their webserver withour MS telling them, if they can't even do that they have bigger problems and threat actors do abuse anti-abuse systems like this all the time and they do deploy multiple things on your site as well as use it to attack other sites and monitor the reputation of their infrastructure.
How does keeping secret (from the bad guys) where the malware is thwart the bad guys?
Or the bad guys themselves do that pretending to be the site owner. MS analysts can only inspect the normal site and the malicious URL that has now been removed in order to unblock it.
This is how abuse and IR works, I am surprised at the naivette of the responses here.
What happens is a website is blocked and the site operator has no idea why. The defense of "we can't share any information as to why you got punished as it might help bad actors avoid punishment" should not be an acceptable stance. It's the equivalent of being thrown to prison without due process and just ignoring false positives. It's a very "natural" way of acting, but that does not make it the right one.
You should secure your site better and have someone who knows what they are doing (there are paid WAF and web security vendors) monitor and respond to security incidents. You are not being punished, MS is protecting its customers. You should blame the hacker not MS for the impact of the hack. It's like someone messed with your car tank and tires and the police stop you from driving it because it is unsafe to other drivers, they are not punishing you but protecting other people from being hurt by your property.
The police says why they stopped you though! Which implies what you have to change in order to be able to drive again. They will not say "you have to figure it out on your own or the guys who messed with your car would have it more easy."
This is a pretty weak position to fall back to.
MS is disparaging their business and is trying to make themselves unaccountable. And they aren't customers so they have nothing to walk away from.
With that said, there is an epidemic of muppet thinking right now. It's not just the intertubes. Suppose a credit card company pulls your credit report because they say you applied for credit with them. No funds are stolen. You demand they show proof. They say nope, because TTPs. So: how do I know it's a one-off, and not data theft by fraud at scale? Off goes a letter to the FTC...
Do you think like a muppet? Here is satirical example (http://athena.m3047.net/temporizing.html):
TEMPORIZING FOUND NOT TO BE A FORM OF LYING
"Temporizing", which is speculating from what we know now as to the
motives of actors in the past and presenting that as historical fact,
has been found not to be a form of lying. "Social proof demonstrates
that temporizing is not lying" said a social commentator.
The news was greeted optimistically as a good day for humanists and
levels the playing field because "now the standards of proof we need
to meet for the existence of society are the same as for religion".
"People must have known about this in the past because it seems
like they should have" said a man in the street. "Everybody who
believes in science trusts society" said another.Imagine if I just suddenly started spreading around rumors of your malfeasance and shadyness, and untrustworthyness.
It's a big deal.
Leave it to HN to get me to defend even MS lol.
Alex Pinto's classic research into the (lack of) overlap among threat indicator feeds should be a shot across the bow; I worked with threat indicators for a decade. To fend off muppet thinking I would like to remind everybody that they're selling threat indicator feeds; nobody that I know of sells not-a-threat feeds. A false positive means a site was falsely reported as a threat [sp]; a false negative does not mean that it is good, it simply means it is omitted from the list of threats.
In my experience vendors are a lot more worred about false positives than dropping something which is a threat on the floor (false negatives in context). However, moral hazard pushes them to publish things which turn out to be false positives anyway, because at the end of the day they're selling FUD.
My network, my rules. Something doesn't have to be a threat for it to be blocked from a private network in my opinion; there are lots of reasons for that, including minimizing potential threats. Something could be hosted on stinky infrastructure, but it's unknown or hasn't been demonstrated to be a threat. Profiles for operational security vary, and so does the appetite for proactively blocking (and whitelisting necessary resources): just because it's legal doesn't mean it doesn't put me at a competitive disadvantage if people know what I'm doing. I have no problem with people sharing and discussing such indicators, but there has to be attribution to the sharer: they have a reputation to be considered with equal concern as that of the indicators they publish.
If you're going to do something public with such information, you can't point fingers at "AI" and indicators you found in a paper bag on the bus: you do that, then you own it. Saying the victim deserves it is something you'd better be prepared to defend in court.
Example: Viral video shows police pulling unarmed (and allegedly innocent) suspect out of a parked car that sparks outrage. It's later found out that the victim was previously evading police pursuit just minutes before, and was trying to blend in with the other cars in a lot.