{"id":15575,"date":"2020-09-06T07:43:33","date_gmt":"2020-09-06T05:43:33","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=15575"},"modified":"2021-04-12T11:07:32","modified_gmt":"2021-04-12T09:07:32","slug":"sicherheitsbedenken-wegen-microsoft-defender-download-feature","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2020\/09\/06\/sicherheitsbedenken-wegen-microsoft-defender-download-feature\/","title":{"rendered":"Security concerns about Microsoft Defender download feature"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" height=\"47\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2020\/09\/06\/sicherheitsbedenken-wegen-microsoft-defender-download-feature\/\" target=\"_blank\" rel=\"noopener noreferrer\">English<\/a>]Microsoft has added a way to download arbitrary files in Defender. However, this download feature causes more headaches than enthusiasm among security experts.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg08.met.vgwort.de\/na\/48d0cd460bd843caa05580bf4cb513a0\" alt=\"\" width=\"1\" height=\"1\" \/>I had read the reference to the new feature these days at deskmodder.de in the article <a href=\"https:\/\/www.deskmodder.de\/blog\/2020\/09\/03\/windows-defender-mpcmdrun-exe-als-download-manager-nutzen-kein-problem\/\" target=\"_blank\" rel=\"noopener noreferrer\">Windows Defender (MpCmdRun.exe) als Download-Manager nutzen? Kein Problem<\/a>. With the Defender update to version 4.18.2007.8-0 (source <a href=\"https:\/\/twitter.com\/wdormann\/status\/1301514271080296448\" target=\"_blank\" rel=\"noopener noreferrer\">Will Dormann<\/a>) there is a new feature in the MpCmdRun.exe. Hacker <a href=\"https:\/\/twitter.com\/mohammadaskar2\" target=\"_blank\" rel=\"noopener noreferrer\">mohammadaskar2<\/a> found <a href=\"https:\/\/twitter.com\/mohammadaskar2\/status\/1301263551638761477\" target=\"_blank\" rel=\"noopener noreferrer\">it by accident<\/a> and calls it the <em>Microsoft Malware Protection Command Line<\/em>. You can use the command:<\/p>\n<p>C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2008.9-0\\MpCmdRun.exe \u00a0-DownloadFile -url &lt;url&gt; -path &lt;local-path&gt;<\/p>\n<p>as an administrator, to download any file with Windows Defender. Microsoft described this in <a href=\"https:\/\/web.archive.org\/web\/20210215024924\/https:\/\/docs.microsoft.com\/en-us\/windows\/security\/threat-protection\/microsoft-defender-antivirus\/command-line-arguments-microsoft-defender-antivirus\" target=\"_blank\" rel=\"noopener noreferrer\">this support article<\/a> published in mid-August 2020. Colleague Lawrence Abrams <a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-defender-can-ironically-be-used-to-download-malware\/\" target=\"_blank\" rel=\"noopener noreferrer\">points out on Bleeping Computer<\/a> that this is a a nice feature for malware writers, they have a new case where legitimate operating system files can be misused for malicious purposes.<\/p>\n<p>The whole thing is called living-off-the-land binaries or LOLBINs. Abrams writes that the feature was introduced with the update to version 4.18.2007.9 or 4.18.2009.9. BleepingComputer was able to download the resources.exe file, the WastedLocker Ransomware example used in a recent Garmin attack.<\/p>\n<p>Let's hope that Microsoft Defender will detect all malicious files downloaded with MpCmdRun.exe. The problem that other antivirus software disables Defender and is blind to this attack should be slowly defused. This is because Microsoft tries to protect Defender to be disabled in Windows (see <a href=\"https:\/\/borncity.com\/win\/2020\/08\/22\/microsoft-defender-unter-windows-nicht-mehr-abschaltbar\/\">Microsoft Defender can no longer be disabled under Windows 10<\/a>). The case shows once again that such nice features can have their archilles heel.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[English]Microsoft has added a way to download arbitrary files in Defender. However, this download feature causes more headaches than enthusiasm among security experts.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,1547],"tags":[773],"class_list":["post-15575","post","type-post","status-publish","format-standard","hentry","category-security","category-software","tag-defender"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/15575","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=15575"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/15575\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=15575"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=15575"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=15575"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}