High volume of "'Phish' malware was detected on one endpoint" alerts on legitimate looking file

I'mLenny 51 Reputation points
2021-07-22T09:16:05.777+00:00

Looked online and can't see anyone else talking about this.

About 26 hours ago received the above alert, which is as generic as they come. all command line, parent processes etc. are above board. The file that is dropped is "microsoft_logo_ee5c8d9fb6248c938fd0dc19370e90bd.svg" (virustotal link below) and is dropped by lync.exe and surrounding activity makes sense for our network, but still seeing large volumes of alerts.

Anyone else experiencing this? Suspect this is maybe just a buggy definition update but issue is still actively occurring after 24 hours so wondering what best approach is? (suppression? Grin and bear it until updates?

Anyone experienced anything similar in the past?

https://www.virustotal.com/gui/file/04d29248ee3a13a074518c93a18d6efc491bf1f298f9b87fc989a6ae4b9fad7a/community

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
{count} votes

1 answer

Sort by: Most helpful
  1. VipulSparsh-MSFT 16,236 Reputation points Microsoft Employee
    2021-08-26T02:37:02.31+00:00

    @I'mLenny Apologies for delay on this.

    An internal investigation has been done and this is found to be a false positive, the latest version of AV signature update should not flag this anymore.

    Please follow the steps below to clear cached detection and obtain the latest malware definitions.

    Open command prompt as administrator and change directory to c:\Program Files\Windows Defender
    Run “MpCmdRun.exe -removedefinitions -dynamicsignatures”
    Run "MpCmdRun.exe -SignatureUpdate"

    Alternatively, the latest definition is available for download here: https://www.microsoft.com/en-us/wdsi/definitions

    ----------------------------------------------------------------------------------------------------------------------------------------------------------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments