{"id":1767,"date":"2021-12-01T10:24:34","date_gmt":"2021-12-01T02:24:34","guid":{"rendered":"https:\/\/tongwing.woon.sg\/blog\/?p=1767"},"modified":"2021-12-01T10:24:34","modified_gmt":"2021-12-01T02:24:34","slug":"microsoft-defender-scares-admins-with-emotet-false-positives","status":"publish","type":"post","link":"https:\/\/tongwing.woon.sg\/blog\/microsoft-defender-scares-admins-with-emotet-false-positives\/","title":{"rendered":"Microsoft Defender scares admins with Emotet false positives"},"content":{"rendered":"<p>Got hit by this today. Was trying to open a Word doc from a colleague when I receive the following scary warning.<br \/>\n<img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-1768\" src=\"https:\/\/tongwing.woon.sg\/blog\/wp-content\/uploads\/2021\/12\/1-2.png\" alt=\"\" width=\"783\" height=\"731\" \/><\/p>\n<p>Submitting the same file to VirusTotal returns 0 threats detected. Hmmm.<br \/>\n<img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-large wp-image-1775\" src=\"https:\/\/tongwing.woon.sg\/blog\/wp-content\/uploads\/2021\/12\/2-1024x768.png\" alt=\"\" width=\"580\" height=\"435\" srcset=\"https:\/\/tongwing.woon.sg\/blog\/wp-content\/uploads\/2021\/12\/2-1024x768.png 1024w, https:\/\/tongwing.woon.sg\/blog\/wp-content\/uploads\/2021\/12\/2-300x225.png 300w, https:\/\/tongwing.woon.sg\/blog\/wp-content\/uploads\/2021\/12\/2-768x576.png 768w, https:\/\/tongwing.woon.sg\/blog\/wp-content\/uploads\/2021\/12\/2-1536x1152.png 1536w, https:\/\/tongwing.woon.sg\/blog\/wp-content\/uploads\/2021\/12\/2-2048x1536.png 2048w, https:\/\/tongwing.woon.sg\/blog\/wp-content\/uploads\/2021\/12\/2-1200x900.png 1200w, https:\/\/tongwing.woon.sg\/blog\/wp-content\/uploads\/2021\/12\/2-1980x1485.png 1980w\" sizes=\"(max-width: 580px) 100vw, 580px\" \/><\/p>\n<p>Searching for the keyword Win32\/PowEmotet.SB returns the following:<\/p>\n<blockquote><p>Microsoft Defender for Endpoint is currently blocking Office documents from being opened and some executables from launching due to a false positive tagging the files as potentially bundling an Emotet malware payload.<\/p><\/blockquote>\n<p>Source: <em><a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-defender-scares-admins-with-emotet-false-positives\/\">Microsoft Defender scares admins with Emotet false positives<\/a><\/em><\/p>\n<p>If you are hit by the same issue, just update your threat definition and it should go away:<br \/>\n<img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-large wp-image-1770\" src=\"https:\/\/tongwing.woon.sg\/blog\/wp-content\/uploads\/2021\/12\/3-1024x809-1.png\" alt=\"\" width=\"580\" height=\"458\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Got hit by this today. Was trying to open a Word doc from a colleague when I receive the following scary warning. Submitting the same file to VirusTotal returns 0 threats detected. Hmmm. Searching for the keyword Win32\/PowEmotet.SB returns the following: Microsoft Defender for Endpoint is currently blocking Office documents from being opened and some [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"_links":{"self":[{"href":"https:\/\/tongwing.woon.sg\/blog\/wp-json\/wp\/v2\/posts\/1767"}],"collection":[{"href":"https:\/\/tongwing.woon.sg\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tongwing.woon.sg\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tongwing.woon.sg\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/tongwing.woon.sg\/blog\/wp-json\/wp\/v2\/comments?post=1767"}],"version-history":[{"count":2,"href":"https:\/\/tongwing.woon.sg\/blog\/wp-json\/wp\/v2\/posts\/1767\/revisions"}],"predecessor-version":[{"id":1776,"href":"https:\/\/tongwing.woon.sg\/blog\/wp-json\/wp\/v2\/posts\/1767\/revisions\/1776"}],"wp:attachment":[{"href":"https:\/\/tongwing.woon.sg\/blog\/wp-json\/wp\/v2\/media?parent=1767"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tongwing.woon.sg\/blog\/wp-json\/wp\/v2\/categories?post=1767"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tongwing.woon.sg\/blog\/wp-json\/wp\/v2\/tags?post=1767"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}