DownloadFile option has been removed from current MpCmdRun.exe, but old binary remains on disk. Defender cmd line mitigation can be bypassed by simply renaming the binary in a folder controlled by the attacker
Thanks!
Added note that slashes (/) can also be used as command separators, and that the UA is MpCommunication Thanks!