What the block actually means
CFA evaluated an executable attempting to write to a protected folder and refused the operation. Microsoft can automatically trust apps by prevalence and reputation; a verified app can still require an explicit allowance when it is not automatically trusted.
The decision is about one application path accessing protected folders. It does not say Luczystrap is malware, and it does not prove every access denied exception comes from Defender.