<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Base64JS.min.js in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935654#M7880</link>
    <description>&lt;P&gt;Absolutely agree.&lt;/P&gt;</description>
    <pubDate>Fri, 06 Oct 2023 18:44:36 GMT</pubDate>
    <dc:creator>noahigros</dc:creator>
    <dc:date>2023-10-06T18:44:36Z</dc:date>
    <item>
      <title>Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935027#M7860</link>
      <description>&lt;P&gt;Good afternoon,&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are using Cisco AMP with our connector version being 8.2.1.21612 and are receiving numerous alerts for a filename Base64JS.min.js. Is anybody else experiencing this? Previously we had a widespread issue with a smss.exe parent process that was found to be an issue with a new BP update on Cisco's end for the same connector version we are on now. Could this be related?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 19:49:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935027#M7860</guid>
      <dc:creator>noahigros</dc:creator>
      <dc:date>2023-10-05T19:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935034#M7861</link>
      <description>Yep... started for me about 20 min ago.&lt;BR /&gt;I've opened a Talos file reputation case, but they closed it because the sha already existed in a ticket. (e.g. someone else already submitted it)&lt;BR /&gt;</description>
      <pubDate>Thu, 05 Oct 2023 19:55:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935034#M7861</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2023-10-05T19:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935036#M7862</link>
      <description>&lt;P&gt;I have 28 isolation events centered around this&amp;nbsp;&lt;SPAN&gt;Base64JS.min.js detection. Can we get word if this is a false positive as we are running scans at the moment this stinks like a false positive.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 19:56:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935036#M7862</guid>
      <dc:creator>chrisguerrero</dc:creator>
      <dc:date>2023-10-05T19:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935046#M7863</link>
      <description>&lt;P&gt;thank you both for the input.&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/321979"&gt;@Ken Stieers&lt;/a&gt;&amp;nbsp;, if you find any further information, please let me know.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 20:03:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935046#M7863</guid>
      <dc:creator>noahigros</dc:creator>
      <dc:date>2023-10-05T20:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935051#M7864</link>
      <description>&lt;P&gt;I am currently seeing the same issue in my console.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 20:12:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935051#M7864</guid>
      <dc:creator>Bbailey2</dc:creator>
      <dc:date>2023-10-05T20:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935055#M7865</link>
      <description>&lt;P&gt;I'm seeing retrospective detection and retrospective quarantine attempt failed for&amp;nbsp;d2e82495607abf54f16e21de04d90ba9ce1605451667d88425babece988f148b&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;C:\&lt;/SPAN&gt;&lt;SPAN&gt;adobeTemp\&lt;/SPAN&gt;&lt;SPAN&gt;ETRDE65.&lt;/SPAN&gt;&lt;SPAN&gt;tmp\&lt;/SPAN&gt;&lt;SPAN&gt;2\&lt;/SPAN&gt;&lt;SPAN&gt;x64\&lt;/SPAN&gt;&lt;SPAN&gt;js\&lt;/SPAN&gt;&lt;SPAN&gt;node_&lt;/SPAN&gt;&lt;SPAN&gt;modules\&lt;/SPAN&gt;&lt;SPAN&gt;base64-&lt;/SPAN&gt;&lt;SPAN&gt;js\&lt;/SPAN&gt;&lt;SPAN&gt;base64js.&lt;/SPAN&gt;&lt;SPAN&gt;min.&lt;/SPAN&gt;&lt;SPAN&gt;js&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 20:23:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935055#M7865</guid>
      <dc:creator>Bbailey2</dc:creator>
      <dc:date>2023-10-05T20:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935064#M7866</link>
      <description>&lt;P&gt;I'm seeing retrospective detection and retrospective quarantine attempt failed on 100+ machines for&amp;nbsp;d2e82495607abf54f16e21de04d90ba9ce1605451667d88425babece988f148b&lt;/P&gt;&lt;P&gt;/c:/adobetemp/etr37a4.tmp/2/x64/js/node_modules/base64-js/base64js.min.js&lt;/P&gt;&lt;P&gt;Two weeks ago we also experienced the sms.exe parent process issue at our organization.&lt;/P&gt;&lt;P&gt;Connector version&amp;nbsp;&lt;SPAN&gt;8.2.1.21612&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 20:41:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935064#M7866</guid>
      <dc:creator>_hAcKeR_kIllEr_</dc:creator>
      <dc:date>2023-10-05T20:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935082#M7867</link>
      <description>&lt;P&gt;For the retrospective quarantine attempt failure, that's a confusing feature. SEP will quarantine the initial event, but until the event is marked as resolved, it will continuously monitor it as still being present and search for the signature that no longer exists due to it already being handled. Thus resulting in a quarantine failure. You could always verify by going into the device trajectory and look for persistence on the same host, but in my experience it's never the case and very time consuming considering the number of alerts.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 20:57:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935082#M7867</guid>
      <dc:creator>noahigros</dc:creator>
      <dc:date>2023-10-05T20:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935093#M7868</link>
      <description>Yep.  That's the one I am seeing too.&lt;BR /&gt;</description>
      <pubDate>Thu, 05 Oct 2023 21:04:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935093#M7868</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2023-10-05T21:04:32Z</dc:date>
    </item>
    <item>
      <title>Re: Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935102#M7869</link>
      <description>&lt;P&gt;Did they update you as to the status? it's been a few hours now since this started.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 21:38:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935102#M7869</guid>
      <dc:creator>chad.preslar</dc:creator>
      <dc:date>2023-10-05T21:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935149#M7870</link>
      <description>&lt;P&gt;We're seeing this as well. Did you get any additional info from Cisco or Talos?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 01:19:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935149#M7870</guid>
      <dc:creator>The Security Guy</dc:creator>
      <dc:date>2023-10-06T01:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935256#M7871</link>
      <description>&lt;P&gt;Hello, same problem here with base64js.min.js. Any news on your side?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 07:36:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935256#M7871</guid>
      <dc:creator>xdumont</dc:creator>
      <dc:date>2023-10-06T07:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935294#M7872</link>
      <description>&lt;P&gt;The execution parent in my environment is setup.exe from Adobe. The Adobe setup.exe file is clean. This is most likely a false-positive. Lighting up my environment with this.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 09:15:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935294#M7872</guid>
      <dc:creator>ventaran</dc:creator>
      <dc:date>2023-10-06T09:15:10Z</dc:date>
    </item>
    <item>
      <title>Re: Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935305#M7873</link>
      <description>&lt;P&gt;On our side it's the latest release of XMind for Windows&amp;nbsp;&lt;A href="https://xmind.app/download/" target="_blank"&gt;https://xmind.app/download/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 09:44:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935305#M7873</guid>
      <dc:creator>xdumont</dc:creator>
      <dc:date>2023-10-06T09:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935363#M7874</link>
      <description>&lt;P class=""&gt;&lt;SPAN&gt;Hello Anthony,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Thank you for contacting us, I am Sara from ATS TAC, and I will be working with you on that case. From what I understand you would like to report&amp;nbsp;&lt;STRONG&gt;a False Positive detection for base64js.min.js (d2e82495607abf54f16e21de04d90ba9ce1605451667d88425babece988f148b)&lt;/STRONG&gt;, correct me if wrong.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Please note that we are aware of this False Positive detection and this was already taken care of.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;I&gt;&lt;SPAN&gt;Talos has analyzed the file and deemed it benign. We have rectified the issue by changing the file disposition in Cisco Secure Endpoint, which effectively allows the customer to access the file. This update should be reflected on the customer’s appliance in the next 1-2 hours. The source of the conviction has been notified so that they can use this example to improve detection content, which will help prevent future false positives. Thank you for bringing this to our attention and let us know if you need further assistance.&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Should you receive any recent detections, please proceed with updating your Connectors on the affected Endpoints. We apologize for any inconvenience this can cause.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P class=""&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 06 Oct 2023 10:03:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935363#M7874</guid>
      <dc:creator>ventaran</dc:creator>
      <dc:date>2023-10-06T10:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935493#M7875</link>
      <description>&lt;P&gt;The statement above is correct I just checked the internal ticket with TALOS and it was confirmed last night around 7pm EST that this is indeed FP event and will be removed from the detection list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 13:44:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935493#M7875</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2023-10-06T13:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935510#M7876</link>
      <description>&lt;P&gt;I entered that hash into Talos and it still shows as UNKNOWN.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 14:25:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935510#M7876</guid>
      <dc:creator>dotran</dc:creator>
      <dc:date>2023-10-06T14:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935625#M7877</link>
      <description>&lt;P&gt;Final thoughts,&lt;/P&gt;&lt;P&gt;although we now have an accepted solution, for future reference you can also create an exclusion for events like this and apply it to your group policies. I personally don't tend to do that, as there is always the possibility of these events to be true and I wouldn't want to miss them. I've only done exclusions for very specific needs of an agency, but not an overarching file or action that's common across the board.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 17:32:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935625#M7877</guid>
      <dc:creator>noahigros</dc:creator>
      <dc:date>2023-10-06T17:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935627#M7878</link>
      <description>&lt;P&gt;That's what we did but prefer Cisco makes a public announcement and provide the updated signature files so the paying customers do not have to do any guess work.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 17:39:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935627#M7878</guid>
      <dc:creator>dotran</dc:creator>
      <dc:date>2023-10-06T17:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: Base64JS.min.js</title>
      <link>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935635#M7879</link>
      <description>&lt;P&gt;I do 100% agree with this statement.&amp;nbsp; Secure Endpoint is definitely not "one click" solution there is many engines and factors that they play a big role in the final verdict and you guys have the power to control most of them. I also agree that FP events could be annoying and distracting but again SE is not just simple AV solution and in today world I rather be safe than sorry.&lt;BR /&gt;&lt;BR /&gt;Also remember guys any doubts you have with False Positive or False Negative event TAC is here to help you and we treat these cases individually case by case. Most of them are resolved with in 24 hours from reporting, but there are cases like those caused by Exploit Prevention engine that are way more complicated than simple detection and those can take longer. So we appreciate the patience and support.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 18:03:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/base64js-min-js/m-p/4935635#M7879</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2023-10-06T18:03:31Z</dc:date>
    </item>
  </channel>
</rss>

