<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AutoHotkeyU.exe disposition is now malicious in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/autohotkeyu-exe-disposition-is-now-malicious/m-p/5031803#M8211</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/35562"&gt;@Matthew Franks&lt;/a&gt;&amp;nbsp;&amp;nbsp;here are the details:&lt;/P&gt;
&lt;P&gt;There appears to be at least 3 versions of AutoHotkey.exe in our environment that are triggering threat detection and retrospective quarantine failure events:&lt;/P&gt;
&lt;P&gt;C:\Program Files\AutoHotkey\AutoHotkeyU32.exe / disposition = malicious&lt;BR /&gt;SHA256: 9ab9738634810cf54edca5a9937f2eb1ff64f8a221558ca57ef23832b413f5a2&lt;BR /&gt;993fcb15d8eb9197f71826d7b60ba86ad407c2c3d31801be2a7e4bac8e1abac3&lt;/P&gt;
&lt;P&gt;AutoHotkey.exe / disposition = malicious&lt;BR /&gt;945adada6cf6698b949359d9b395a5f905989d0d1eb84f537de492ecc1263148&lt;/P&gt;</description>
    <pubDate>Fri, 01 Mar 2024 14:41:30 GMT</pubDate>
    <dc:creator>mski7861</dc:creator>
    <dc:date>2024-03-01T14:41:30Z</dc:date>
    <item>
      <title>AutoHotkeyU.exe disposition is now malicious</title>
      <link>https://community.cisco.com/t5/endpoint-security/autohotkeyu-exe-disposition-is-now-malicious/m-p/5030318#M8207</link>
      <description>&lt;P&gt;Anyone else using&amp;nbsp;AutoHotkeyU.exe in their environment and experiencing multiple retrospective quarantine events because the file disposition is now malicious?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I understand what it does, but I'm curious why the disposition recently changed&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 21:16:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/autohotkeyu-exe-disposition-is-now-malicious/m-p/5030318#M8207</guid>
      <dc:creator>mski7861</dc:creator>
      <dc:date>2024-02-29T21:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: AutoHotkeyU.exe disposition is now malicious</title>
      <link>https://community.cisco.com/t5/endpoint-security/autohotkeyu-exe-disposition-is-now-malicious/m-p/5031688#M8209</link>
      <description>&lt;P&gt;Could you post the SHA256 hash of the file please? Then we can look into why it was marked malicious.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 13:08:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/autohotkeyu-exe-disposition-is-now-malicious/m-p/5031688#M8209</guid>
      <dc:creator>Matthew Franks</dc:creator>
      <dc:date>2024-03-01T13:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: AutoHotkeyU.exe disposition is now malicious</title>
      <link>https://community.cisco.com/t5/endpoint-security/autohotkeyu-exe-disposition-is-now-malicious/m-p/5031697#M8210</link>
      <description>&lt;P&gt;If you trust the sha and its affecting your business critical applications then I suggest whitelisting the SHA until Cisco comes back with an explanation.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 13:17:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/autohotkeyu-exe-disposition-is-now-malicious/m-p/5031697#M8210</guid>
      <dc:creator>Pulkit Mittal</dc:creator>
      <dc:date>2024-03-01T13:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: AutoHotkeyU.exe disposition is now malicious</title>
      <link>https://community.cisco.com/t5/endpoint-security/autohotkeyu-exe-disposition-is-now-malicious/m-p/5031803#M8211</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/35562"&gt;@Matthew Franks&lt;/a&gt;&amp;nbsp;&amp;nbsp;here are the details:&lt;/P&gt;
&lt;P&gt;There appears to be at least 3 versions of AutoHotkey.exe in our environment that are triggering threat detection and retrospective quarantine failure events:&lt;/P&gt;
&lt;P&gt;C:\Program Files\AutoHotkey\AutoHotkeyU32.exe / disposition = malicious&lt;BR /&gt;SHA256: 9ab9738634810cf54edca5a9937f2eb1ff64f8a221558ca57ef23832b413f5a2&lt;BR /&gt;993fcb15d8eb9197f71826d7b60ba86ad407c2c3d31801be2a7e4bac8e1abac3&lt;/P&gt;
&lt;P&gt;AutoHotkey.exe / disposition = malicious&lt;BR /&gt;945adada6cf6698b949359d9b395a5f905989d0d1eb84f537de492ecc1263148&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 14:41:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/autohotkeyu-exe-disposition-is-now-malicious/m-p/5031803#M8211</guid>
      <dc:creator>mski7861</dc:creator>
      <dc:date>2024-03-01T14:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: AutoHotkeyU.exe disposition is now malicious</title>
      <link>https://community.cisco.com/t5/endpoint-security/autohotkeyu-exe-disposition-is-now-malicious/m-p/5031809#M8212</link>
      <description>&lt;DIV&gt;A little more background:&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;There are a number of users in our organization that have been using AutoHotKey for quite some time, primarily to automate repetitive tasks.&amp;nbsp; Working with a few end users yesterday, I noticed most were running the older version 1.1.37.01.&amp;nbsp; We uninstalled and installed 2.0.11.&amp;nbsp; There were also a couple users that generated events and were already running version 2.0.11.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;So this morning I downloaded and installed both versions in my sandbox and the hash files are different as seen below:&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;- I downloaded AutoHotKey_1.1.37.01_setup.exe (SHA256: dbf3490648efe876bd9a98d53e4d9110bf5e02a3914c0dd4b2a48db4a09799b5)&lt;/DIV&gt;
&lt;DIV&gt;- Installed and verified the following files:&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;- AutoHotkey.exe SHA256: 7d47220e8a09c113b82ba9f366ce2cbe5924b0cc661dc9df93c13e8dbfa1f254 - Talos currently evaluating disposition&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;- AutoHotkeyU32.exe SHA256: 897b0d0e64cf87ac7086241c86f757f3c94d6826f949a1f0fec9c40892c0cecb - Talos currently evaluating disposition&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;- I also downloaded AutoHotkey_2.0.11_setup.exe (SHA256: 2a3e882103232c1355e2a6a8f1d9bc7cc23134cd)&lt;/DIV&gt;
&lt;DIV&gt;- Installed and verified the following files:&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;- AutoHotkey.exe SHA256: f325aa17f9d8b3580b6a89ef8ee18dcf95961a3d28e0d79b7478f9800eba237c - Talos currently evaluating disposition&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;- AutoHotkey32.exe SHA256: bfde2b58f0a083d9d10e31cd95164d2812575b897e2eb04c6528f30fb2eabdf0 - Talos currently evaluating disposition&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 01 Mar 2024 14:47:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/autohotkeyu-exe-disposition-is-now-malicious/m-p/5031809#M8212</guid>
      <dc:creator>mski7861</dc:creator>
      <dc:date>2024-03-01T14:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: AutoHotkeyU.exe disposition is now malicious</title>
      <link>https://community.cisco.com/t5/endpoint-security/autohotkeyu-exe-disposition-is-now-malicious/m-p/5031812#M8213</link>
      <description>If you know it's a ln FP,  I would add it to the whitelist temporarily and then submit file reputation disputes on talosintelligence.com.&lt;BR /&gt;&lt;BR /&gt;Once Talos clears it, I pull it from the whitelist.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 01 Mar 2024 14:59:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/autohotkeyu-exe-disposition-is-now-malicious/m-p/5031812#M8213</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2024-03-01T14:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: AutoHotkeyU.exe disposition is now malicious</title>
      <link>https://community.cisco.com/t5/endpoint-security/autohotkeyu-exe-disposition-is-now-malicious/m-p/5031819#M8214</link>
      <description>&lt;P&gt;Good advice from Ken as always. I submitted the first 3 hashes as FPs because I don't see anything in the report that jumps out to me as overtly malicious. Could you please submit that latest batch if you haven't already and they're showing as malicious?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 15:01:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/autohotkeyu-exe-disposition-is-now-malicious/m-p/5031819#M8214</guid>
      <dc:creator>Matthew Franks</dc:creator>
      <dc:date>2024-03-01T15:01:54Z</dc:date>
    </item>
  </channel>
</rss>

