ONTAP ARP detects existing .hta files on first access after feature enablement
Applies to
ONTAP 9
Issue
- ARP detects multiple .hta files located within a printer driver directory
- Files are known good Canon driver installation components
- Files existed prior to ARP enablement
- No modification timestamps or access history suggesting tampering
- ARP report shows detection triggered at the moment an administrator accessed file properties
- ARP classification flags high entropy and unsafe extension:
3/4/2026 14:50:10 csq_min=10000 csq_avg=12976 unsafe_extn=1 file_hdr=1 safe_extn=0 score=0.8381126355643528 hta /xxx/xxx/Drivers/CANON Driver/xxx/xxx/x64/Readme/Readme_en-US.hta
