AutoIT loader script (kojuyn.ini) executed by dropped AutoIT interpreter

This rule detects the execution of a malicious AutoIT loader script (identified by the filename 'kojuyn.ini' and a specific SHA-256 hash). The loader is designed to deobfuscate runtime API names and payload paths from XOR-encoded strings, bypassing static analysis. The detection links the presence of this script with the execution of a corresponding AutoIT interpreter binary.