<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: file getting blocked (false positive) in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539675#M1920</link>
    <description>&lt;P&gt;That is interesting.&amp;nbsp; I submitted the URL of the file to wildfire and that decided it was benign.&amp;nbsp; Do you know if that automatically reclassifies it, or is that just an assessment for information?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Apr 2023 08:32:57 GMT</pubDate>
    <dc:creator>djr</dc:creator>
    <dc:date>2023-04-21T08:32:57Z</dc:date>
    <item>
      <title>file getting blocked (false positive)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539493#M1914</link>
      <description>&lt;P&gt;Can I get assistance on this false positive.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;TABLE id="antivirus-signatures" class="table table-bordered pan-grid table-hover" data-pagination="true" data-toggle="table" data-pagination-v-align="top" data-reactid=".0.1.1:$VbSpS.1"&gt;
&lt;TBODY data-reactid=".0.1.1:$VbSpS.1.1"&gt;
&lt;TR data-index="0" data-reactid=".0.1.1:$VbSpS.1.1.0"&gt;
&lt;TD data-reactid=".0.1.1:$VbSpS.1.1.0.2"&gt;
&lt;DIV data-reactid=".0.1.1:$VbSpS.1.1.0.2.0"&gt;
&lt;P class="hash sha256" data-reactid=".0.1.1:$VbSpS.1.1.0.2.0.0"&gt;9a27f17d859d7f60a26030c7a0ef3698ffa0ff5ff4230963e52ab79a6a4dacdf&lt;/P&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;SPAN&gt;Virus/Win32.WGeneric.dyafjk&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="" data-reactid=".0.1.1:$VbSpS.1.1.0.0.1"&gt;Unique Threat ID: 575312775&lt;BR /&gt;&lt;SPAN&gt;Create Time: 2023-03-15 02:43:51 (UTC)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 07:34:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539493#M1914</guid>
      <dc:creator>Salathiwe</dc:creator>
      <dc:date>2023-04-20T07:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: file getting blocked (false positive)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539497#M1915</link>
      <description>&lt;P&gt;I have been seeing this since 17th March on downloads of utorrent installer which appear to be legitimate&lt;/P&gt;
&lt;P&gt;URL:&amp;nbsp;llsw.download3.utorrent.com/3.6.0/utorrent.46738.installer.exe&lt;/P&gt;
&lt;P&gt;I have raised this with our support partner.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 08:08:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539497#M1915</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2023-04-20T08:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: file getting blocked (false positive)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539516#M1916</link>
      <description>&lt;P&gt;Support Partner as in Palo Alto&amp;nbsp; (TAC) ?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 09:51:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539516#M1916</guid>
      <dc:creator>Salathiwe</dc:creator>
      <dc:date>2023-04-20T09:51:32Z</dc:date>
    </item>
    <item>
      <title>Re: file getting blocked (false positive)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539528#M1917</link>
      <description>&lt;P&gt;It has been raised with TAC via our support partner.&amp;nbsp; I am not getting sensible answers yet from either.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 11:32:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539528#M1917</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2023-04-20T11:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: file getting blocked (false positive)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539529#M1918</link>
      <description>&lt;P&gt;I have an answer from TAC that they are confident the file I have queried is malicious.&amp;nbsp; I still find that odd, but that's their assessment.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 11:51:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539529#M1918</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2023-04-20T11:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: file getting blocked (false positive)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539639#M1919</link>
      <description>&lt;P&gt;If you suspect that the verdict is incorrect, you can submit a verdict change request.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reference:&lt;BR /&gt;- WildFire report incorrect verdict (virus false positive or false negative)&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm7KCAS" target="_self"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm7KCAS&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 00:40:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539639#M1919</guid>
      <dc:creator>ymiyashita</dc:creator>
      <dc:date>2023-04-21T00:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: file getting blocked (false positive)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539675#M1920</link>
      <description>&lt;P&gt;That is interesting.&amp;nbsp; I submitted the URL of the file to wildfire and that decided it was benign.&amp;nbsp; Do you know if that automatically reclassifies it, or is that just an assessment for information?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 08:32:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539675#M1920</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2023-04-21T08:32:57Z</dc:date>
    </item>
    <item>
      <title>Re: file getting blocked (false positive)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539680#M1922</link>
      <description>&lt;P&gt;The WildFire verdict of the sample (9a27f17d859d7f60a26030c7a0ef3698ffa0ff5ff4230963e52ab79a6a4dacdf) is still "Malware".&lt;BR /&gt;Please go into the report itself and check the verdict and the hash value.&lt;/P&gt;
&lt;P&gt;If the hash value is different, you may want to submit the sample rather than the URL.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 01:22:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539680#M1922</guid>
      <dc:creator>ymiyashita</dc:creator>
      <dc:date>2023-04-24T01:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: file getting blocked (false positive)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539700#M1923</link>
      <description>&lt;P&gt;Thank you for pointing that out.&amp;nbsp; I find it odd that on one screen it says Benign, but if you click for details it says it is malicious.&amp;nbsp; The hash does match so it seems they do believe it's bad so blocking it is the right thing to do.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks again&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 13:11:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539700#M1923</guid>
      <dc:creator>djr</dc:creator>
      <dc:date>2023-04-21T13:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: file getting blocked (false positive)</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539840#M1924</link>
      <description>&lt;P&gt;Ok, thanks for checking the report.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By the way, please note that submitting the same sample or the URL of the same sample doesn't trigger the reclassification (especially, when it's uploaded to the same regional cloud), e.g. the WildFire just reuses the existing result.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you submit a verdict change request, then the sample will be re-analyzed by the Palo Alto Networks researcher/engineer manually.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 01:28:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/file-getting-blocked-false-positive/m-p/539840#M1924</guid>
      <dc:creator>ymiyashita</dc:creator>
      <dc:date>2023-04-24T01:28:54Z</dc:date>
    </item>
  </channel>
</rss>

