<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Virus alerts on odd files in July 2023 in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/virus-alerts-on-odd-files-in-july-2023/m-p/554457#M1986</link>
    <description>&lt;P&gt;False Positives: Sometimes, security tools can mistakenly flag legitimate files as malicious. Given the nature of the flagged files (associated with Microsoft and Adobe), this is a possibility. Infected Source: There's a chance you've downloaded the software from a non-official or compromised source. Outdated Signatures: The threat database or signatures of your security tools might be outdated, leading to incorrect flagging. I haven't personally seen these specific flags recently, but I would advise: Ensure you're downloading software and updates only from official sources. Update your security tools and their signatures. Check with the vendors (Adobe, Microsoft, Sutherland Global) for any known issues. If you're part of a larger organization or network, reach out on security forums or groups related to Palo Alto Networks for shared experiences.&lt;/P&gt;</description>
    <pubDate>Mon, 21 Aug 2023 05:54:11 GMT</pubDate>
    <dc:creator>KianMarsh</dc:creator>
    <dc:date>2023-08-21T05:54:11Z</dc:date>
    <item>
      <title>Virus alerts on odd files in July 2023</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/virus-alerts-on-odd-files-in-july-2023/m-p/551125#M1973</link>
      <description>&lt;P&gt;Our SIEM has received several virus alerts from the Palo firewall since mid July.&amp;nbsp; The AV or Wildfire has flagged Adobe and Microsoft files. And now a web site for for a digital transformation and process company smartupload.sutherlandglobal.com.&amp;nbsp; Alerts include:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Virus/Win32.WGeneric.dzuhnx(#s removed) was detected at Microsoft.VisualStudio.Web.Scaffolding.vsix&lt;/P&gt;
&lt;P&gt;Virus/Win32.pioneer.uzd(#s removed) was detected at VulcanMessage5.dll&lt;/P&gt;
&lt;P&gt;Dropper/Win32.fiy.clu(#s removed) was detected at AGMService.exe&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone else seen this odd behaviour lately?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 16:32:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/virus-alerts-on-odd-files-in-july-2023/m-p/551125#M1973</guid>
      <dc:creator>Jeromey-Lanvera</dc:creator>
      <dc:date>2023-07-26T16:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: Virus alerts on odd files in July 2023</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/virus-alerts-on-odd-files-in-july-2023/m-p/551134#M1974</link>
      <description>&lt;P&gt;Yes, have seen the same for the last two. Appears to be a false positive which was finally removed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Threat ID 593953851 -&amp;nbsp;&lt;SPAN&gt;Dropper/Win32.fiy.clu was entered into the AV database on or about 7/18. On 7/19 it started constantly flagging the Adobe Photoshop update process trying to download AGMService.exe. The AV database entry completely disappeared on 7/20 like it never existed...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This was then followed by Threat ID 595725048 -&amp;nbsp;Virus/Win32.mikcer.flsd which was entered into the AV database sometime on or before 7/20. It flagged the same AGMService.exe file from Adobe. The AV database entry was updated at some point around 7/21 and stopped detecting the Adobe file, but the database doesn't give the initial release date... just a 7/25 current release update.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Threat ID 595101261 - Virus/Win32.pioneer.uzd was entered into the Wildfire database on 7/18 and the main AV database on 7/20 (I think). On 7/21 it started constantly flagging Adobe Photoshop update processes trying to download VulcanMessage5.dll file. The Wildfire database entry is no longer active (as of yesterday?), the AV database entry has completely disappeared yesterday like it never existed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Overall... yeah not happy with PA as they keep having these false positive database entries that have all their information wiped like they never happened, instead of showing the true initial release and withdrawal dates....&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 18:42:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/virus-alerts-on-odd-files-in-july-2023/m-p/551134#M1974</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2023-07-26T18:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: Virus alerts on odd files in July 2023</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/virus-alerts-on-odd-files-in-july-2023/m-p/554457#M1986</link>
      <description>&lt;P&gt;False Positives: Sometimes, security tools can mistakenly flag legitimate files as malicious. Given the nature of the flagged files (associated with Microsoft and Adobe), this is a possibility. Infected Source: There's a chance you've downloaded the software from a non-official or compromised source. Outdated Signatures: The threat database or signatures of your security tools might be outdated, leading to incorrect flagging. I haven't personally seen these specific flags recently, but I would advise: Ensure you're downloading software and updates only from official sources. Update your security tools and their signatures. Check with the vendors (Adobe, Microsoft, Sutherland Global) for any known issues. If you're part of a larger organization or network, reach out on security forums or groups related to Palo Alto Networks for shared experiences.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 05:54:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/virus-alerts-on-odd-files-in-july-2023/m-p/554457#M1986</guid>
      <dc:creator>KianMarsh</dc:creator>
      <dc:date>2023-08-21T05:54:11Z</dc:date>
    </item>
  </channel>
</rss>

