<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VirusTotal False Positive: Internal App in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/virustotal-false-positive-internal-app/m-p/283787#M1164</link>
    <description>&lt;P&gt;Understood, and thank you for the clarification.&lt;/P&gt;</description>
    <pubDate>Tue, 20 Aug 2019 19:03:06 GMT</pubDate>
    <dc:creator>EngA_DerekBannard</dc:creator>
    <dc:date>2019-08-20T19:03:06Z</dc:date>
    <item>
      <title>VirusTotal False Positive: Internal App</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/virustotal-false-positive-internal-app/m-p/283763#M1154</link>
      <description>&lt;P&gt;I would like to submit the following information so that your team can investigate and change verdicts when warranted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;File Hash: [UTM/VirusTotal]&lt;/P&gt;&lt;P&gt;File Digest: 5fe238f2a8d7ce601370d18f18764eab274fb3397826c9fa48c65ef04a72408d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Link to Virustotal report for the file: &lt;A href="https://www.virustotal.com/gui/file/5fe238f2a8d7ce601370d18f18764eab274fb3397826c9fa48c65ef04a72408d/detection" target="_blank"&gt;https://www.virustotal.com/gui/file/5fe238f2a8d7ce601370d18f18764eab274fb3397826c9fa48c65ef04a72408d/detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Current VirustTotal Verdict:&amp;nbsp;&lt;SPAN&gt;Generic.ml&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Current UTM Verdict: malicious&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Description: This is an internally created application that is used by our office workers. This EXE is being flagged by our Palo UTM as "malicious" and listed on VirusTotal as "Generic.ml".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2019 17:39:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/virustotal-false-positive-internal-app/m-p/283763#M1154</guid>
      <dc:creator>EngA_DerekBannard</dc:creator>
      <dc:date>2019-08-20T17:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: VirusTotal False Positive: Internal App</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/virustotal-false-positive-internal-app/m-p/283774#M1158</link>
      <description>&lt;P&gt;As a Palo Alto Customer,&lt;/P&gt;&lt;P&gt;Please open a support case for this.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2019 17:47:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/virustotal-false-positive-internal-app/m-p/283774#M1158</guid>
      <dc:creator>dparris</dc:creator>
      <dc:date>2019-08-20T17:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: VirusTotal False Positive: Internal App</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/virustotal-false-positive-internal-app/m-p/283778#M1162</link>
      <description>&lt;P&gt;Is there a reason a posting in this forum is no longer accepted to report a false positive, with all the requested information in the "&lt;A href="https://live.paloaltonetworks.com/t5/VirusTotal/VirusTotal-Verdict-Change-Request-for-False-Positive/td-p/147165" target="_self"&gt;sticky&lt;/A&gt;" detailing what to include?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2019 17:55:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/virustotal-false-positive-internal-app/m-p/283778#M1162</guid>
      <dc:creator>EngA_DerekBannard</dc:creator>
      <dc:date>2019-08-20T17:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: VirusTotal False Positive: Internal App</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/virustotal-false-positive-internal-app/m-p/283780#M1163</link>
      <description>&lt;DIV&gt;&lt;SPAN&gt;As a Palo Alto customer you are entitled to support, here we only look at requests and flip the verdict if or when necessary.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;As Palo Alto customer we can look into why you are getting possible false positives and into other means of fixing the issue. &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;This has never been the method for Palo Alto Customers to report false positives. &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;This is the method for those that are not our customers and have no other means of reporting a malicious verdict.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 20 Aug 2019 18:06:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/virustotal-false-positive-internal-app/m-p/283780#M1163</guid>
      <dc:creator>dparris</dc:creator>
      <dc:date>2019-08-20T18:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: VirusTotal False Positive: Internal App</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/virustotal-false-positive-internal-app/m-p/283787#M1164</link>
      <description>&lt;P&gt;Understood, and thank you for the clarification.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2019 19:03:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/virustotal-false-positive-internal-app/m-p/283787#M1164</guid>
      <dc:creator>EngA_DerekBannard</dc:creator>
      <dc:date>2019-08-20T19:03:06Z</dc:date>
    </item>
  </channel>
</rss>

