<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Report False Positive in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/report-false-positive/m-p/382588#M1773</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the quick reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding the contacting IP, indeed, the app makes a request at every launch to our server to check for updates. The page it contacts is a simple HTML file with the latest version and the app simply reads the last version number posted on the page and if different from the current version of the app, it informs the user and asks him if he wants to update or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding the code signing, even from the first version, we sign the code. We never ship it unsigned.&lt;/P&gt;</description>
    <pubDate>Thu, 28 Jan 2021 14:38:33 GMT</pubDate>
    <dc:creator>hydraproxy</dc:creator>
    <dc:date>2021-01-28T14:38:33Z</dc:date>
    <item>
      <title>Report False Positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/report-false-positive/m-p/378116#M1741</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi team,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am Cristian, the founder of HydraProxy.com and creator of HydraHeaders, a browser profile management app for Windows.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We launched the HydraHeaders app on the 23rd of December 2020 and as of January 5th 2020, a couple of users signaled that your scan shows our app's executable file (the exe used for running the app, not the installer) as malicious.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;VirusTotal scan of installer exe: &lt;/SPAN&gt;&lt;A href="https://www.virustotal.com/gui/file/08ae48bc9de44bb4720f94e007dadf54a5195a77fd9839eb4d808d40513a1862/detection" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://www.virustotal.com/gui/file/08ae48bc9de44bb4720f94e007dadf54a5195a77fd9839eb4d808d40513a1862/detection&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;(False Positive) VirusTotal scan of exe file:&lt;/STRONG&gt; &lt;A href="https://www.virustotal.com/gui/file/0fbd26fbb6eff68a08748fdd95473e6e9880ee168f5b326a99bc1ef038a02419/detection" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://www.virustotal.com/gui/file/0fbd26fbb6eff68a08748fdd95473e6e9880ee168f5b326a99bc1ef038a02419/detection&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here’s the G Drive link of the installer: &lt;/SPAN&gt;&lt;A href="https://drive.google.com/file/d/1lWoK9JcR5S-jslO0D_kbofn0ABx7iILI/view?usp=sharing" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://drive.google.com/file/d/1lWoK9JcR5S-jslO0D_kbofn0ABx7iILI/view?usp=sharing&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here are some technical details of our app:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Development language: Python 3.6&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Exe package builder: pyinstaller&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Code signing certificate from Comodo&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;External files used: chromedriver and sqlite&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Administrator install required: optional (users can install it only for their Windows user, there is no need for install for all Windows users)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And here are some useful links:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Our website and HydraHeaders presentation page: &lt;A href="https://hydraproxy.com/hydraheaders/" target="_blank" rel="noopener"&gt;https://hydraproxy.com/hydraheaders/&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Download link for our users (we host it on box.com): &lt;A href="https://app.box.com/s/fcpkecprhbm87e6ouib5k2fgvu5huj0f" target="_blank" rel="noopener"&gt;https://app.box.com/s/fcpkecprhbm87e6ouib5k2fgvu5huj0f&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Softpedia listing page: &lt;/SPAN&gt;&lt;A href="https://www.softpedia.com/get/Internet/Other-Internet-Related/HydraHeaders.shtml" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://www.softpedia.com/get/Internet/Other-Internet-Related/HydraHeaders.shtml&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;AlternativeTo listing page: &lt;/SPAN&gt;&lt;A href="https://alternativeto.net/software/hydraheaders/" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://alternativeto.net/software/hydraheaders/&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We would greatly appreciate it if you can consider solving this false positive.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please let me know if you need further information from our end.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cristian Timofte&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;HydraProxy&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 13:32:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/report-false-positive/m-p/378116#M1741</guid>
      <dc:creator>hydraproxy</dc:creator>
      <dc:date>2021-01-06T13:32:27Z</dc:date>
    </item>
    <item>
      <title>Re: Report False Positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/report-false-positive/m-p/378127#M1742</link>
      <description>&lt;P&gt;Under review&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 13:42:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/report-false-positive/m-p/378127#M1742</guid>
      <dc:creator>tsullivan7</dc:creator>
      <dc:date>2021-01-06T13:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Report False Positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/report-false-positive/m-p/378134#M1743</link>
      <description>&lt;P&gt;Sample is no longer malicious&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 15:59:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/report-false-positive/m-p/378134#M1743</guid>
      <dc:creator>tsullivan7</dc:creator>
      <dc:date>2021-01-06T15:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: Report False Positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/report-false-positive/m-p/382520#M1769</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62538"&gt;@tsullivan7&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please note that our update (v 1.1) has been flagged as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are some useful links:&lt;/P&gt;&lt;P&gt;VirusTotal page:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/gui/file/21bfe53702e1752e46d70f79ae303ffcef53922ffca4cd882b635b9357ea6c05/detection" target="_blank"&gt;https://www.virustotal.com/gui/file/21bfe53702e1752e46d70f79ae303ffcef53922ffca4cd882b635b9357ea6c05/detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;App landing page:&lt;/P&gt;&lt;P&gt;&lt;A href="https://hydraproxy.com/hydraheaders/" target="_blank"&gt;https://hydraproxy.com/hydraheaders/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Version 1.1 update download link:&lt;/P&gt;&lt;P&gt;&lt;A href="https://app.box.com/s/oj2hrtm2fygotzd0ffvpidsz0r7q92od" target="_blank"&gt;https://app.box.com/s/oj2hrtm2fygotzd0ffvpidsz0r7q92od&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please consider this for removing the false-positive?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 09:06:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/report-false-positive/m-p/382520#M1769</guid>
      <dc:creator>hydraproxy</dc:creator>
      <dc:date>2021-01-28T09:06:25Z</dc:date>
    </item>
    <item>
      <title>Re: Report False Positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/report-false-positive/m-p/382587#M1772</link>
      <description>&lt;P&gt;If your software continues getting flagged by Wildfire as malicious, it would be advisable to consider what's in the code.&amp;nbsp; Is the code digitally signed?&amp;nbsp; If not you may want to consider this to limit the false positives.&amp;nbsp;&amp;nbsp;One thing Wildfire detected is the sample contacting an IP address info service via HTTP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is often used by malware to tailor a message or note to the compromised system in a user's language by geographic IP location. This behavior is also used often used by malware to identify sandboxes to prevent executing in a lab environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've submitted it for a verdict change evaluation.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 14:32:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/report-false-positive/m-p/382587#M1772</guid>
      <dc:creator>tsullivan7</dc:creator>
      <dc:date>2021-01-28T14:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: Report False Positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/report-false-positive/m-p/382588#M1773</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the quick reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding the contacting IP, indeed, the app makes a request at every launch to our server to check for updates. The page it contacts is a simple HTML file with the latest version and the app simply reads the last version number posted on the page and if different from the current version of the app, it informs the user and asks him if he wants to update or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding the code signing, even from the first version, we sign the code. We never ship it unsigned.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 14:38:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/report-false-positive/m-p/382588#M1773</guid>
      <dc:creator>hydraproxy</dc:creator>
      <dc:date>2021-01-28T14:38:33Z</dc:date>
    </item>
  </channel>
</rss>

