<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic False positive submission in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/389628#M1800</link>
    <description>&lt;P&gt;File Hash: lots of files (all versions we have distributed since the service started)&lt;/P&gt;&lt;P&gt;Files to download :&amp;nbsp;&lt;A href="https://drive.google.com/file/d/1UU_LUlLwhNan-Z657WEMD9gOtDyfFvET/view?usp=sharing" target="_blank" rel="noopener noreferrer"&gt;https://drive.google.com/file/d/1UU_LUlLwhNan-Z657WEMD9gOtDyfFvET/view?usp=sharing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Link to Virustotal report for the file:&amp;nbsp;&lt;A href="https://www.virustotal.com/gui/file/e6ed2f92fe26eb85dc5019654da03c11b7b3a03adb0e6de065c54d9c71c5ded1/detection" target="_blank" rel="noopener"&gt;https://www.virustotal.com/gui/file/e6ed2f92fe26eb85dc5019654da03c11b7b3a03adb0e6de065c54d9c71c5ded1/detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Current VirustTotal Verdict:&amp;nbsp;&lt;SPAN class="individual-detection"&gt;Generic.ml (&lt;/SPAN&gt;2 / 67)&lt;/P&gt;&lt;P&gt;Description:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Our product is developed with C# .NET framework and we use .NET Reactor to secure it. .Net Reactor is a tool for code protection and anti-debug. This service is utility tools for small businesses in South Korea.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;And all our binaries signed with EV Code Signing certificate.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;About 5 month ago, we noticed that our product was treated as a malware by multiple anti-virus softwares.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The problem was an option of .NET Reactor. We received advice from .NET Reactor team and turned off the 'Native EXE' option in their software since Oct 15th, 2020. KST&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;After changing the option, most false positive detection have disappeared. However, TotalVirus keeps histories of previous versions of our binaries which are not distributing anymore.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ex.&lt;/SPAN&gt;&lt;A href="https://www.virustotal.com/gui/file/6693d1f5eec019580667d10a52d6623777ba774ee7714bac3e7f3a38e06cd5a0/detection" target="_blank" rel="noopener noreferrer"&gt;https://www.virustotal.com/gui/file/6693d1f5eec019580667d10a52d6623777ba774ee7714bac3e7f3a38e06cd5a0/detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And Paloalto keeps '&lt;SPAN&gt;Generic.ml&lt;/SPAN&gt;' after it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://drive.google.com/file/d/1UU_LUlLwhNan-Z657WEMD9gOtDyfFvET/view?usp=sharing" target="_blank" rel="noopener noreferrer"&gt;https://drive.google.com/file/d/1UU_LUlLwhNan-Z657WEMD9gOtDyfFvET/view?usp=sharing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;These are all the binaries we have distributed. Some are clean by Paloalto and some are treated as a malware by Paloalto.&lt;/P&gt;&lt;P&gt;Please review all the files.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Mar 2021 01:14:57 GMT</pubDate>
    <dc:creator>young_kcd</dc:creator>
    <dc:date>2021-03-08T01:14:57Z</dc:date>
    <item>
      <title>False positive submission</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/389628#M1800</link>
      <description>&lt;P&gt;File Hash: lots of files (all versions we have distributed since the service started)&lt;/P&gt;&lt;P&gt;Files to download :&amp;nbsp;&lt;A href="https://drive.google.com/file/d/1UU_LUlLwhNan-Z657WEMD9gOtDyfFvET/view?usp=sharing" target="_blank" rel="noopener noreferrer"&gt;https://drive.google.com/file/d/1UU_LUlLwhNan-Z657WEMD9gOtDyfFvET/view?usp=sharing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Link to Virustotal report for the file:&amp;nbsp;&lt;A href="https://www.virustotal.com/gui/file/e6ed2f92fe26eb85dc5019654da03c11b7b3a03adb0e6de065c54d9c71c5ded1/detection" target="_blank" rel="noopener"&gt;https://www.virustotal.com/gui/file/e6ed2f92fe26eb85dc5019654da03c11b7b3a03adb0e6de065c54d9c71c5ded1/detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Current VirustTotal Verdict:&amp;nbsp;&lt;SPAN class="individual-detection"&gt;Generic.ml (&lt;/SPAN&gt;2 / 67)&lt;/P&gt;&lt;P&gt;Description:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Our product is developed with C# .NET framework and we use .NET Reactor to secure it. .Net Reactor is a tool for code protection and anti-debug. This service is utility tools for small businesses in South Korea.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;And all our binaries signed with EV Code Signing certificate.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;About 5 month ago, we noticed that our product was treated as a malware by multiple anti-virus softwares.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The problem was an option of .NET Reactor. We received advice from .NET Reactor team and turned off the 'Native EXE' option in their software since Oct 15th, 2020. KST&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;After changing the option, most false positive detection have disappeared. However, TotalVirus keeps histories of previous versions of our binaries which are not distributing anymore.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ex.&lt;/SPAN&gt;&lt;A href="https://www.virustotal.com/gui/file/6693d1f5eec019580667d10a52d6623777ba774ee7714bac3e7f3a38e06cd5a0/detection" target="_blank" rel="noopener noreferrer"&gt;https://www.virustotal.com/gui/file/6693d1f5eec019580667d10a52d6623777ba774ee7714bac3e7f3a38e06cd5a0/detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And Paloalto keeps '&lt;SPAN&gt;Generic.ml&lt;/SPAN&gt;' after it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://drive.google.com/file/d/1UU_LUlLwhNan-Z657WEMD9gOtDyfFvET/view?usp=sharing" target="_blank" rel="noopener noreferrer"&gt;https://drive.google.com/file/d/1UU_LUlLwhNan-Z657WEMD9gOtDyfFvET/view?usp=sharing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;These are all the binaries we have distributed. Some are clean by Paloalto and some are treated as a malware by Paloalto.&lt;/P&gt;&lt;P&gt;Please review all the files.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 01:14:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/389628#M1800</guid>
      <dc:creator>young_kcd</dc:creator>
      <dc:date>2021-03-08T01:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: False positive submission</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/389977#M1803</link>
      <description>&lt;P&gt;I tested all binaries of our product in VirusTotal.&lt;/P&gt;&lt;P&gt;These are specific version of files that is detected by paloalto.&lt;/P&gt;&lt;P&gt;All detection name are &lt;STRONG&gt;generic.ml&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.0.1.2\CashNotePos.UI.exe&lt;BR /&gt;1.0.0.3\CashNotePos.exe&lt;BR /&gt;1.0.0.5\CashNotePos.Manager.exe&lt;BR /&gt;1.0.1.7\CashNotePos.UI.exe&lt;BR /&gt;1.0.1.9\CashNotePos.UI.exe&lt;BR /&gt;1.0.0.5\CashNotePos.exe&lt;BR /&gt;1.0.0.6\CashNotePos.exe&lt;BR /&gt;1.0.1.17\CashNotePos.UI.exe&lt;BR /&gt;1.0.0.7\CashNotePos.exe&lt;BR /&gt;1.0.0.9\CashNotePos.Manager.exe&lt;BR /&gt;1.0.1.18\CashNotePos.UI.exe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SHA-256 of each files above&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;f2b8adf78d71a9fac993e2ac3772bec04937c20d88e56975f8f28d1b13d18389&lt;BR /&gt;2e1e551405694404d2940ff334f74bef7e1f88856dfdbadf1445aafc7ad4ac05&lt;BR /&gt;6693d1f5eec019580667d10a52d6623777ba774ee7714bac3e7f3a38e06cd5a0&lt;BR /&gt;2e940a779dfe7b3e99df92681180ef580e75de394e4c79307d261d09c2a4aadb&lt;BR /&gt;ced0bb043d0c8a9f8e99d212b3b2f5d5eebabf25ed15ff1279e9ddf92b36fcfd&lt;BR /&gt;2735aad2170ac6c570912139be73e6f86d1d33572841688e44c68675fc33515f&lt;BR /&gt;b430cf4b86912c4313516f7bf2fcfe32d82da3eec616fafd661c444c208c3ab5&lt;BR /&gt;3d5384768343049fc3572e9ef3bc7e121271f5a5de8575bb695ac05c379ff40a&lt;BR /&gt;b430cf4b86912c4313516f7bf2fcfe32d82da3eec616fafd661c444c208c3ab5&lt;BR /&gt;e6ed2f92fe26eb85dc5019654da03c11b7b3a03adb0e6de065c54d9c71c5ded1&lt;BR /&gt;92f2c87c72ac271b066cd1bbdb37e10e18b471eb29823898e3f5e259d89fba57&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 13:10:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/389977#M1803</guid>
      <dc:creator>young_kcd</dc:creator>
      <dc:date>2021-03-09T13:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: False positive submission</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/394099#M1817</link>
      <description>&lt;P&gt;detected count by Paloalto increased to 40.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our company is using Paloalto product. Even though it is not anti-virus software&lt;/P&gt;&lt;P&gt;How long should we wait for this to proceed?&lt;/P&gt;&lt;P&gt;I think we've been waiting enough so far.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.0.0.0_CashNotePos.Manager.exe 20b35ac4208e550178b98eea32291eea4333482b417d6fa1804b46cf1daed821&lt;BR /&gt;1.0.0.0_CashNotePos.UI.PayNotePaymentUI.exe be5b3d27dc52f7b2b65058dd8bb3fcf3835dc41abf1967f67cb06aee3bf6e842&lt;BR /&gt;1.0.0.1_CashNotePos.Manager.exe 3d654b01f01166d66d671b7852f76e07dd524dfc7ea634658d90e2d5d3a892b4&lt;BR /&gt;1.0.0.1_CashNotePos.exe 3a2f2af31619a9b354469610b38f52d0895902750a52d7582578447c06d28e3a&lt;BR /&gt;1.0.0.10_CashNotePos.Manager.exe 6f35c45a2e181970a7fb915731885a53d9475975b3fa47a8993159f64dd7c8fd&lt;BR /&gt;1.0.0.12_CashNotePos.Helper.exe 5cde0a5e3bfea047acaf8a23e727cd8314948c8b5151d35994bc041c9b244c0d&lt;BR /&gt;1.0.0.13_CashNotePos.Helper.exe 47c32df676ed72c7ac0f9fc060bc7b23f4f6df00567c5faf6e94c46dad73664a&lt;BR /&gt;1.0.0.2_CashNotePos.Helper.exe ce632f72cd5e6769440bcd456a2b8efeac87f798a4ee3f985ffb9e98fb070308&lt;BR /&gt;1.0.0.2_CashNotePos.Manager.exe 9a0d5d2f4963595d8787911069b1ce13982f3b1a28da3a16757790572883abbc&lt;BR /&gt;1.0.0.2_CashNotePos.exe cbcb39642401b534e808d97292770588bf4c96737d875cd3aece8eb5aac4b295&lt;BR /&gt;1.0.0.3_CashNotePos.Manager.exe d0765398107aed3ffec41e884436dbd84d68113a2929601f5b7844088d76a842&lt;BR /&gt;1.0.0.3_CashNotePos.Printer.exe 708d5b4f236f973314bd1202f6ac546fad6d5eb8af28f98465b3403d83ab263a&lt;BR /&gt;1.0.0.3_CashNotePos.exe 2e1e551405694404d2940ff334f74bef7e1f88856dfdbadf1445aafc7ad4ac05&lt;BR /&gt;1.0.0.4_CashNotePos.Manager.exe fbb536adf3826a2cff84ed929dc0cc165e4b42270f463f58c39f59c6ec2d2a72&lt;BR /&gt;1.0.0.4_CashNotePos.Printer.exe 4fcc5fbb61e23fc6ed48f9dba16f28d2a4926fe2d1e2f8346abe8420f19acb28&lt;BR /&gt;1.0.0.5_CashNotePos.Helper.exe 87e6c940b46256848cba3e046b9a58429b83d6f657b3728849cd8e3a4ee45644&lt;BR /&gt;1.0.0.5_CashNotePos.Manager.exe 6693d1f5eec019580667d10a52d6623777ba774ee7714bac3e7f3a38e06cd5a0&lt;BR /&gt;1.0.0.5_CashNotePos.Printer.exe ba3809226de85b9786ea8fda2f47a024fe5448561d37beb9a0b27d693d7fbd7c&lt;BR /&gt;1.0.0.5_CashNotePos.exe 2735aad2170ac6c570912139be73e6f86d1d33572841688e44c68675fc33515f&lt;BR /&gt;1.0.0.56_CashNotePos.Helper.exe c942bda90d2e4937946df801f6006ff1d8815984b5784ad9160be97ad94baf91&lt;BR /&gt;1.0.0.6_CashNotePos.Helper.exe 13be8b3907c5c1f18edb7c4b34019694c3cbc62e281cace0704ed3f0bdf1e3da&lt;BR /&gt;1.0.0.6_CashNotePos.Printer.exe a058491e80c94e2c411f9ced1ad22b4ea53efa020632647dc2b5f932ebc6d6ef&lt;BR /&gt;1.0.0.6_CashNotePos.exe b430cf4b86912c4313516f7bf2fcfe32d82da3eec616fafd661c444c208c3ab5&lt;BR /&gt;1.0.0.7_CashNotePos.Printer.exe 503ea9f82ff58574d4b65beeb6a66e97fed67808185121524b0118a58a0d060c&lt;BR /&gt;1.0.0.7_CashNotePos.exe b430cf4b86912c4313516f7bf2fcfe32d82da3eec616fafd661c444c208c3ab5&lt;BR /&gt;1.0.0.8_CashNotePos.Printer.Tool.exe e8aebbb0c95d3ba0b5169f47f37153c30dc89e70ee2eae6523aa601e2397be8b&lt;BR /&gt;1.0.0.8_CashNotePos.Printer.exe b72a7e8c54b49e82ea5223878c16b35ab5f067073f26540a2815f1505439d30a&lt;BR /&gt;1.0.0.9_CashNotePos.Manager.exe e6ed2f92fe26eb85dc5019654da03c11b7b3a03adb0e6de065c54d9c71c5ded1&lt;BR /&gt;1.0.0.9_CashNotePos.Printer.exe 48cdc589be714086adfd2396c16fe2bcf73bc0d67c4b45f43b0ad28b300f1587&lt;BR /&gt;1.0.1.1_CashNotePos.UI.exe 01688b68abc75c1cf4bdc31f32e16e985b24b5da19621b6453d3f88b36b9ae8b&lt;BR /&gt;1.0.1.17_CashNotePos.UI.exe 3d5384768343049fc3572e9ef3bc7e121271f5a5de8575bb695ac05c379ff40a&lt;BR /&gt;1.0.1.18_CashNotePos.UI.exe 92f2c87c72ac271b066cd1bbdb37e10e18b471eb29823898e3f5e259d89fba57&lt;BR /&gt;1.0.1.19_CashNotePos.UI.exe 47510427bfd7921d551994ceac7362b164e7107e693b591186e43974a3a7138c&lt;BR /&gt;1.0.1.2_CashNotePos.UI.exe f2b8adf78d71a9fac993e2ac3772bec04937c20d88e56975f8f28d1b13d18389&lt;BR /&gt;1.0.1.3_CashNotePos.UI.exe c9e6497befe72e12dc6ab9cdba40f7a1b512a990c1d19abe97045b3475094af4&lt;BR /&gt;1.0.1.4_CashNotePos.UI.exe 00ec840807a9e621587bcb6340300452ec71859e8ea69e9753e6c82c5f06858e&lt;BR /&gt;1.0.1.5_CashNotePos.UI.exe 12f3c29858a3a5b9b18073eba0612689e780c468837afdcb954f6eb9936c40b8&lt;BR /&gt;1.0.1.6_CashNotePos.UI.exe 8c9da1ef8ab6c1591ac5a8753195cf115774f08d09ced6e5b3b770958330b8af&lt;BR /&gt;1.0.1.7_CashNotePos.UI.exe 2e940a779dfe7b3e99df92681180ef580e75de394e4c79307d261d09c2a4aadb&lt;BR /&gt;1.0.1.9_CashNotePos.UI.exe ced0bb043d0c8a9f8e99d212b3b2f5d5eebabf25ed15ff1279e9ddf92b36fcfd&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 00:53:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/394099#M1817</guid>
      <dc:creator>young_kcd</dc:creator>
      <dc:date>2021-03-26T00:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: False positive submission</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/394330#M1819</link>
      <description>&lt;P&gt;If you are a Palo Alto customer please open a case with support to fix this error.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 13:22:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/394330#M1819</guid>
      <dc:creator>dparris</dc:creator>
      <dc:date>2021-03-26T13:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: False positive submission</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/394725#M1824</link>
      <description>&lt;P&gt;Our company uses Paloalto firewall product via a reseller in South Korea.&lt;/P&gt;&lt;P&gt;So we don't have any direct account for Paloalto at the moment.&lt;/P&gt;&lt;P&gt;Do we need to buy something to submit false positive cases? (even though it's unusual, we want it if you proceed this)&lt;/P&gt;&lt;P&gt;Then which one should we buy?&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have been waiting more than 3 weeks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 07:10:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/394725#M1824</guid>
      <dc:creator>young_kcd</dc:creator>
      <dc:date>2021-03-29T07:10:59Z</dc:date>
    </item>
    <item>
      <title>Re: False positive submission</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/394934#M1825</link>
      <description>&lt;P&gt;under review&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 13:18:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/394934#M1825</guid>
      <dc:creator>rnorouzi</dc:creator>
      <dc:date>2021-03-30T13:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: False positive submission</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/394979#M1827</link>
      <description>&lt;P&gt;since you are Palo Alto customer , please open Tac case . This form is for non Palo Alto customers .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 18:18:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/394979#M1827</guid>
      <dc:creator>rnorouzi</dc:creator>
      <dc:date>2021-03-30T18:18:37Z</dc:date>
    </item>
  </channel>
</rss>

