<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic False Positive, gRO in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-gro/m-p/168938#M181</link>
    <description>&lt;P&gt;The sample is in the password protected zip file:&lt;/P&gt;&lt;P&gt;&lt;A href="http://37.61.202.134/false/GatheringRO-Patcher.zip" target="_blank"&gt;http://37.61.202.134/false/GatheringRO-Patcher.zip&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://37.61.202.134/false/gRO_Patcher_Update_05-08-17.zip" target="_blank"&gt;http://37.61.202.134/false/gRO_Patcher_Update_05-08-17.zip&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The password for the zip file is:&lt;/P&gt;&lt;P&gt;infected&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GatheringRO-Patcher&lt;/P&gt;&lt;P&gt;&lt;A href="https://virustotal.com/de/file/2d8fc70dbcb38c2f1985d7fdda2b1734aaee5ae131c4382ba53730d53a4ee981/analysis/1502275330/" target="_blank"&gt;https://virustotal.com/de/file/2d8fc70dbcb38c2f1985d7fdda2b1734aaee5ae131c4382ba53730d53a4ee981/analysis/1502275330/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Patcher Installer Update&lt;BR /&gt;&lt;A href="https://virustotal.com/de/file/74fada5542b81b7b469540f5a1b5d8cfbb6abe49933eba26dc2541902d83630e/analysis/1502275393/" target="_blank"&gt;https://virustotal.com/de/file/74fada5542b81b7b469540f5a1b5d8cfbb6abe49933eba26dc2541902d83630e/analysis/1502275393/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're running a MMORPG game with the name Gathering Ragnarok Online.&lt;/P&gt;&lt;P&gt;The game is online since over 12 years during which time we've always been using the same patcher system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we've released a new version of the patcher which is currently being detected as a false positive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only thing that changed with this latest relase was the IP Adress the patcher does connect to, because we've moved our server hardware.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This patcher is part of our game installer which can be officialy downloaded from our website:&lt;/P&gt;&lt;P&gt;&lt;A href="https://gatheringro.ch/?module=client" target="_blank"&gt;https://gatheringro.ch/?module=client&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Patcher Update can be downloaded from here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.gatheringro.ch/_forum/index.php?/topic/48947-server-migration-finished/" target="_blank"&gt;https://www.gatheringro.ch/_forum/index.php?/topic/48947-server-migration-finished/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.gatheringro.ch/_forum/index.php?/topic/37892-patcher-error-solutions/" target="_blank"&gt;https://www.gatheringro.ch/_forum/index.php?/topic/37892-patcher-error-solutions/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The patcher system we're using is from here:&lt;/P&gt;&lt;P&gt;&lt;A href="http://thor.aeomin.net/" target="_blank"&gt;http://thor.aeomin.net/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Version 2.6.4.13b&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're awaiting your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sincerely&lt;/P&gt;&lt;P&gt;Marc Bless&lt;/P&gt;</description>
    <pubDate>Wed, 09 Aug 2017 11:18:06 GMT</pubDate>
    <dc:creator>Everade</dc:creator>
    <dc:date>2017-08-09T11:18:06Z</dc:date>
    <item>
      <title>False Positive, gRO</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-gro/m-p/168938#M181</link>
      <description>&lt;P&gt;The sample is in the password protected zip file:&lt;/P&gt;&lt;P&gt;&lt;A href="http://37.61.202.134/false/GatheringRO-Patcher.zip" target="_blank"&gt;http://37.61.202.134/false/GatheringRO-Patcher.zip&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://37.61.202.134/false/gRO_Patcher_Update_05-08-17.zip" target="_blank"&gt;http://37.61.202.134/false/gRO_Patcher_Update_05-08-17.zip&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The password for the zip file is:&lt;/P&gt;&lt;P&gt;infected&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GatheringRO-Patcher&lt;/P&gt;&lt;P&gt;&lt;A href="https://virustotal.com/de/file/2d8fc70dbcb38c2f1985d7fdda2b1734aaee5ae131c4382ba53730d53a4ee981/analysis/1502275330/" target="_blank"&gt;https://virustotal.com/de/file/2d8fc70dbcb38c2f1985d7fdda2b1734aaee5ae131c4382ba53730d53a4ee981/analysis/1502275330/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Patcher Installer Update&lt;BR /&gt;&lt;A href="https://virustotal.com/de/file/74fada5542b81b7b469540f5a1b5d8cfbb6abe49933eba26dc2541902d83630e/analysis/1502275393/" target="_blank"&gt;https://virustotal.com/de/file/74fada5542b81b7b469540f5a1b5d8cfbb6abe49933eba26dc2541902d83630e/analysis/1502275393/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're running a MMORPG game with the name Gathering Ragnarok Online.&lt;/P&gt;&lt;P&gt;The game is online since over 12 years during which time we've always been using the same patcher system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we've released a new version of the patcher which is currently being detected as a false positive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only thing that changed with this latest relase was the IP Adress the patcher does connect to, because we've moved our server hardware.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This patcher is part of our game installer which can be officialy downloaded from our website:&lt;/P&gt;&lt;P&gt;&lt;A href="https://gatheringro.ch/?module=client" target="_blank"&gt;https://gatheringro.ch/?module=client&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Patcher Update can be downloaded from here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.gatheringro.ch/_forum/index.php?/topic/48947-server-migration-finished/" target="_blank"&gt;https://www.gatheringro.ch/_forum/index.php?/topic/48947-server-migration-finished/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.gatheringro.ch/_forum/index.php?/topic/37892-patcher-error-solutions/" target="_blank"&gt;https://www.gatheringro.ch/_forum/index.php?/topic/37892-patcher-error-solutions/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The patcher system we're using is from here:&lt;/P&gt;&lt;P&gt;&lt;A href="http://thor.aeomin.net/" target="_blank"&gt;http://thor.aeomin.net/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Version 2.6.4.13b&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're awaiting your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sincerely&lt;/P&gt;&lt;P&gt;Marc Bless&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2017 11:18:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-gro/m-p/168938#M181</guid>
      <dc:creator>Everade</dc:creator>
      <dc:date>2017-08-09T11:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive, gRO</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-gro/m-p/189967#M279</link>
      <description>&lt;P&gt;74fada5542b81b7b469540f5a1b5d8cfbb6abe49933eba26dc2541902d83630e&lt;BR /&gt;2d8fc70dbcb38c2f1985d7fdda2b1734aaee5ae131c4382ba53730d53a4ee981&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Submitted for FP Analysis&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 23:05:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-gro/m-p/189967#M279</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2017-12-04T23:05:10Z</dc:date>
    </item>
  </channel>
</rss>

