<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Virus/Win32.WGeneric.clqdkh in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/virus-win32-wgeneric-clqdkh/m-p/492221#M2131</link>
    <description>&lt;P&gt;Alert name:&amp;nbsp;&lt;SPAN&gt;Virus/Win32.WGeneric.clqdkh&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Hash:(sha256):&amp;nbsp;&lt;SPAN&gt;354ef16a451f716c8cb3b47ced9878d8962088c143dfa2cf01f4f2ddfc70c097&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've checked the hash file for the the alert name through the&amp;nbsp;&lt;A href="https://threatvault.paloaltonetworks.com/" target="_blank"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt;&amp;nbsp;and I got the hash on it.&lt;/P&gt;&lt;P&gt;After checking this hash on Virustotal, the result is "No Matches found".&lt;/P&gt;&lt;P&gt;My questions:&lt;/P&gt;&lt;P&gt;1) If no matches found result, does it mean that the hash is new?&lt;/P&gt;&lt;P&gt;2) How may i determine if is it false positive or malicious?&lt;BR /&gt;&lt;BR /&gt;I checked similar cases regarding on&amp;nbsp;Virus/Win32.WGeneric and they says that this is a false positive.&lt;BR /&gt;Give me some thoughts and ideas about this for additional knowledge as i'm starting on this role as a cyber security.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 26 May 2022 06:15:17 GMT</pubDate>
    <dc:creator>EJaspe</dc:creator>
    <dc:date>2022-05-26T06:15:17Z</dc:date>
    <item>
      <title>Virus/Win32.WGeneric.clqdkh</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/virus-win32-wgeneric-clqdkh/m-p/492221#M2131</link>
      <description>&lt;P&gt;Alert name:&amp;nbsp;&lt;SPAN&gt;Virus/Win32.WGeneric.clqdkh&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Hash:(sha256):&amp;nbsp;&lt;SPAN&gt;354ef16a451f716c8cb3b47ced9878d8962088c143dfa2cf01f4f2ddfc70c097&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've checked the hash file for the the alert name through the&amp;nbsp;&lt;A href="https://threatvault.paloaltonetworks.com/" target="_blank"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt;&amp;nbsp;and I got the hash on it.&lt;/P&gt;&lt;P&gt;After checking this hash on Virustotal, the result is "No Matches found".&lt;/P&gt;&lt;P&gt;My questions:&lt;/P&gt;&lt;P&gt;1) If no matches found result, does it mean that the hash is new?&lt;/P&gt;&lt;P&gt;2) How may i determine if is it false positive or malicious?&lt;BR /&gt;&lt;BR /&gt;I checked similar cases regarding on&amp;nbsp;Virus/Win32.WGeneric and they says that this is a false positive.&lt;BR /&gt;Give me some thoughts and ideas about this for additional knowledge as i'm starting on this role as a cyber security.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2022 06:15:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/virus-win32-wgeneric-clqdkh/m-p/492221#M2131</guid>
      <dc:creator>EJaspe</dc:creator>
      <dc:date>2022-05-26T06:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Virus/Win32.WGeneric.clqdkh</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/virus-win32-wgeneric-clqdkh/m-p/492720#M2132</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;This forum is for non-customers to request that their files be manually reviewed.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If you have a support license then please open a case with the threat team, Product/Problem area = Threat.&lt;BR /&gt;&lt;BR /&gt;You can also get the actual file that is being deemed malicious and review the file, is this a file from your DEV team and they are creating a new program?&amp;nbsp; Basically what is this file?&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;There is a possibility this could be a signature collision.&amp;nbsp; Meaning, the file you have matches the signature we have for an actual malicious file.&amp;nbsp; However, you file maybe benign.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Do you own this file?&amp;nbsp; Does this file come from your company/organization?&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2022 17:31:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/virus-win32-wgeneric-clqdkh/m-p/492720#M2132</guid>
      <dc:creator>DaBone</dc:creator>
      <dc:date>2022-05-26T17:31:42Z</dc:date>
    </item>
  </channel>
</rss>

