<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic False positive in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive/m-p/183596#M215</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;We are facing some false positive issues in the software we develop. Here is a link to download a sample installer and also individual content:&lt;BR /&gt;&lt;A href="https://cp.sync.com/dl/f0ef29c20#hnvbmt7r-zbpvwdaa-qc6feknz-ks834c37" target="_blank"&gt;https://cp.sync.com/dl/f0ef29c20#hnvbmt7r-zbpvwdaa-qc6feknz-ks834c37&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://cp.sync.com/dl/d4f2b98c0#9bi8w8ve-st3xx7fd-3e4hr9mi-9k5j6gyq" target="_blank"&gt;https://cp.sync.com/dl/d4f2b98c0#9bi8w8ve-st3xx7fd-3e4hr9mi-9k5j6gyq&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;We think this could have been caused by the use of an EXE protector/packer/antidebug/anti-tampering&lt;BR /&gt;Unfortunately we can't stop using it for security reasons but we digitally sign all the installers and files, so we hope you can whitelist our digital signature, since this is causing many reputation issues to our company and negatively affecting to our relation with customers.&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Here you have links to the report of both files on VirusTotal:&lt;BR /&gt;&lt;A href="https://www.virustotal.com/#/file/f221e67a88d8b72dae0901e22356a5e5231485f8f40679" target="_blank"&gt;https://www.virustotal.com/#/file/f221e67a88d8b72dae0901e22356a5e5231485f8f40679&lt;/A&gt; 1e0895fbe63e8199b8/detection&lt;BR /&gt;&lt;A href="https://www.virustotal.com/#/file/afc4aff64a02d2f697d8ca413984524524c819a4667d9a" target="_blank"&gt;https://www.virustotal.com/#/file/afc4aff64a02d2f697d8ca413984524524c819a4667d9a&lt;/A&gt; ce9bfed45ed589ecfe/detection&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Thank you very much in advance.&lt;BR /&gt;If you should need any further details or contact information, please do not hesitate to contact me.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Oct 2017 08:59:28 GMT</pubDate>
    <dc:creator>carles</dc:creator>
    <dc:date>2017-10-25T08:59:28Z</dc:date>
    <item>
      <title>False positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive/m-p/183596#M215</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;We are facing some false positive issues in the software we develop. Here is a link to download a sample installer and also individual content:&lt;BR /&gt;&lt;A href="https://cp.sync.com/dl/f0ef29c20#hnvbmt7r-zbpvwdaa-qc6feknz-ks834c37" target="_blank"&gt;https://cp.sync.com/dl/f0ef29c20#hnvbmt7r-zbpvwdaa-qc6feknz-ks834c37&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://cp.sync.com/dl/d4f2b98c0#9bi8w8ve-st3xx7fd-3e4hr9mi-9k5j6gyq" target="_blank"&gt;https://cp.sync.com/dl/d4f2b98c0#9bi8w8ve-st3xx7fd-3e4hr9mi-9k5j6gyq&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;We think this could have been caused by the use of an EXE protector/packer/antidebug/anti-tampering&lt;BR /&gt;Unfortunately we can't stop using it for security reasons but we digitally sign all the installers and files, so we hope you can whitelist our digital signature, since this is causing many reputation issues to our company and negatively affecting to our relation with customers.&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Here you have links to the report of both files on VirusTotal:&lt;BR /&gt;&lt;A href="https://www.virustotal.com/#/file/f221e67a88d8b72dae0901e22356a5e5231485f8f40679" target="_blank"&gt;https://www.virustotal.com/#/file/f221e67a88d8b72dae0901e22356a5e5231485f8f40679&lt;/A&gt; 1e0895fbe63e8199b8/detection&lt;BR /&gt;&lt;A href="https://www.virustotal.com/#/file/afc4aff64a02d2f697d8ca413984524524c819a4667d9a" target="_blank"&gt;https://www.virustotal.com/#/file/afc4aff64a02d2f697d8ca413984524524c819a4667d9a&lt;/A&gt; ce9bfed45ed589ecfe/detection&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Thank you very much in advance.&lt;BR /&gt;If you should need any further details or contact information, please do not hesitate to contact me.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2017 08:59:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive/m-p/183596#M215</guid>
      <dc:creator>carles</dc:creator>
      <dc:date>2017-10-25T08:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: False positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive/m-p/189590#M248</link>
      <description>&lt;P&gt;Submitted analysis for&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;f221e67a88d8b72dae0901e22356a5e5231485f8f406791e0895fbe63e8199b8&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;afc4aff64a02d2f697d8ca413984524524c819a4667d9ace9bfed45ed589ecfe is the sha256 of the ZIP files. We don't create verdicts or signatures for ZIP files. That file is being blocked due to file inside being found to be malware:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;FeasaTerminal.exe with sha256&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;decd12804e4781be496b6451460bf89f51a215e609775dd31052fbb4c8d8a900.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;I'm submitting&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;decd12804e4781be496b6451460bf89f51a215e609775dd31052fbb4c8d8a900 separatelly for analysis.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;If these are found to be Benign, the associated signature will get disabled within the next 3 business days.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 16:51:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive/m-p/189590#M248</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2017-12-04T16:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: False positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive/m-p/189848#M253</link>
      <description>&lt;P&gt;&lt;STRONG&gt;The following samples were changed to a Benign verdict:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;f221e67a88d8b72dae0901e22356a5e5231485f8f406791e0895fbe63e8199b8&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;decd12804e4781be496b6451460bf89f51a215e609775dd31052fbb4c8d8a900&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The change will reflect in tomorrow's Antivirus release.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Your digital signatur will be added to our trusted signer list.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 16:53:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive/m-p/189848#M253</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2017-12-04T16:53:40Z</dc:date>
    </item>
  </channel>
</rss>

