<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False Positive Submission: 7zip installer in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission-7zip-installer/m-p/187291#M227</link>
    <description>&lt;P&gt;&lt;SPAN&gt;We've made the signature more specific, to prevent probability of collisions.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If the change yields the expected results, you&amp;nbsp;should see the collision resolved after installing tomorrows release of the Antivirus package.&lt;/P&gt;</description>
    <pubDate>Wed, 15 Nov 2017 21:55:10 GMT</pubDate>
    <dc:creator>mivaldi</dc:creator>
    <dc:date>2017-11-15T21:55:10Z</dc:date>
    <item>
      <title>False Positive Submission: 7zip installer</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission-7zip-installer/m-p/186266#M221</link>
      <description>&lt;P&gt;Hi There&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The following is being detected as a virus, and since it's a reputable source, it's probably a false positive. VirusTotal detects no threat:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Virus/Win32.WGeneric.nnpwy(188234211)&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://www.7-zip.org/a/7z1602-x64.exe" target="_blank" rel="nofollow"&gt;http://www.7-zip.org/a/7z1602-x64.exe&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/en/url/40719e870a1df9806d7a856f4dcf115b15c867c5dc4b8057ccfd7d59601df4df/analysis/1510241062/" target="_blank"&gt;https://www.virustotal.com/en/url/40719e870a1df9806d7a856f4dcf115b15c867c5dc4b8057ccfd7d59601df4df/analysis/1510241062/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 15:32:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission-7zip-installer/m-p/186266#M221</guid>
      <dc:creator>puppetjt</dc:creator>
      <dc:date>2017-11-09T15:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive Submission: 7zip installer</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission-7zip-installer/m-p/187202#M225</link>
      <description>&lt;P&gt;Have I put this in the correct place?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 15:37:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission-7zip-installer/m-p/187202#M225</guid>
      <dc:creator>puppetjt</dc:creator>
      <dc:date>2017-11-15T15:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive Submission: 7zip installer</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission-7zip-installer/m-p/187247#M226</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/64701"&gt;@puppetjt&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Virus Total link you submitted is for the URL of the installer, not for the file.&lt;/P&gt;&lt;P&gt;The file is deemed Benign by WildFire.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The right sha256 for the sample is&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;f1601b09cd0c9627b1aab7299b83529e8fbc6b5078e43dfd81a1b0bfcdf4a308&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;The VirusTotal report is clean.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;A href="https://www.virustotal.com/en/file/f1601b09cd0c9627b1aab7299b83529e8fbc6b5078e43dfd81a1b0bfcdf4a308/analysis/" target="_blank"&gt;https://www.virustotal.com/en/file/f1601b09cd0c9627b1aab7299b83529e8fbc6b5078e43dfd81a1b0bfcdf4a308/analysis/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;If the file triggers an Antivirus signature, this is most likely the case of a signature collision.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Signature collisions happen when the digital patterns of a Benign file that the firewall looks at to determine a match with a virus signature, coincide with those of a sample that has been determined to be Malware (which includes the possibility of a signature collision with a False Positive).&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;In this particular case, the Signature Collision is with sample&amp;nbsp;&lt;SPAN&gt;f70870509dc2845e1720e68957f7a159b2cd7a2f69950d4707119f9bd5a6c5cc which is a trojanized version of the 7zip installer.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.virustotal.com/en/file/f70870509dc2845e1720e68957f7a159b2cd7a2f69950d4707119f9bd5a6c5cc/analysis/" target="_blank"&gt;https://www.virustotal.com/en/file/f70870509dc2845e1720e68957f7a159b2cd7a2f69950d4707119f9bd5a6c5cc/analysis/&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN&gt;In general, the recommendation in cases like these is to create an Antivirus Exception in the Antivirus profile tied to the Security Policy matching you traffic. The reason why we can't disable the signature, is because that would mean that we would allow both the Benign installer, and the trojanized version, resolving the problem for you, but exposing everyone else to get infected.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN&gt;One of the possible counter-measures to this, is to increase the specifity of the Malware signature, to make sure it matches the Malware variant, and not the Benign file.&amp;nbsp;The increased specifity of the signature not always resolves the collisions, but I will give it a try, and come back to you with our results.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 19:26:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission-7zip-installer/m-p/187247#M226</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2017-11-15T19:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive Submission: 7zip installer</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission-7zip-installer/m-p/187291#M227</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We've made the signature more specific, to prevent probability of collisions.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If the change yields the expected results, you&amp;nbsp;should see the collision resolved after installing tomorrows release of the Antivirus package.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 21:55:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission-7zip-installer/m-p/187291#M227</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2017-11-15T21:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive Submission: 7zip installer</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission-7zip-installer/m-p/187458#M228</link>
      <description>&lt;P&gt;Mivaldi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much for looking in to this. I'll have to wait until the realse is ready, as I think im 4 hour off at this stage.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Out of interest, what was incorrect with the link I gave? It was indeed the installer itself that was flagging the Palo Alto (literally just clicking that link in the browser would throw the error). Reason I'm interested is that I'd like to understand how better to submit these issues in the future.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;JT&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2017 11:03:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission-7zip-installer/m-p/187458#M228</guid>
      <dc:creator>puppetjt</dc:creator>
      <dc:date>2017-11-16T11:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive Submission: 7zip installer</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission-7zip-installer/m-p/187539#M229</link>
      <description>&lt;P&gt;When you submit an URL to Virus Total instead of a File, it scans the website for any persistent malicious code that would attempt to hijack your browser. The follow up download happens at a separate report. (I just realized there's a left-over link that points you to the analysis of the downloaded file).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So it was not incorrect, but the VT report you submitted was for the URL,&amp;nbsp;not the file -not a big deal-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are a Palo Alto Networks customer, you should&amp;nbsp;open a case with Palo Alto Networks Support, instead of using this forum.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2017 17:40:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission-7zip-installer/m-p/187539#M229</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2017-11-16T17:40:05Z</dc:date>
    </item>
  </channel>
</rss>

