<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False positive detected for Radioplayer app. Please white list. in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-detected-for-radioplayer-app-please-white-list/m-p/532543#M2330</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Please provide the requested information in the format that is outlined in the pinned thread at the top of this forum.&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/virustotal/virustotal-verdict-change-request-for-false-positive/td-p/287364" target="_blank"&gt;https://live.paloaltonetworks.com/t5/virustotal/virustotal-verdict-change-request-for-false-positive/td-p/287364&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Feb 2023 21:23:50 GMT</pubDate>
    <dc:creator>DaBone</dc:creator>
    <dc:date>2023-02-28T21:23:50Z</dc:date>
    <item>
      <title>False positive detected for Radioplayer app. Please white list.</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-detected-for-radioplayer-app-please-white-list/m-p/532532#M2329</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our app, Radioplayer v6.6, has been tagged by Cortex XDR as malware.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Please whitelist it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We're a reputable non-profit company: &lt;A title="Radioplayer" href="https://www.radioplayer.org" target="_blank" rel="noopener"&gt;https://www.radioplayer.org&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image0000001 (1).jpg" style="width: 450px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48248i06F302A53545C1E4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image0000001 (1).jpg" alt="image0000001 (1).jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image0000001.jpg" style="width: 450px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48249i228860A1E6FA55F6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image0000001.jpg" alt="image0000001.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 20:31:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-detected-for-radioplayer-app-please-white-list/m-p/532532#M2329</guid>
      <dc:creator>billbest21</dc:creator>
      <dc:date>2023-02-28T20:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: False positive detected for Radioplayer app. Please white list.</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-detected-for-radioplayer-app-please-white-list/m-p/532543#M2330</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Please provide the requested information in the format that is outlined in the pinned thread at the top of this forum.&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/virustotal/virustotal-verdict-change-request-for-false-positive/td-p/287364" target="_blank"&gt;https://live.paloaltonetworks.com/t5/virustotal/virustotal-verdict-change-request-for-false-positive/td-p/287364&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 21:23:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-detected-for-radioplayer-app-please-white-list/m-p/532543#M2330</guid>
      <dc:creator>DaBone</dc:creator>
      <dc:date>2023-02-28T21:23:50Z</dc:date>
    </item>
    <item>
      <title>Re: False positive detected for Radioplayer app. Please white list.</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-detected-for-radioplayer-app-please-white-list/m-p/532547#M2331</link>
      <description>&lt;P&gt;I had a similar instance with the Spectrum App.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would recommend to go to the Cortex XDR tenant and find this specific incident. Locate the wildfire information and identify the action/behavior that triggered that verdict.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the case of the Spectrum mobile app, I downloaded the Wildfire report from Cortex XDR and found out that this app was trying to contact a fishy URL. The URL had no information and was potentially malicious (virustotal was inconclusive I think, can't remember), it could have been just a brand new domain which could also trigger URL filtering to flag as malicious.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gustavo_Aristi_0-1677619478760.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48255iC416B5556613D063/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Gustavo_Aristi_0-1677619478760.png" alt="Gustavo_Aristi_0-1677619478760.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example of another similar incident:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gustavo_Aristi_1-1677619590904.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48256i8C8C0E1F946AD9E2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Gustavo_Aristi_1-1677619590904.png" alt="Gustavo_Aristi_1-1677619590904.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 21:29:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-detected-for-radioplayer-app-please-white-list/m-p/532547#M2331</guid>
      <dc:creator>Gustavo_Aristi</dc:creator>
      <dc:date>2023-02-28T21:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: False positive detected for Radioplayer app. Please white list.</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-detected-for-radioplayer-app-please-white-list/m-p/532550#M2332</link>
      <description>&lt;P&gt;Info given in screenshots posted above.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;App hash: &lt;STRONG&gt;f80297408af811666d54e5305accd9b27cbf0713097014a94f91c3ac7d6d16a1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Signature hash: &lt;STRONG&gt;f2782f7234b6091b1693bbeedffacc45&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Link to Virustotal report for the file: &lt;STRONG&gt;unknown&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Current VirustTotal Verdict: &lt;STRONG&gt;Malware&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Description: &lt;STRONG&gt;see screenshots&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image0000001 (1).jpg" style="width: 450px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48257iF5E1817DB0EEF359/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image0000001 (1).jpg" alt="image0000001 (1).jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image0000001.jpg" style="width: 450px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48258iAAA19CD66CC21CE0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image0000001.jpg" alt="image0000001.jpg" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 21:32:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-detected-for-radioplayer-app-please-white-list/m-p/532550#M2332</guid>
      <dc:creator>billbest21</dc:creator>
      <dc:date>2023-02-28T21:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: False positive detected for Radioplayer app. Please white list.</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-detected-for-radioplayer-app-please-white-list/m-p/532553#M2333</link>
      <description>&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately, I don't know what this means:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;I would recommend to go to the Cortex XDR tenant&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 21:35:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-detected-for-radioplayer-app-please-white-list/m-p/532553#M2333</guid>
      <dc:creator>billbest21</dc:creator>
      <dc:date>2023-02-28T21:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: False positive detected for Radioplayer app. Please white list.</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-detected-for-radioplayer-app-please-white-list/m-p/532556#M2334</link>
      <description>&lt;P&gt;Gotcha, no problem. Whomever installed Cortex XDR agent on your device perhaps your IT department, or your managed services provider, etc, would know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is the central point of intelligence for your Cortex XDR deployment. Your Cortex XDR agent is connected to it and sends information to this central location and this central location sends information back to your device as well as instructions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your Cortex XDR / IT / Security team could also report the verdict as incorrect as follows:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gustavo_Aristi_0-1677620395211.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48260i8D9B442E3D53124D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Gustavo_Aristi_0-1677620395211.png" alt="Gustavo_Aristi_0-1677620395211.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would first take a look at the previously mentioned Wildfire report to get a concrete idea of what triggered this verdict. This is potentially something that the developers of the the radioplayer app will find useful and will address it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 21:42:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-detected-for-radioplayer-app-please-white-list/m-p/532556#M2334</guid>
      <dc:creator>Gustavo_Aristi</dc:creator>
      <dc:date>2023-02-28T21:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: False positive detected for Radioplayer app. Please white list.</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-detected-for-radioplayer-app-please-white-list/m-p/532562#M2335</link>
      <description>&lt;P&gt;I've submitted this file for review.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 21:55:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-detected-for-radioplayer-app-please-white-list/m-p/532562#M2335</guid>
      <dc:creator>DaBone</dc:creator>
      <dc:date>2023-02-28T21:55:51Z</dc:date>
    </item>
  </channel>
</rss>

