<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Removal from high-risk due to false positive in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564204#M2406</link>
    <description>&lt;P&gt;Are you a Palo Alto customer?&amp;nbsp; If so, open a TAC case.&amp;nbsp; If not, you can do the Request Change, and if it is changed, the Risk level will be lowered after ~30 days.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Nov 2023 22:23:44 GMT</pubDate>
    <dc:creator>DaBone</dc:creator>
    <dc:date>2023-11-02T22:23:44Z</dc:date>
    <item>
      <title>Removal from high-risk due to false positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564194#M2402</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our website, electask.com, was recently cleared of a false positive by CDRF and now has 0/90 vendors on VirusTotal flagging us as malicious. Can you please reduce our risk level?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.virustotal.com/gui/url/8e1462a33ee7402dd3c3168239d3fe50cb0f5a8fc85527043398cf64e1dc3801?nocache=1" target="_blank"&gt;https://www.virustotal.com/gui/url/8e1462a33ee7402dd3c3168239d3fe50cb0f5a8fc85527043398cf64e1dc3801?nocache=1&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Max&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 22:07:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564194#M2402</guid>
      <dc:creator>Electask</dc:creator>
      <dc:date>2023-11-02T22:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Removal from high-risk due to false positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564199#M2403</link>
      <description>&lt;P&gt;This is not the place for these types of requests.&amp;nbsp; This is for files and for non-customers to request a verdict change for their files.&lt;BR /&gt;&lt;BR /&gt;The reason you are seeing a high risk by Palo Alto Networks is due to this URL being deemed malware:&lt;/P&gt;
&lt;P&gt;electask[.]com/k56b&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;You can do a Request Change here:&lt;BR /&gt;&lt;A href="https://urlfiltering.paloaltonetworks.com/" target="_blank"&gt;https://urlfiltering.paloaltonetworks.com/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;We will then do a manual review of the URL.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 22:15:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564199#M2403</guid>
      <dc:creator>DaBone</dc:creator>
      <dc:date>2023-11-02T22:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: Removal from high-risk due to false positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564201#M2404</link>
      <description>&lt;P&gt;Thank you.&amp;nbsp;&lt;A href="https://www.electask.com/k56b" target="_blank"&gt;https://www.electask.com/k56b&lt;/A&gt;&amp;nbsp;just directs to a 404. I'll submit a review&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 22:17:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564201#M2404</guid>
      <dc:creator>Electask</dc:creator>
      <dc:date>2023-11-02T22:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: Removal from high-risk due to false positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564202#M2405</link>
      <description>&lt;P&gt;Hi Dabone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I submit a request it gives me the following message:&amp;nbsp;&lt;/P&gt;
&lt;DIV class="alert alert-danger"&gt;"If you are trying to change the Risk rating, this cannot be done via Change Request. If the Risk rating is incorrect, please contact support."&lt;/DIV&gt;
&lt;DIV class="alert alert-danger"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="alert alert-danger"&gt;Before this forum, I've tried half a dozen times to contact support via phone, chat, and submitting on the website but have been unable to reach anyone. Do you have any advice?&lt;/DIV&gt;</description>
      <pubDate>Thu, 02 Nov 2023 22:21:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564202#M2405</guid>
      <dc:creator>Electask</dc:creator>
      <dc:date>2023-11-02T22:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: Removal from high-risk due to false positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564204#M2406</link>
      <description>&lt;P&gt;Are you a Palo Alto customer?&amp;nbsp; If so, open a TAC case.&amp;nbsp; If not, you can do the Request Change, and if it is changed, the Risk level will be lowered after ~30 days.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 22:23:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564204#M2406</guid>
      <dc:creator>DaBone</dc:creator>
      <dc:date>2023-11-02T22:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Removal from high-risk due to false positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564205#M2407</link>
      <description>&lt;P&gt;I am not a customer. Is there anyway to get it faster than 30 days? Our customers use PANW and it’s impacting our business&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 22:28:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564205#M2407</guid>
      <dc:creator>Electask</dc:creator>
      <dc:date>2023-11-02T22:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: Removal from high-risk due to false positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564227#M2408</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;I have engaged our internal PANDB team to review this issue.&amp;nbsp;&lt;BR /&gt;Here is a link to the ticket for reference.&amp;nbsp; This is not a public facing domain.&amp;nbsp; This is for reference for those that can assist with any updates. This could take a couple of working days for a response.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://jira-dc.paloaltonetworks.com/browse/PDE-2806" target="_self"&gt;PDE-2806&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 01:39:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564227#M2408</guid>
      <dc:creator>DaBone</dc:creator>
      <dc:date>2023-11-03T01:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: Removal from high-risk due to false positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564301#M2409</link>
      <description>&lt;P&gt;You're awesome. Thank you very much for the help!&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 12:34:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564301#M2409</guid>
      <dc:creator>Electask</dc:creator>
      <dc:date>2023-11-03T12:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: Removal from high-risk due to false positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564539#M2410</link>
      <description>&lt;P&gt;Hi DaBone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm still seeing us as "high-risk." Is there any update on your end? Thank you again very much for looking into this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Max&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 17:57:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564539#M2410</guid>
      <dc:creator>Electask</dc:creator>
      <dc:date>2023-11-06T17:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: Removal from high-risk due to false positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564558#M2411</link>
      <description>&lt;P&gt;I inquired from the engineers about the progress on this issue.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 22:44:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564558#M2411</guid>
      <dc:creator>tsullivan7</dc:creator>
      <dc:date>2023-11-06T22:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: Removal from high-risk due to false positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564563#M2412</link>
      <description>&lt;P&gt;here is the response from our internal engineering team.&lt;/P&gt;
&lt;P&gt;This domain was released as high-risk on 10/12/2023 as we observed the malicious child URL electask&lt;SPAN&gt;[.]&lt;/SPAN&gt;com/k56b (VT 7 hits) on the same day. Our standard policy is to re-evaluate the risk level 30 days after the last release (i.e. 11/12/2023) and lower the risk if the malicious URL(s) are no longer present. However, I manually analyzed the domain and since the malicious URL is cleaned now, we lowered the risk to low-risk now.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;==========&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;electask.com is now Low Risk&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 00:09:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564563#M2412</guid>
      <dc:creator>DaBone</dc:creator>
      <dc:date>2023-11-07T00:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: Removal from high-risk due to false positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564564#M2413</link>
      <description>&lt;P&gt;You all are awesome! Thank you so much!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Max&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 00:19:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564564#M2413</guid>
      <dc:creator>Electask</dc:creator>
      <dc:date>2023-11-07T00:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: Removal from high-risk due to false positive</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564565#M2414</link>
      <description>&lt;P&gt;You're very welcome; we are happy to help.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 00:28:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/removal-from-high-risk-due-to-false-positive/m-p/564565#M2414</guid>
      <dc:creator>DaBone</dc:creator>
      <dc:date>2023-11-07T00:28:28Z</dc:date>
    </item>
  </channel>
</rss>

