<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trying to understand what is wrong with my servers ip 5.182.39.34 in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/trying-to-understand-what-is-wrong-with-my-servers-ip-5-182-39/m-p/1221705#M2956</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;I have server (for last 6 months) with ip&amp;nbsp;5.182.39.34 (for internal purposes, no public services at all) partially used as proxy for accessing services with region restrictions, but some of them warns me that my reputation on virustotal is bad (or just denies usage at all), so had to start investigation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for now I have this situation&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.virustotal.com/gui/ip-address/5.182.39.34" target="_blank"&gt;https://www.virustotal.com/gui/ip-address/5.182.39.34&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="engine hstack"&gt;&lt;SPAN class="engine-name" data-tooltip-text="May differ from commercial off-the-shelf product. The
                        company decides the particular settings with which the
                        engine should run in our platform."&gt;SOCRadar&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; - tried all provided tools at &lt;A href="https://socradar.io" target="_blank"&gt;https://socradar.io&lt;/A&gt; - looks like this ip is clean and there should not be any issues, but virustotal thinks that ip is flagged by this provider&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="engine hstack"&gt;&lt;SPAN class="engine-name" data-tooltip-text="May differ from commercial off-the-shelf product. The
                        company decides the particular settings with which the
                        engine should run in our platform."&gt;CyRadar&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; - is not providing any tools for investigation, contacted them via website contact form without any luck, don't have any facebook account to use "report a false positive" button on cyradar.com =(&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone from virustotal help me with this?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 23 Feb 2025 12:04:51 GMT</pubDate>
    <dc:creator>roma</dc:creator>
    <dc:date>2025-02-23T12:04:51Z</dc:date>
    <item>
      <title>Trying to understand what is wrong with my servers ip 5.182.39.34</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/trying-to-understand-what-is-wrong-with-my-servers-ip-5-182-39/m-p/1221705#M2956</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;I have server (for last 6 months) with ip&amp;nbsp;5.182.39.34 (for internal purposes, no public services at all) partially used as proxy for accessing services with region restrictions, but some of them warns me that my reputation on virustotal is bad (or just denies usage at all), so had to start investigation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for now I have this situation&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.virustotal.com/gui/ip-address/5.182.39.34" target="_blank"&gt;https://www.virustotal.com/gui/ip-address/5.182.39.34&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="engine hstack"&gt;&lt;SPAN class="engine-name" data-tooltip-text="May differ from commercial off-the-shelf product. The
                        company decides the particular settings with which the
                        engine should run in our platform."&gt;SOCRadar&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; - tried all provided tools at &lt;A href="https://socradar.io" target="_blank"&gt;https://socradar.io&lt;/A&gt; - looks like this ip is clean and there should not be any issues, but virustotal thinks that ip is flagged by this provider&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="engine hstack"&gt;&lt;SPAN class="engine-name" data-tooltip-text="May differ from commercial off-the-shelf product. The
                        company decides the particular settings with which the
                        engine should run in our platform."&gt;CyRadar&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; - is not providing any tools for investigation, contacted them via website contact form without any luck, don't have any facebook account to use "report a false positive" button on cyradar.com =(&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone from virustotal help me with this?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Feb 2025 12:04:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/trying-to-understand-what-is-wrong-with-my-servers-ip-5-182-39/m-p/1221705#M2956</guid>
      <dc:creator>roma</dc:creator>
      <dc:date>2025-02-23T12:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to understand what is wrong with my servers ip 5.182.39.34</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/trying-to-understand-what-is-wrong-with-my-servers-ip-5-182-39/m-p/1221756#M2957</link>
      <description>&lt;P&gt;writed letter directly to socradar, looks like they tuned something and now I'm not flagged at virustotal, thanks everyone here)&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 12:26:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/trying-to-understand-what-is-wrong-with-my-servers-ip-5-182-39/m-p/1221756#M2957</guid>
      <dc:creator>roma</dc:creator>
      <dc:date>2025-02-24T12:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to understand what is wrong with my servers ip 5.182.39.34</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/trying-to-understand-what-is-wrong-with-my-servers-ip-5-182-39/m-p/1221760#M2958</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/915812055"&gt;@roma&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the heads up !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 13:26:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/trying-to-understand-what-is-wrong-with-my-servers-ip-5-182-39/m-p/1221760#M2958</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2025-02-24T13:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to understand what is wrong with my servers ip 5.182.39.34</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/trying-to-understand-what-is-wrong-with-my-servers-ip-5-182-39/m-p/1222025#M2963</link>
      <description>&lt;P&gt;Have another question regarding about "relations" -&amp;gt; Communicating Files&lt;/P&gt;
&lt;P&gt;There are some malicious software on virustotal on relations tab that "communicates" with my ip. I can't believe that this files speaking directly to ip address without any outdated domain name resolution.&lt;/P&gt;
&lt;P&gt;Is it possible to clean this records? Rescanning ony of that file is not helping at all =(&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2025 12:42:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/trying-to-understand-what-is-wrong-with-my-servers-ip-5-182-39/m-p/1222025#M2963</guid>
      <dc:creator>roma</dc:creator>
      <dc:date>2025-02-26T12:42:40Z</dc:date>
    </item>
  </channel>
</rss>

