<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False positive removal request (generic.ml) in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/194024#M312</link>
    <description>&lt;P&gt;Files with hash 42db01439e1ab94638bb1c96b9e27a52c9a8a75e622e8f8df85241e895507cc7 and&amp;nbsp;&lt;SPAN&gt;8ee884ec7bf9d728a15b3b5edcbf6de3197b822a842e8013725ecd2d8fee07c1 have been submitted for review by our analysts and verdict flip to benign.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jan 2018 16:01:24 GMT</pubDate>
    <dc:creator>bvandivier</dc:creator>
    <dc:date>2018-01-05T16:01:24Z</dc:date>
    <item>
      <title>False positive removal request (generic.ml)</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/193517#M304</link>
      <description>&lt;P&gt;2 versions of Dll file used in our company's privacy/anti-tracking app are falsely marked as generic.ml by Palo Alto engine (results based on Virustotal scan report.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;File version#1&lt;/P&gt;&lt;P&gt;File Hash: 6c7af7cf2a87f6a12be2b254cfc8349c&lt;/P&gt;&lt;P&gt;Link to Virustotal report for the file: &lt;A href="https://www.virustotal.com/#/file/42db01439e1ab94638bb1c96b9e27a52c9a8a75e622e8f8df85241e895507cc7/details" target="_blank"&gt;https://www.virustotal.com/#/file/42db01439e1ab94638bb1c96b9e27a52c9a8a75e622e8f8df85241e895507cc7/details&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Current VirustTotal Verdict: &lt;SPAN class="individual_detection style-scope vt-detections"&gt;generic.ml&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="individual_detection style-scope vt-detections"&gt;File version#2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="individual_detection style-scope vt-detections"&gt;File Hash: &lt;/SPAN&gt;5deecfe1beec58021a92e4838fc58e70&lt;/P&gt;&lt;P&gt;&lt;SPAN class="individual_detection style-scope vt-detections"&gt;Link to Viristotal: &lt;A href="https://www.virustotal.com/#/file/8ee884ec7bf9d728a15b3b5edcbf6de3197b822a842e8013725ecd2d8fee07c1/details" target="_blank"&gt;https://www.virustotal.com/#/file/8ee884ec7bf9d728a15b3b5edcbf6de3197b822a842e8013725ecd2d8fee07c1/details&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="individual_detection style-scope vt-detections"&gt;Current VirusTotal Verdict: generic.ml&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="individual_detection style-scope vt-detections"&gt;These files are used by our app to provide anti-tracking and advertisment blocking services to our customers. Is there a possibility to whitelist these files by signature, so that we don't run into same FP in future? Thank you!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2018 16:42:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/193517#M304</guid>
      <dc:creator>George2018</dc:creator>
      <dc:date>2018-01-02T16:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: False positive removal request (generic.ml)</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/193993#M311</link>
      <description>&lt;P&gt;Still waiting for some feedback on our product case.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2018 14:10:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/193993#M311</guid>
      <dc:creator>George2018</dc:creator>
      <dc:date>2018-01-05T14:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: False positive removal request (generic.ml)</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/194024#M312</link>
      <description>&lt;P&gt;Files with hash 42db01439e1ab94638bb1c96b9e27a52c9a8a75e622e8f8df85241e895507cc7 and&amp;nbsp;&lt;SPAN&gt;8ee884ec7bf9d728a15b3b5edcbf6de3197b822a842e8013725ecd2d8fee07c1 have been submitted for review by our analysts and verdict flip to benign.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2018 16:01:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/194024#M312</guid>
      <dc:creator>bvandivier</dc:creator>
      <dc:date>2018-01-05T16:01:24Z</dc:date>
    </item>
    <item>
      <title>Re: False positive removal request (generic.ml)</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/194129#M315</link>
      <description>&lt;P&gt;Hi, thak you for an update, but on VT we still see the same result (detection with generic.ml). Do we have to wait for the update?&lt;/P&gt;&lt;P&gt;Also, is there a possibility to whitelist this file by our signature, so that it doesn't get marked in the upcoming versions of the product?&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jan 2018 11:05:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/194129#M315</guid>
      <dc:creator>George2018</dc:creator>
      <dc:date>2018-01-06T11:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: False positive removal request (generic.ml)</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/194438#M319</link>
      <description>&lt;P&gt;You had to wait for the update, it's showing clean now. If I understood the update correctly from our analysts, the signer has been added to the trusted signer list, but I don't have a way to verify that at this time.&amp;nbsp;If you observe a new FP, please make sure to request the signer be added to the trusted list to prevent FP's from reocurring.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2018 19:31:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/194438#M319</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-01-09T19:31:59Z</dc:date>
    </item>
  </channel>
</rss>

