<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False positive for Visual Studio extension in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-for-visual-studio-extension/m-p/194942#M327</link>
    <description>&lt;P&gt;Please submit the following information in the order listed below so that our team can investigate your claim and change verdicts when warranted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;File Hash: &amp;lt;hash&amp;gt;&lt;/P&gt;&lt;P&gt;Link to Virustotal report for the file: &amp;lt;link&amp;gt;&lt;/P&gt;&lt;P&gt;Current VirustTotal Verdict: &amp;lt;verdict&amp;gt;&lt;/P&gt;&lt;P&gt;Description: &amp;lt;description&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our team will update each submission to this discussion forum at the conclusion of their research into your claim.&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jan 2018 15:08:04 GMT</pubDate>
    <dc:creator>bvandivier</dc:creator>
    <dc:date>2018-01-12T15:08:04Z</dc:date>
    <item>
      <title>False positive for Visual Studio extension</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-for-visual-studio-extension/m-p/194909#M326</link>
      <description>&lt;P&gt;I'm the author of this extension:&amp;nbsp;&lt;A href="https://marketplace.visualstudio.com/items?itemName=ionoy.XamarinFormsLive-18843" target="_blank"&gt;https://marketplace.visualstudio.com/items?itemName=ionoy.XamarinFormsLive-18843&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a xlserver.exe file that is a simple&amp;nbsp;.NET assembly serving as a TCP server. There is nothing malicious which can be easily verified. Please remove the false positive.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 08:17:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-for-visual-studio-extension/m-p/194909#M326</guid>
      <dc:creator>ionoy123</dc:creator>
      <dc:date>2018-01-12T08:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: False positive for Visual Studio extension</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-for-visual-studio-extension/m-p/194942#M327</link>
      <description>&lt;P&gt;Please submit the following information in the order listed below so that our team can investigate your claim and change verdicts when warranted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;File Hash: &amp;lt;hash&amp;gt;&lt;/P&gt;&lt;P&gt;Link to Virustotal report for the file: &amp;lt;link&amp;gt;&lt;/P&gt;&lt;P&gt;Current VirustTotal Verdict: &amp;lt;verdict&amp;gt;&lt;/P&gt;&lt;P&gt;Description: &amp;lt;description&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our team will update each submission to this discussion forum at the conclusion of their research into your claim.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 15:08:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-for-visual-studio-extension/m-p/194942#M327</guid>
      <dc:creator>bvandivier</dc:creator>
      <dc:date>2018-01-12T15:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: False positive for Visual Studio extension</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-for-visual-studio-extension/m-p/194944#M328</link>
      <description>&lt;P&gt;File Hash: &lt;SPAN&gt;6bf09b81fd56d6fdb4558018540dc5cf760c9dadc73b7c633fe76372297cc2d2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Link to Virustotal report for the file:&amp;nbsp;&lt;A href="https://www.virustotal.com/#/file/6bf09b81fd56d6fdb4558018540dc5cf760c9dadc73b7c633fe76372297cc2d2/detection" target="_blank"&gt;https://www.virustotal.com/#/file/6bf09b81fd56d6fdb4558018540dc5cf760c9dadc73b7c633fe76372297cc2d2/detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Current VirustTotal Verdict: &lt;SPAN&gt;generic.ml&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Description: &lt;SPAN&gt;xlserver.exe is the file that is contained inside VSIX package, which is actually a ZIP with another extension. My client has a corporate firewall or something, that is based on VirusTotal. Out of all vendors, only Palo Alto and CrowdStrike detected it as a possible malware. It's easy to check `xlserver.exe` because it's an unobfuscated .NET assembly. There is nothing malicious inside.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 15:16:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-for-visual-studio-extension/m-p/194944#M328</guid>
      <dc:creator>ionoy123</dc:creator>
      <dc:date>2018-01-12T15:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: False positive for Visual Studio extension</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-for-visual-studio-extension/m-p/194945#M329</link>
      <description>&lt;P&gt;Sample with hash&amp;nbsp;&lt;SPAN&gt;6bf09b81fd56d6fdb4558018540dc5cf760c9dadc73b7c633fe76372297cc2d2 has been queued for manual review.&amp;nbsp; Please allow us 24 to 48 hours to conduct a proper review and adjust verdict as appropriate.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 15:20:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-for-visual-studio-extension/m-p/194945#M329</guid>
      <dc:creator>bvandivier</dc:creator>
      <dc:date>2018-01-12T15:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: False positive for Visual Studio extension</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-for-visual-studio-extension/m-p/195327#M330</link>
      <description>&lt;P&gt;This sample has been updated to benign.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;STRONG&gt;Resolved Time&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;2018-01-15T17:57:40.755004&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 16 Jan 2018 16:04:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-for-visual-studio-extension/m-p/195327#M330</guid>
      <dc:creator>bvandivier</dc:creator>
      <dc:date>2018-01-16T16:04:08Z</dc:date>
    </item>
  </channel>
</rss>

