<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MTGAInstaller.exe in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/mtgainstaller-exe/m-p/196896#M342</link>
    <description>&lt;P&gt;The verdict has been updated to grayware and the associated signature has been disabled.&lt;/P&gt;&lt;P&gt;The reason for the grayware verdict is that the sample downloads an unverified .msi package.&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jan 2018 18:24:46 GMT</pubDate>
    <dc:creator>mivaldi</dc:creator>
    <dc:date>2018-01-25T18:24:46Z</dc:date>
    <item>
      <title>MTGAInstaller.exe</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/mtgainstaller-exe/m-p/196540#M334</link>
      <description>&lt;P&gt;I am not the creator of this file, nor am I affiliated with the creators.&amp;nbsp; We had a user on our network report that this file was blocked and so I investigated on our firewall.&amp;nbsp; The firewall is reporting "Virus/Win32.WGeneric.pjeib" and VirusTotal is reporting "&lt;SPAN&gt;generic.ml" for Palo Alto.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;File Hash: &lt;SPAN&gt;8d7c493fd2a51f2cc2bf212e4cd39130d305cb3d758962c322b54bad2052b1cc&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Link to Virustotal report for the file: &lt;A href="https://www.virustotal.com/#/file/8d7c493fd2a51f2cc2bf212e4cd39130d305cb3d758962c322b54bad2052b1cc/detection" target="_blank"&gt;https://www.virustotal.com/#/file/8d7c493fd2a51f2cc2bf212e4cd39130d305cb3d758962c322b54bad2052b1cc/detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Current VirustTotal Verdict: 5/65&lt;/P&gt;&lt;P&gt;Description:&amp;nbsp;I haven't downloaded this myself but the user is reporting it is an installer for an alpha test and it looks like it is from a gaming site.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 23:21:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/mtgainstaller-exe/m-p/196540#M334</guid>
      <dc:creator>jsalmans</dc:creator>
      <dc:date>2018-01-23T23:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: MTGAInstaller.exe</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/mtgainstaller-exe/m-p/196745#M337</link>
      <description>&lt;P&gt;Thank you. The sample was submitted for FP analysis.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2018 22:10:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/mtgainstaller-exe/m-p/196745#M337</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-01-24T22:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: MTGAInstaller.exe</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/mtgainstaller-exe/m-p/196896#M342</link>
      <description>&lt;P&gt;The verdict has been updated to grayware and the associated signature has been disabled.&lt;/P&gt;&lt;P&gt;The reason for the grayware verdict is that the sample downloads an unverified .msi package.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 18:24:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/mtgainstaller-exe/m-p/196896#M342</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-01-25T18:24:46Z</dc:date>
    </item>
  </channel>
</rss>

