<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False positive removal request-generic.ml in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/200472#M369</link>
    <description>&lt;P&gt;that was super quick response to the post... appreciate it.. will await a response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;btw- if there are options for whitelisting proactively do share the same , appreciate the help&lt;/P&gt;</description>
    <pubDate>Wed, 14 Feb 2018 15:35:48 GMT</pubDate>
    <dc:creator>vinod_r2</dc:creator>
    <dc:date>2018-02-14T15:35:48Z</dc:date>
    <item>
      <title>False positive removal request-generic.ml</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/200468#M367</link>
      <description>&lt;P&gt;We are seeing False positive on our binaries , request assitance to Whitelist this... if possible also point me to place for proactive whitelisting to avoid detection in future on other binaries as all our binaries are signed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;File Hash:&amp;nbsp;07c3fe8a8f0b2f3dce76e7754f71efb8b6cfaf92e6ec0d575462a719b090603b&lt;/P&gt;&lt;P&gt;Link to Virustotal report for the file:&amp;nbsp;&lt;A href="https://www.virustotal.com/#/file/07c3fe8a8f0b2f3dce76e7754f71efb8b6cfaf92e6ec0d575462a719b090603b/detection" target="_blank"&gt;https://www.virustotal.com/#/file/07c3fe8a8f0b2f3dce76e7754f71efb8b6cfaf92e6ec0d575462a719b090603b/detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Current VirustTotal Verdict:&amp;nbsp;&lt;SPAN&gt;generic.ml&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Description: In house file used by support reps. digitally signed binaries.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;File Hash:&amp;nbsp; c1e0ca19ca664ffb65db7957fabc5ad2&lt;/P&gt;&lt;P&gt;Link to Virustotal report for the file:&amp;nbsp;&lt;A href="https://www.virustotal.com/#/file/f8fdef3d819b4ec04dbda43e83a0e0cb9900059a2f015cee6e2a1f54f37994f6/detection" target="_blank"&gt;https://www.virustotal.com/#/file/07c3fe8a8f0b2f3dce76e7754f71efb8b6cfaf92e6ec0d575462a719b090603b/detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Current VirustTotal Verdict:&amp;nbsp;&lt;SPAN&gt;generic.ml&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Description: In house file used by support reps. digitally signed binaries.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2018 15:12:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/200468#M367</guid>
      <dc:creator>vinod_r2</dc:creator>
      <dc:date>2018-02-14T15:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: False positive removal request-generic.ml</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/200470#M368</link>
      <description>&lt;P&gt;Both files have been queued for review.&amp;nbsp; Please allow us 24 to 48 hours to process these samples.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2018 15:29:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/200470#M368</guid>
      <dc:creator>bvandivier</dc:creator>
      <dc:date>2018-02-14T15:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: False positive removal request-generic.ml</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/200472#M369</link>
      <description>&lt;P&gt;that was super quick response to the post... appreciate it.. will await a response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;btw- if there are options for whitelisting proactively do share the same , appreciate the help&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2018 15:35:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/200472#M369</guid>
      <dc:creator>vinod_r2</dc:creator>
      <dc:date>2018-02-14T15:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: False positive removal request-generic.ml</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/200578#M370</link>
      <description>&lt;P&gt;We can whitelist a signer. Are these samples digitally signed?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2018 22:58:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/200578#M370</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-02-14T22:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: False positive removal request-generic.ml</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/200620#M371</link>
      <description>&lt;P&gt;Yes all our binaries are digitally signed by SHA256 and sha1 signatures.. EV authenticode&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2018 07:33:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/200620#M371</guid>
      <dc:creator>vinod_r2</dc:creator>
      <dc:date>2018-02-15T07:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: False positive removal request-generic.ml</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/200728#M372</link>
      <description>&lt;P&gt;Both samples were update to "benign" as of 9:43 CST this morning.&amp;nbsp; Please allow some time for this change to be reflected on virustotal.com.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2018 16:15:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/200728#M372</guid>
      <dc:creator>bvandivier</dc:creator>
      <dc:date>2018-02-15T16:15:36Z</dc:date>
    </item>
    <item>
      <title>Re: False positive removal request-generic.ml</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/202310#M383</link>
      <description>&lt;P&gt;What is the process to proceed for whitelist based on signature?.. would love to take this up to avoid chasing detection for suppression etc.....&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 16:17:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/202310#M383</guid>
      <dc:creator>vinod_r2</dc:creator>
      <dc:date>2018-02-26T16:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: False positive removal request-generic.ml</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/202654#M387</link>
      <description>&lt;P&gt;The next time you submit an FP, please ask the signer to be whitelisted.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 23:23:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/202654#M387</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-02-27T23:23:51Z</dc:date>
    </item>
    <item>
      <title>Re: False positive removal request-generic.ml</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/202695#M388</link>
      <description>&lt;P&gt;Wondering if we should wait for a False positive to occur and then raise this request. Would it not be easier for all if we proceed with the CA whitelisting now than later so its more proactive rather reactive. if the team requires more file samples or such happy to supply those&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 09:33:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/202695#M388</guid>
      <dc:creator>vinod_r2</dc:creator>
      <dc:date>2018-02-28T09:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: False positive removal request-generic.ml</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/203188#M389</link>
      <description>&lt;P&gt;Ok, I opened an internal request for you, will let you know once our threat researchers review the sample's signer.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Mar 2018 23:35:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/203188#M389</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-03-01T23:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: False positive removal request-generic.ml</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/203226#M390</link>
      <description>&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 07:16:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/203226#M390</guid>
      <dc:creator>vinod_r2</dc:creator>
      <dc:date>2018-03-02T07:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: False positive removal request-generic.ml</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/203338#M391</link>
      <description>&lt;P&gt;The signer's related samples have been reviewed, and there is now a formal WildFire Cloud request to have '&lt;SPAN&gt;Sutherland Global Services, Inc.' added to our whitelist.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 18:56:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/203338#M391</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-03-02T18:56:55Z</dc:date>
    </item>
  </channel>
</rss>

