<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False positive on VirusTotal in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/208944#M423</link>
    <description>&lt;P&gt;Can you explain what "Grayware" is?&amp;nbsp; Why not greenware or some other color.&amp;nbsp; We operate above board with over 1m subscribers.&amp;nbsp; Why would you not list this app in your whitelist?&lt;/P&gt;</description>
    <pubDate>Thu, 05 Apr 2018 22:12:50 GMT</pubDate>
    <dc:creator>RD1111</dc:creator>
    <dc:date>2018-04-05T22:12:50Z</dc:date>
    <item>
      <title>False positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/208689#M416</link>
      <description>&lt;P&gt;Can you please address this false positive &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/#/file/ff32c2227af54f738c2bab0301bc0a101b64d6f1715865fc220ea1064ec1399a/details" target="_blank"&gt;https://www.virustotal.com/#/file/ff32c2227af54f738c2bab0301bc0a101b64d6f1715865fc220ea1064ec1399a/details&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Apr 2018 23:20:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/208689#M416</guid>
      <dc:creator>RD1111</dc:creator>
      <dc:date>2018-04-03T23:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: False positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/208690#M417</link>
      <description>&lt;P&gt;I will see what I can do to get this verdict changed&lt;/P&gt;</description>
      <pubDate>Tue, 03 Apr 2018 23:24:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/208690#M417</guid>
      <dc:creator>dparris</dc:creator>
      <dc:date>2018-04-03T23:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: False positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/208692#M418</link>
      <description>&lt;P&gt;&lt;SPAN&gt;This has been submitted for manual evaluation.&amp;nbsp; I've confirmed that Virus Total has this rated at 6/66&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Apr 2018 23:50:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/208692#M418</guid>
      <dc:creator>dparris</dc:creator>
      <dc:date>2018-04-03T23:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: False positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/208915#M422</link>
      <description>&lt;P&gt;&lt;SPAN&gt;You requested the verdict be changed to &lt;STRONG&gt;&lt;SPAN&gt;benign&lt;/SPAN&gt;&lt;/STRONG&gt;, but was instead changed to &lt;STRONG&gt;&lt;SPAN&gt;grayware&lt;/SPAN&gt;&lt;/STRONG&gt;. According to our internal annalysis team this is a Greyware app.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2018 18:29:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/208915#M422</guid>
      <dc:creator>dparris</dc:creator>
      <dc:date>2018-04-05T18:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: False positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/208944#M423</link>
      <description>&lt;P&gt;Can you explain what "Grayware" is?&amp;nbsp; Why not greenware or some other color.&amp;nbsp; We operate above board with over 1m subscribers.&amp;nbsp; Why would you not list this app in your whitelist?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2018 22:12:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/208944#M423</guid>
      <dc:creator>RD1111</dc:creator>
      <dc:date>2018-04-05T22:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: False positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/208946#M424</link>
      <description>&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/translated/70/newfeaturesguide/wildfire-features/wildfire-grayware-verdict" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/translated/70/newfeaturesguide/wildfire-features/wildfire-grayware-verdict&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The WildFire grayware verdict classifies files that behave similarly to malware, but are not malicious in nature or intent. A grayware verdict might be assigned to files that do not pose a direct security threat, but display otherwise obtrusive behavior (for example, installing unwanted software, changing various system settings, or reducing system performance). Examples of grayware software can typically include adware, spyware, and Browser Helper Objects (BHOs). The grayware verdict allows you to quickly distinguish malicious files on the network from grayware, and to prioritize accordingly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Antivirus signatures are not generated for grayware and security policies cannot be enforced based on the grayware verdict. However, logs and reports can continue to alert to endpoints downloading grayware, enabling you to take any necessary action.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2018 23:09:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/208946#M424</guid>
      <dc:creator>dparris</dc:creator>
      <dc:date>2018-04-05T23:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: False positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/208948#M425</link>
      <description>&lt;P&gt;Thank you for claryfying - but this does not answer my initial question.&amp;nbsp; Please see below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- This app does is not marketed to anyone who did not specifically request to download and install it.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- This app is not obtrusive, distruptive, does not change any system settings without users explicit permission, does not in any way reduce system performance - in fact it does the opposite.&lt;/P&gt;&lt;P&gt;- This app does not include any adware or spyware or BHOs - in fact its designed to remove or block these types of files/behaviours&lt;/P&gt;&lt;P&gt;- This app has gone through extensive 3rd party validation and is currently certified by AppEsteem (&lt;A href="https://customer.appesteem.com/vendors/REALD/171117-PEF-REALD-00039" target="_blank"&gt;https://customer.appesteem.com/vendors/REALD/171117-PEF-REALD-00039&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Per above - how does this app qualify as a grayware?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2018 23:16:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/208948#M425</guid>
      <dc:creator>RD1111</dc:creator>
      <dc:date>2018-04-05T23:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: False positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/209059#M428</link>
      <description>&lt;P&gt;Our Malware Reverse Engineers manually reviewed the software and from their analysis the software exhibits characteristics that malware also performs. Some of these things could be self signed certs or software that isn't signed at all. Proxy changes are also listed as potentaly harmful and this program was seen to perform that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I am not the one who analyzes the software itself, I can't speak to why they determined it to be Greyware. If you look at it in Virus Total it says that it's Clean and not Malware. This was the goal, correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Apr 2018 17:56:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/209059#M428</guid>
      <dc:creator>dparris</dc:creator>
      <dc:date>2018-04-06T17:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: False positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/209076#M429</link>
      <description>&lt;P&gt;Our software is not self signed and we use DigiCert and other reputable 3rd party certs.&amp;nbsp; We do not use Proxies.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you tell me where you are detecting this info.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We do not want our software categories incorrectly and greyware classification is certainly not accetable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We just want to know the facts.&amp;nbsp; If you say we are using proxies or 1st party certs or display behaviour consistent with malware - please show us where you are seeing this or provide any evidence to prove this.&amp;nbsp; Nothing that you have mentioned is consistent with how our software works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise further&lt;/P&gt;</description>
      <pubDate>Fri, 06 Apr 2018 18:21:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/209076#M429</guid>
      <dc:creator>RD1111</dc:creator>
      <dc:date>2018-04-06T18:21:11Z</dc:date>
    </item>
    <item>
      <title>Re: False positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/209610#M437</link>
      <description>&lt;P&gt;Any updates on this?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 19:16:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/209610#M437</guid>
      <dc:creator>RD1111</dc:creator>
      <dc:date>2018-04-11T19:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: False positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/209612#M438</link>
      <description>&lt;P&gt;The verdict for this file has been set, there will not be any changes. As far as Palo Alto is conserned this file is Greyware.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 19:19:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/209612#M438</guid>
      <dc:creator>dparris</dc:creator>
      <dc:date>2018-04-11T19:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: False positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/209670#M439</link>
      <description>&lt;P&gt;Can you please provide contact info for your legal department?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 22:12:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/209670#M439</guid>
      <dc:creator>RD1111</dc:creator>
      <dc:date>2018-04-11T22:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: False positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/209822#M440</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm part of the product management team here at Palo Alto Networks focusing on WildFire.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We'd like to help out.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A couple questions:&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;Is your primary concern the representation of this file on VT?&amp;nbsp;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;Pending on your response, what is your concern with the verdict of grayware? Customer's rarely block or restrict file access based on grayware and VT should no longer reflect a hit after the sample is reanalyzed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 16:39:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/209822#M440</guid>
      <dc:creator>ghamilton</dc:creator>
      <dc:date>2018-04-12T16:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: False positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/209881#M441</link>
      <description>&lt;P&gt;Hello and thank you for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our biggest concern is that our app does not fit into your Grayware criteria.&lt;/P&gt;&lt;P&gt;I have clearly explained what our app does and asked your team to specifically point out how our application is classified under your Grayware definition and your staff has yet to reply with specific examples.&amp;nbsp; Your definition is broad and does not explicitly or directly addresses our application.&amp;nbsp; Your definition of Grayware includes business and technology practices that are a) not applicable to us b) completely the opposite of what our app does c) missleading and counter intuitive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise as to next steps.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 20:27:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/209881#M441</guid>
      <dc:creator>RD1111</dc:creator>
      <dc:date>2018-04-12T20:27:38Z</dc:date>
    </item>
    <item>
      <title>Re: False positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/210643#M452</link>
      <description>&lt;P&gt;Hello again&lt;/P&gt;&lt;P&gt;Looks like you guys are flagging us again.&lt;/P&gt;&lt;P&gt;Can you please remove the blocking and whitelist us.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 01:57:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/210643#M452</guid>
      <dc:creator>RD1111</dc:creator>
      <dc:date>2018-04-18T01:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: False positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/210801#M453</link>
      <description>&lt;P&gt;Please advise if you received last post.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 18:01:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/210801#M453</guid>
      <dc:creator>RD1111</dc:creator>
      <dc:date>2018-04-18T18:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: False positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/210802#M454</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We took your advice to escalate to our legal department, and recommend&amp;nbsp;that your attorney contact our Corporate Legal Counsel, Ms. Wee, directly at lwee@paloaltonetworks.com if you wish to discuss the matter further.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 18:17:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/210802#M454</guid>
      <dc:creator>brcook</dc:creator>
      <dc:date>2018-04-18T18:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: False positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/210804#M455</link>
      <description>&lt;P&gt;Thank you&lt;BR /&gt;We are simply asking you to remove the blocking as its inacurate.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 18:21:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/210804#M455</guid>
      <dc:creator>RD1111</dc:creator>
      <dc:date>2018-04-18T18:21:48Z</dc:date>
    </item>
  </channel>
</rss>

