<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False-positive submission in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/233381#M735</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The verdict for "&lt;STRONG&gt;f40e85443f50cb78db68c343bc53d7fc30d05f6f4ac58ad59d492e7088478be5"&amp;nbsp; i&lt;/STRONG&gt;s no longer listed as malicious.&amp;nbsp;&lt;SPAN&gt;VirusTotal is been updated, the AntiVirus next release will have updated information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Himani&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Oct 2018 18:42:26 GMT</pubDate>
    <dc:creator>hisingh</dc:creator>
    <dc:date>2018-10-02T18:42:26Z</dc:date>
    <item>
      <title>False-positive submission</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/233107#M728</link>
      <description>Hi, Please find false-positive detection. VirusTotal link: &lt;A href="https://www.virustotal.com/#/file/f40e85443f50cb78db68c343bc53d7fc30d05f6f4ac58ad59d492e7088478be5/detection" target="_blank"&gt;https://www.virustotal.com/#/file/f40e85443f50cb78db68c343bc53d7fc30d05f6f4ac58ad59d492e7088478be5/detection&lt;/A&gt; SHA-256 f40e85443f50cb78db68c343bc53d7fc30d05f6f4ac58ad59d492e7088478be5 The file can be downloaded from: &lt;A href="https://cdn4.hola.org/static/Hola-Setup-x64-1.108.133.exe" target="_blank"&gt;https://cdn4.hola.org/static/Hola-Setup-x64-1.108.133.exe&lt;/A&gt; Would appreciate your clearance of the false-positive detection ASAP and please verify that Hola Networks digital signature was added to trusted signer list, please see paloalto live community recent discussions. Thanks, Roi</description>
      <pubDate>Sun, 30 Sep 2018 13:56:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/233107#M728</guid>
      <dc:creator>roipaz</dc:creator>
      <dc:date>2018-09-30T13:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: False-positive submission</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/233234#M731</link>
      <description>&lt;P&gt;Hello Roipaz,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are looking at the possibility of the False positive on this case, I will update you when we are finished with our research.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Himani&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2018 21:00:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/233234#M731</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2018-10-01T21:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: False-positive submission</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/233381#M735</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The verdict for "&lt;STRONG&gt;f40e85443f50cb78db68c343bc53d7fc30d05f6f4ac58ad59d492e7088478be5"&amp;nbsp; i&lt;/STRONG&gt;s no longer listed as malicious.&amp;nbsp;&lt;SPAN&gt;VirusTotal is been updated, the AntiVirus next release will have updated information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Himani&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 18:42:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/233381#M735</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2018-10-02T18:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: False-positive submission</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/233383#M737</link>
      <description>Thank you Haimani, When it will be a convenient time for you to have a short call to discuss how to prevent the repeating false-positive? Thanks, Roi</description>
      <pubDate>Tue, 02 Oct 2018 18:04:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/233383#M737</guid>
      <dc:creator>roipaz</dc:creator>
      <dc:date>2018-10-02T18:04:32Z</dc:date>
    </item>
    <item>
      <title>Re: False-positive submission</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/233392#M740</link>
      <description>&lt;P&gt;Hello Roipaz,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are not able to call or support non customers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have checked with engineering and they&amp;nbsp;declined to add your files to the trusted signer white list.&lt;/P&gt;&lt;P&gt;If you disagree with a verdict for a file, you will have to ask for evaluation on a file by file basis.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Don, Palo Alto Threat Specialist&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 18:48:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/233392#M740</guid>
      <dc:creator>dparris</dc:creator>
      <dc:date>2018-10-02T18:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: False-positive submission</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/233409#M741</link>
      <description>Hi Don, What cause the false-positive detection? Is there something we can do from our side to prevent such cases to happened so frequently? Thanks, Roi</description>
      <pubDate>Tue, 02 Oct 2018 19:17:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/233409#M741</guid>
      <dc:creator>roipaz</dc:creator>
      <dc:date>2018-10-02T19:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: False-positive submission</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/233430#M742</link>
      <description>&lt;P&gt;In many of the cases it is the way you write your code.&amp;nbsp; In this file for instance, you have the file copies itself ,contacts unregistered dns server , Uses http direct ip connection, uses http with no ua ,uses http requests with short headers. Along with many other pieces that are common in malware.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 20:37:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-submission/m-p/233430#M742</guid>
      <dc:creator>dparris</dc:creator>
      <dc:date>2018-10-02T20:37:25Z</dc:date>
    </item>
  </channel>
</rss>

