<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False Positive on VirusTotal in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/233592#M744</link>
    <description>&lt;P&gt;We do not rely on other vendors for our verdicts. Our own internal engineers and tools have deemed this file to perform possibly malicious activities erning it a malicious verdict. If the file is changed at a later date and no longer performes these possably malicious actions, we can take a look then, but at that point it will have a different hash.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Oct 2018 13:03:47 GMT</pubDate>
    <dc:creator>dparris</dc:creator>
    <dc:date>2018-10-03T13:03:47Z</dc:date>
    <item>
      <title>False Positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/233066#M726</link>
      <description>&lt;P&gt;Detection result on virustotal.com below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Puppet3G.exe&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Palo Alto Networks (Known Signatures) generic.ml 20180929&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://s3-ap-northeast-1.amazonaws.com/puppet.dev/falsepositive/Puppet3G_Puppet3R.zip" target="_blank"&gt;https://s3-ap-northeast-1.amazonaws.com/puppet.dev/falsepositive/Puppet3G_Puppet3R.zip&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Puppet3G.exe is detected, but Puppet3R.exe is not detected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;source&lt;BR /&gt;&lt;A href="https://github.com/leo-typeb/Puppet3" target="_blank"&gt;https://github.com/leo-typeb/Puppet3&lt;/A&gt;&lt;BR /&gt;distributed installer&lt;BR /&gt;&lt;A href="https://github.com/leo-typeb/Puppet3/releases/download/v3.1.3/Puppet3.1.3G.zip" target="_blank"&gt;https://github.com/leo-typeb/Puppet3/releases/download/v3.1.3/Puppet3.1.3G.zip&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://github.com/leo-typeb/Puppet3/releases/download/v3.1.3/Puppet3.1.3R.zip" target="_blank"&gt;https://github.com/leo-typeb/Puppet3/releases/download/v3.1.3/Puppet3.1.3R.zip&lt;/A&gt;&lt;BR /&gt;I developed it.&lt;BR /&gt;Puppet3 is distributed 2 versions Puppet3G and Puppet3R.&lt;BR /&gt;The difference between the 2 versions:&lt;BR /&gt;- GUID of .exe&lt;BR /&gt;- Picture in the Resource&lt;BR /&gt;- Name: Puppet3G.exe Puppet3R.exe&lt;BR /&gt;Puppet3 is hobby software. It moves eyes and mouth with Microphone sound or Application sound.&lt;BR /&gt;The reason why 2 versions are distributed is that there are users on YouTube wish to display their two puppets on the live streaming or movies.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Sep 2018 08:09:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/233066#M726</guid>
      <dc:creator>leo-typeb</dc:creator>
      <dc:date>2018-09-29T08:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/233252#M733</link>
      <description>&lt;P&gt;Hello Leo-typeb,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In your bundle&amp;nbsp;&lt;A href="https://s3-ap-northeast-1.amazonaws.com/puppet.dev/falsepositive/Puppet3G_Puppet3R.zip" target="_blank" rel="nofollow noopener noreferrer"&gt;https://s3-ap-northeast-1.amazonaws.com/puppet.dev/falsepositive/Puppet3G_Puppet3R.zip&lt;/A&gt;, you have two files -&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;Puppet3G.exe&amp;nbsp; sha256:&amp;nbsp;fd65e473242b97f5ea01393158550d30f5779c3706e29e3367e0c440260d520e&lt;/P&gt;&lt;P&gt;VT Detection Ratio: 10 / 68&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/file/fd65e473242b97f5ea01393158550d30f5779c3706e29e3367e0c440260d520e/analysis/1538401934/" target="_blank"&gt;https://www.virustotal.com/file/fd65e473242b97f5ea01393158550d30f5779c3706e29e3367e0c440260d520e/analysis/1538401934/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since 10 other vendors think that it could be malicious, we need to check and will update soon.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Puppet3R.exea . 9a82cb19692af4c3178e5354bcb71d4950a0d9068890a6b8a02df7dbccbc62e&lt;/P&gt;&lt;P&gt;VT Detection Ratio: 7 / 68&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/file/a9a82cb19692af4c3178e5354bcb71d4950a0d9068890a6b8a02df7dbccbc62e/analysis/1538402069/" target="_blank"&gt;https://www.virustotal.com/file/a9a82cb19692af4c3178e5354bcb71d4950a0d9068890a6b8a02df7dbccbc62e/analysis/1538402069/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Paloalto networks verdict is already&amp;nbsp;benign.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Himani&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2018 22:54:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/233252#M733</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2018-10-01T22:54:57Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/233390#M739</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our malware team took another look at the sample, file and Sha256 hash. our team is&amp;nbsp;&lt;SPAN&gt;keeping the verdict as malware for generic hits for malware.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Himani&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 18:29:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/233390#M739</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2018-10-02T18:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/233551#M743</link>
      <description>&lt;P class="p1"&gt;Hi Himani,&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;Thank you for your reply.&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;About 20 of vendors detected on virustotal.com. So I am sending reports to them.&lt;/P&gt;&lt;P class="p1"&gt;Some vendors (Microsoft, Symantec, F-Secure, etc.) have update their product already, but some other vendors have not reply yet.&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;Can I re-report to you after I get these vendors reply?&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;Best Regards,&lt;/P&gt;&lt;P class="p1"&gt;Leo-typeb&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 12:07:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/233551#M743</guid>
      <dc:creator>leo-typeb</dc:creator>
      <dc:date>2018-10-03T12:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/233592#M744</link>
      <description>&lt;P&gt;We do not rely on other vendors for our verdicts. Our own internal engineers and tools have deemed this file to perform possibly malicious activities erning it a malicious verdict. If the file is changed at a later date and no longer performes these possably malicious actions, we can take a look then, but at that point it will have a different hash.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 13:03:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/233592#M744</guid>
      <dc:creator>dparris</dc:creator>
      <dc:date>2018-10-03T13:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/233716#M745</link>
      <description>&lt;P class="p1"&gt;Hi dparris,&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;Thank you for your support.&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p3"&gt;I understand.&lt;/P&gt;&lt;P class="p3"&gt;I am publishing the source code and only one of the two executable files built from the same code is marked as malware.&lt;/P&gt;&lt;P class="p3"&gt;I will notify users of this version that I can not support false positives from your products.&lt;/P&gt;&lt;P class="p4"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p3"&gt;Best Regards,&lt;/P&gt;&lt;P class="p3"&gt;Leo-typeb&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 15:52:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/233716#M745</guid>
      <dc:creator>leo-typeb</dc:creator>
      <dc:date>2018-10-03T15:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive on VirusTotal</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/233719#M746</link>
      <description>&lt;P&gt;Hi Leo-typeb,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No problem, like I said as far as our engineers and tools show us, and it seems many other of the top AV and Malware protection providers this is a true positive. We can not change that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have a wonderful day, I hope you get this strieghtened out.&lt;/P&gt;&lt;P&gt;Don&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 16:35:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-on-virustotal/m-p/233719#M746</guid>
      <dc:creator>dparris</dc:creator>
      <dc:date>2018-10-03T16:35:34Z</dc:date>
    </item>
  </channel>
</rss>

