<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False Positive Removal Request in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request/m-p/237325#M784</link>
    <description>&lt;P&gt;HI Artem.Razin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This SHA256=&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;fe7e560f4cf440ffb7dd79fb8001c43c8760b3015aad0f677ddc99fde156e2f2 is already benign.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is a trap message, we think it was blocked by your traps client.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Please open a support case with traps team with threat log, threat-ID or signature is been triggered.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Himani&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Oct 2018 19:01:58 GMT</pubDate>
    <dc:creator>hisingh</dc:creator>
    <dc:date>2018-10-26T19:01:58Z</dc:date>
    <item>
      <title>False Positive Removal Request</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request/m-p/237288#M782</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Today I've got a request from one of my customers that Deleaker, a popular C++ profiler, is dected as malware by&amp;nbsp;&lt;SPAN&gt;TRAPS from Palo Alto Networks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;File Hash: &lt;SPAN&gt;fe7e560f4cf440ffb7dd79fb8001c43c8760b3015aad0f677ddc99fde156e2f2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here the&amp;nbsp;virustotal report:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/#/file/fe7e560f4cf440ffb7dd79fb8001c43c8760b3015aad0f677ddc99fde156e2f2/detection" target="_blank"&gt;https://www.virustotal.com/#/file/fe7e560f4cf440ffb7dd79fb8001c43c8760b3015aad0f677ddc99fde156e2f2/detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;VirustTotal verdict: &lt;SPAN&gt;No engines detected this file&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Description: DeleakerSetup_2018.37.0.0.exe is&amp;nbsp;an installer of Deleaker.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The installer itself and&amp;nbsp;all files being installed are code signed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The installer can be downloaded &lt;A href="https://www.deleaker.com/download/DeleakerSetup.zip" target="_self"&gt;here&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please fix it ASAP as customer can't install Deleaker.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 13:11:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request/m-p/237288#M782</guid>
      <dc:creator>Artem.Razin</dc:creator>
      <dc:date>2018-10-26T13:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive Removal Request</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request/m-p/237325#M784</link>
      <description>&lt;P&gt;HI Artem.Razin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This SHA256=&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;fe7e560f4cf440ffb7dd79fb8001c43c8760b3015aad0f677ddc99fde156e2f2 is already benign.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is a trap message, we think it was blocked by your traps client.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Please open a support case with traps team with threat log, threat-ID or signature is been triggered.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Himani&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2018 19:01:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request/m-p/237325#M784</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2018-10-26T19:01:58Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive Removal Request</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request/m-p/237446#M794</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Himani,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you for the&amp;nbsp;fast reply.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am sorry, probably I misunderstood you.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you mean this file is already whitelisted?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Oct 2018 15:30:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request/m-p/237446#M794</guid>
      <dc:creator>Artem.Razin</dc:creator>
      <dc:date>2018-10-27T15:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive Removal Request</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request/m-p/237484#M795</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;Hi Artem.Razin,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;The file is blocked by traps; it could be a false positive case but with traps, not the wildfire.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;In the wildFire, this file is not identified as malware.&amp;nbsp; By opening a case with traps, the team can be useful.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Himani&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 06:07:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request/m-p/237484#M795</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2018-10-28T06:07:44Z</dc:date>
    </item>
  </channel>
</rss>

