<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False Positive Removal Request: generic.ml in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/242900#M834</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I heard from our team, the verdict for this file is changed to benign. This change is immediately&amp;nbsp;reflected in the WildFire and within 24-48 hours in our Anti Virus.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Himani&lt;/P&gt;</description>
    <pubDate>Tue, 11 Dec 2018 21:19:33 GMT</pubDate>
    <dc:creator>hisingh</dc:creator>
    <dc:date>2018-12-11T21:19:33Z</dc:date>
    <item>
      <title>False Positive Removal Request: generic.ml</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/242720#M832</link>
      <description>&lt;P class="engine style-scope vt-detections"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SHA-256&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;cf9a5ca5ad376234ba38d374d855fce048dd7abda4955a4548874d412fb4355e&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Vox_Imago_PC.exe&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;236 KB&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2018-12-10 14:00:51 UTC&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/#/file/cf9a5ca5ad376234ba38d374d855fce048dd7abda4955a4548874d412fb4355e/detection" target="_blank"&gt;https://www.virustotal.com/#/file/cf9a5ca5ad376234ba38d374d855fce048dd7abda4955a4548874d412fb4355e/detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can download a sample from &lt;A href="http://giga.simetranet.com/Vox_Imago_PC.zip" target="_blank"&gt;http://giga.simetranet.com/Vox_Imago_PC.zip&lt;/A&gt;&lt;/P&gt;&lt;P&gt;is a password protected zip file the archive password is "infected"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a FALSE POSITIVE, please we kindly request to correct your antivirus detection&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This an executable for a ROM track (DVD-ROM) Multimedia DVD that simply auto-execute the multimedia application present in the dvd-rom.&lt;/P&gt;&lt;P&gt;We made the executable and it isn't a virus or malware but actually it is recognized by your antivirus heuristic code as a malware-like.&lt;/P&gt;&lt;P&gt;We hereby declare that this code doesn't contain any malware or virus code, the executable will generate a simple BAT file that will change directory and call another executable in the cd-rom executing those shell commands:&lt;BR /&gt;--&lt;BR /&gt;cd voximago&lt;BR /&gt;Vox_Imago_PC.exe&lt;BR /&gt;--&lt;BR /&gt;Actually is needed because the real executable only work in a sub-directory but we need to execute it from the root directory of the cd-rom.&lt;BR /&gt;&lt;BR /&gt;We are requesting to be identified as secure also because we can’t modify the cd-rom already distribuited.&lt;BR /&gt;&lt;BR /&gt;Thankyou very much.&lt;BR /&gt;Best regards.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Carlo Santagostino&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:carlo@sugartec.it" target="_blank"&gt;carlo@sugartec.it&lt;/A&gt;&lt;/P&gt;&lt;P&gt;+39 371 1437050&lt;/P&gt;&lt;P&gt;SUGARTEC by NORMADIGITAL SRL&lt;/P&gt;&lt;P&gt;Sede legale: Viale Renato Serra 6 – 20148 – Milano (MI)&lt;/P&gt;&lt;P&gt;Tel. +39.02.84258991 - Fax. +39.02.87183135 – &lt;A href="mailto:info@sugartec.it" target="_blank"&gt;info@sugartec.it&lt;/A&gt; – &lt;A href="http://www.sugartec.it" target="_blank"&gt;www.sugartec.it&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Registro delle Imprese di Milano - Codice Fiscale e P.I. n. 08885450968 - C.C.I.A.A. di Milano R.E.A. n. MI-2054939&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 14:40:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/242720#M832</guid>
      <dc:creator>Normadigital</dc:creator>
      <dc:date>2018-12-10T14:40:22Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive Removal Request: generic.ml</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/242753#M833</link>
      <description>&lt;P&gt;Hi Normadigital,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The VT scan is 18/67.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have submitted this sample to our malware team. I will update once I hear from them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Himani&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 19:42:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/242753#M833</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2018-12-10T19:42:05Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive Removal Request: generic.ml</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/242900#M834</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I heard from our team, the verdict for this file is changed to benign. This change is immediately&amp;nbsp;reflected in the WildFire and within 24-48 hours in our Anti Virus.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Himani&lt;/P&gt;</description>
      <pubDate>Tue, 11 Dec 2018 21:19:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-removal-request-generic-ml/m-p/242900#M834</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2018-12-11T21:19:33Z</dc:date>
    </item>
  </channel>
</rss>

