<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: possible to know what triggered malicious website classification on my website? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/possible-to-know-what-triggered-malicious-website-classification/m-p/574668#M115495</link>
    <description>&lt;P&gt;I had similar problems when I used unverified online gambling sites. However, everything changed after I read this review &lt;A href="https://topcasinosreviews.in/minimum-deposit-casinos/" target="_blank"&gt;https://topcasinosreviews.in/minimum-deposit-casinos/&lt;/A&gt; about an online casino that offers excellent terms of use. I liked that on this gaming platform you can start with a minimum deposit, and this significantly reduces the risk of losing a large amount of personal funds. I believe that the immersive experience and evolving technology make it more than just a pastime; it is a modern form of entertainment.&lt;/P&gt;</description>
    <pubDate>Wed, 31 Jan 2024 09:43:47 GMT</pubDate>
    <dc:creator>Sunnyprot</dc:creator>
    <dc:date>2024-01-31T09:43:47Z</dc:date>
    <item>
      <title>possible to know what triggered malicious website classification on my website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-to-know-what-triggered-malicious-website-classification/m-p/535625#M110169</link>
      <description>&lt;P&gt;I run a small website&amp;nbsp;(&lt;A href="http://www.milkywayidle.com" target="_blank"&gt;www.milkywayidle.com&lt;/A&gt;)&amp;nbsp;which is an online game ran directly in the browser. after a few recent updates around 2-3 weeks ago, I saw noticed that &lt;A href="https://urlfiltering.paloaltonetworks.com/query/" target="_blank"&gt;https://urlfiltering.paloaltonetworks.com/query/&lt;/A&gt;&amp;nbsp;classified my website as malicious. I requested reclassify and it quickly classified to "game". However around the same time many users complained about their ISP (Spectrum, Xfinity) security shield which is part of the router their ISP provided them also started classifying my website as malicious and blocked them from access. I'm able to contact them and it gets temporarily whitelisted, but every time I make an update (even tiny updates) to the website, it gets blocked again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I looked at a lot of other website scanners/classifiers online and nothing else classified my website as malicious. I'm wondering if it's possible to learn what triggered the malicious content classification from PAN since it could be related to the ISP false positives as well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 01:32:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-to-know-what-triggered-malicious-website-classification/m-p/535625#M110169</guid>
      <dc:creator>chezedude</dc:creator>
      <dc:date>2023-03-24T01:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: possible to know what triggered malicious website classification on my website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-to-know-what-triggered-malicious-website-classification/m-p/535646#M110172</link>
      <description>&lt;P&gt;Maybe ask again why Palo Alto is doing this by using the webform for reclassify as they should send you email update.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From checking your site with the link below I see that your site is new and maybe this adds to Palo Alto and other systems monitoring for changes. Also your SSL cer is not organization verified just domain verified, so maybe increase the SSL security and it could get better clasification.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nikoolayy1_0-1679641440015.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48996iE7061373C744B545/image-size/medium?v=v2&amp;amp;px=400" role="button" title="nikoolayy1_0-1679641440015.png" alt="nikoolayy1_0-1679641440015.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also there is some data that you may like to hide as I see that you have a "Server" response header and this better be removed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is what I can tell as maybe other people have better ideas.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sitereport.netcraft.com/?url=https://www.milkywayidle.com" target="_blank" rel="noopener"&gt;https://sitereport.netcraft.com/?url=https://www.milkywayidle.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also in AWS you can add also a WAF product before your site as maybe if Palo Alto sees some vunrablity maybe from the &lt;A href="https://www.exploit-db.com/google-hacking-database" target="_blank"&gt;https://www.exploit-db.com/google-hacking-database&lt;/A&gt; it will not like it. You can scan your site with &lt;A href="https://www.qualys.com/free-services/" target="_blank"&gt;https://www.qualys.com/free-services/&lt;/A&gt; as they have a free web scanner community edition that may give you some ideas.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is interesting what bad category was your site added to as this may provide extra info.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 07:13:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-to-know-what-triggered-malicious-website-classification/m-p/535646#M110172</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-03-24T07:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: possible to know what triggered malicious website classification on my website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-to-know-what-triggered-malicious-website-classification/m-p/535650#M110174</link>
      <description>&lt;P&gt;Thanks for the suggestions. I will try some of these and see if it will help. I actually asked about it in the additional notes for reclassify, but all I got back is a generic response that it did get reclassified.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The main thing that is odd is that the site was fine for over half a year without any of these issues. The only significant change I made 2-3 weeks ago was combining all of my website SVG assets into a number of sprite files (which seems fairly benign in terms of security concerns). Nothing in terms of SSL or server responses were changed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I added images for the classification results from before, but it doesn't give too much detail.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chezedude_1-1679642947154.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48998iD73144CDEC1AD00E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="chezedude_1-1679642947154.png" alt="chezedude_1-1679642947154.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chezedude_0-1679642895964.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48997i1319865ABC3156CE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="chezedude_0-1679642895964.png" alt="chezedude_0-1679642895964.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 07:29:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-to-know-what-triggered-malicious-website-classification/m-p/535650#M110174</guid>
      <dc:creator>chezedude</dc:creator>
      <dc:date>2023-03-24T07:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: possible to know what triggered malicious website classification on my website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-to-know-what-triggered-malicious-website-classification/m-p/535652#M110176</link>
      <description>&lt;P&gt;Strange your SSL cert says "Not valid before 21.02.2023", so for me this suggests it is a new ssl cert but you say that you did not renew it. Maybe it was autorenewed and this could have caused the issue.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 07:56:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-to-know-what-triggered-malicious-website-classification/m-p/535652#M110176</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-03-24T07:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: possible to know what triggered malicious website classification on my website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-to-know-what-triggered-malicious-website-classification/m-p/535900#M110179</link>
      <description>&lt;P&gt;I originally created the certificate sept 25 2021 on AWS certificate manager. I did not manually renew it, so I guess AWS did auto renew it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you suggesting that there could be issues simply because the SSL cert is new? or that there may have been some problem with the renewed SSL itself?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 09:21:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-to-know-what-triggered-malicious-website-classification/m-p/535900#M110179</guid>
      <dc:creator>chezedude</dc:creator>
      <dc:date>2023-03-24T09:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: possible to know what triggered malicious website classification on my website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-to-know-what-triggered-malicious-website-classification/m-p/535986#M110180</link>
      <description>&lt;P&gt;Can't give 100% that this caused the issue but many ML engines will monitor such a thing when evaluating sites. Maybe the SSL change lowered the score then your file change may have lowered it even more.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Other than that if you have a licensed palo alto firewall you can ask a user to access your site and have a security rule for that user by matching source user or ip address and see if the palo alto wildfire/antivirus/vunrability profiles will block you when accessing the modified files as they may trigger a bad false positive signature and then you may submit to &lt;A href="https://live.paloaltonetworks.com/t5/virustotal/bd-p/VirusTotal_Discussions" target="_blank"&gt;https://live.paloaltonetworks.com/t5/virustotal/bd-p/VirusTotal_Discussions&lt;/A&gt; the false positive. If a user was blocked by the security profiles and the palo alto firewall was providing telemetry to the Palo Alto cloud , this could explain why palo alto marked the website as "Malware" that suggests that the modified files triggered antivirus or wildfire protections for files. Also configure the Palo Alto antivirus and wildfire profiles to scan your sprite file types &lt;STRONG&gt;(&lt;A href="https://docs.paloaltonetworks.com/wildfire/10-2/wildfire-admin/wildfire-overview/wildfire-file-type-support" target="_blank"&gt;https://docs.paloaltonetworks.com/wildfire/10-2/wildfire-admin/wildfire-overview/wildfire-file-type-support&lt;/A&gt; ).&lt;/STRONG&gt; Palo Alto may have already fixed this with the latest content updates for antivirus signatures, so keep that in mind.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is what I can provide you as input for this issue.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 09:41:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-to-know-what-triggered-malicious-website-classification/m-p/535986#M110180</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-03-24T09:41:04Z</dc:date>
    </item>
    <item>
      <title>Re: possible to know what triggered malicious website classification on my website?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-to-know-what-triggered-malicious-website-classification/m-p/574668#M115495</link>
      <description>&lt;P&gt;I had similar problems when I used unverified online gambling sites. However, everything changed after I read this review &lt;A href="https://topcasinosreviews.in/minimum-deposit-casinos/" target="_blank"&gt;https://topcasinosreviews.in/minimum-deposit-casinos/&lt;/A&gt; about an online casino that offers excellent terms of use. I liked that on this gaming platform you can start with a minimum deposit, and this significantly reduces the risk of losing a large amount of personal funds. I believe that the immersive experience and evolving technology make it more than just a pastime; it is a modern form of entertainment.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 09:43:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-to-know-what-triggered-malicious-website-classification/m-p/574668#M115495</guid>
      <dc:creator>Sunnyprot</dc:creator>
      <dc:date>2024-01-31T09:43:47Z</dc:date>
    </item>
  </channel>
</rss>

