<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic wildfire findings into the pan-db in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-findings-into-the-pan-db/m-p/29215#M21368</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;today a user tried to download a wallpaper from www.wallsave.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wildfire says it is &lt;SPAN class="label-important label"&gt;Malware.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="label-important label"&gt;&lt;A href="https://wildfire.paloaltonetworks.com/wildfire/reportdetail/2d6540e44f081882b611e1ed702e8f0032d309f0311ae0232f9a9a8da082e306/422433975/2" title="https://wildfire.paloaltonetworks.com/wildfire/reportdetail/2d6540e44f081882b611e1ed702e8f0032d309f0311ae0232f9a9a8da082e306/422433975/2"&gt;https://wildfire.paloaltonetworks.com/wildfire/reportdetail/2d6540e44f081882b611e1ed702e8f0032d309f0311ae0232f9a9a8da082e306/422433975/2&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="label-important label"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="label-important label"&gt;A few engines from virustotal also:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/de/url/59e5f7d67a03d71946dd6b617c1ff130aec6b6b4178519ad9d77cc076b5c7a17/analysis/1403173699/" title="https://www.virustotal.com/de/url/59e5f7d67a03d71946dd6b617c1ff130aec6b6b4178519ad9d77cc076b5c7a17/analysis/1403173699/"&gt;https://www.virustotal.com/de/url/59e5f7d67a03d71946dd6b617c1ff130aec6b6b4178519ad9d77cc076b5c7a17/analysis/1403173699/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;(www.wallsave.com/get/2588352)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my question is: why or when is this site marked as malware in the pan-db cloud?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;actual:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;test url-info-cloud &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.wallsave.com/" rel="nofollow"&gt;http://www.wallsave.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;BM:&lt;/P&gt;&lt;P&gt;wallsave.com,9,3,&lt;STRONG&gt;shareware-and-freeware&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Sebastian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 19 Jun 2014 11:15:02 GMT</pubDate>
    <dc:creator>sebastian</dc:creator>
    <dc:date>2014-06-19T11:15:02Z</dc:date>
    <item>
      <title>wildfire findings into the pan-db</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-findings-into-the-pan-db/m-p/29215#M21368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;today a user tried to download a wallpaper from www.wallsave.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wildfire says it is &lt;SPAN class="label-important label"&gt;Malware.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="label-important label"&gt;&lt;A href="https://wildfire.paloaltonetworks.com/wildfire/reportdetail/2d6540e44f081882b611e1ed702e8f0032d309f0311ae0232f9a9a8da082e306/422433975/2" title="https://wildfire.paloaltonetworks.com/wildfire/reportdetail/2d6540e44f081882b611e1ed702e8f0032d309f0311ae0232f9a9a8da082e306/422433975/2"&gt;https://wildfire.paloaltonetworks.com/wildfire/reportdetail/2d6540e44f081882b611e1ed702e8f0032d309f0311ae0232f9a9a8da082e306/422433975/2&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="label-important label"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="label-important label"&gt;A few engines from virustotal also:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/de/url/59e5f7d67a03d71946dd6b617c1ff130aec6b6b4178519ad9d77cc076b5c7a17/analysis/1403173699/" title="https://www.virustotal.com/de/url/59e5f7d67a03d71946dd6b617c1ff130aec6b6b4178519ad9d77cc076b5c7a17/analysis/1403173699/"&gt;https://www.virustotal.com/de/url/59e5f7d67a03d71946dd6b617c1ff130aec6b6b4178519ad9d77cc076b5c7a17/analysis/1403173699/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;(www.wallsave.com/get/2588352)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my question is: why or when is this site marked as malware in the pan-db cloud?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;actual:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;test url-info-cloud &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.wallsave.com/" rel="nofollow"&gt;http://www.wallsave.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;BM:&lt;/P&gt;&lt;P&gt;wallsave.com,9,3,&lt;STRONG&gt;shareware-and-freeware&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Sebastian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jun 2014 11:15:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-findings-into-the-pan-db/m-p/29215#M21368</guid>
      <dc:creator>sebastian</dc:creator>
      <dc:date>2014-06-19T11:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: wildfire findings into the pan-db</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-findings-into-the-pan-db/m-p/29216#M21369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think the URL reputation is malware and malicious site . which version of wildfire you are using .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jun 2014 11:33:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-findings-into-the-pan-db/m-p/29216#M21369</guid>
      <dc:creator>tiwara</dc:creator>
      <dc:date>2014-06-19T11:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: wildfire findings into the pan-db</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-findings-into-the-pan-db/m-p/29217#M21370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Now it's getting funny.&lt;BR /&gt;Can please someone explain that to me?&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Tahoma','sans-serif';"&gt;That's my response to my change request for that malware site.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Tahoma','sans-serif';"&gt;---&lt;BR style="font-size: 10.0pt; font-family: 'Tahoma','sans-serif';" /&gt;&lt;STRONG&gt;SUBJECT:&lt;/STRONG&gt; Change request processed for: www.wallsave.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you once again for your submission. After careful evaluation, we have determined that the original categorization is correct, and as such, its category will not change.&lt;BR /&gt; &lt;BR /&gt; URL: &lt;A href="http://www.wallsave.com/"&gt;www.wallsave.com&lt;/A&gt;&lt;BR /&gt; Current category: shareware-and-freeware&lt;BR /&gt; You suggested: malware&lt;BR /&gt; If you'd like to submit another request, please visit:&lt;BR /&gt; &lt;A href="http://urlfiltering.paloaltonetworks.com/testASite.aspx"&gt;http://urlfiltering.paloaltonetworks.com/testASite.aspx&lt;/A&gt;&lt;BR /&gt; &lt;BR /&gt; Thanks,&lt;BR /&gt; Palo Alto Networks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jun 2014 05:42:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-findings-into-the-pan-db/m-p/29217#M21370</guid>
      <dc:creator>sebastian</dc:creator>
      <dc:date>2014-06-20T05:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: wildfire findings into the pan-db</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wildfire-findings-into-the-pan-db/m-p/29218#M21371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sebastian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generally speaking, if WildFire has identified a downloaded file as malicious, the corresponding domain should also be categorized by PAN-DB as malware.&amp;nbsp; There are a few exceptions to this, so I'm looking into the reason for your case.&amp;nbsp; I'll report back as soon as I get more information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Doris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jun 2014 06:49:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wildfire-findings-into-the-pan-db/m-p/29218#M21371</guid>
      <dc:creator>dyang</dc:creator>
      <dc:date>2014-06-20T06:49:05Z</dc:date>
    </item>
  </channel>
</rss>

