<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PAN-DB Re-Categorization Requests in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-db-re-categorization-requests/m-p/64788#M38775</link>
    <description>&lt;P&gt;Just curious what everyone's expereince / success has been when trying to get URLs re-categorized, especially malicious domains?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't seem to have much luck instilling a sense of urgency with support on these requests.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I submitted a support case for a domain on a domain on the 10th that we see phishing/credential harvesting and I've still got no action from support (on a Case I submitted as a high).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anything I could do to get better results? &amp;nbsp;I'd think Palo Alto, for all intents and purposes, a network defense company would have more timely reponses to these requests.&lt;/P&gt;</description>
    <pubDate>Fri, 18 Sep 2015 13:09:17 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2015-09-18T13:09:17Z</dc:date>
    <item>
      <title>PAN-DB Re-Categorization Requests</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-db-re-categorization-requests/m-p/64788#M38775</link>
      <description>&lt;P&gt;Just curious what everyone's expereince / success has been when trying to get URLs re-categorized, especially malicious domains?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't seem to have much luck instilling a sense of urgency with support on these requests.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I submitted a support case for a domain on a domain on the 10th that we see phishing/credential harvesting and I've still got no action from support (on a Case I submitted as a high).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anything I could do to get better results? &amp;nbsp;I'd think Palo Alto, for all intents and purposes, a network defense company would have more timely reponses to these requests.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2015 13:09:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-db-re-categorization-requests/m-p/64788#M38775</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-09-18T13:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-DB Re-Categorization Requests</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-db-re-categorization-requests/m-p/64789#M38776</link>
      <description>&lt;P&gt;I should add, it was categorized as unkown and got categorized as "real-estate" prior to the 10th, which precipitated the support request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We submitted the inital one as phishing, to which Palo's categorization was "real-estate."&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2015 13:11:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-db-re-categorization-requests/m-p/64789#M38776</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-09-18T13:11:28Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-DB Re-Categorization Requests</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-db-re-categorization-requests/m-p/64791#M38777</link>
      <description>&lt;P&gt;Hi Brandon&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you try submitting the URL through&amp;nbsp;&lt;A href="https://urlfiltering.paloaltonetworks.com/" target="_blank"&gt;https://urlfiltering.paloaltonetworks.com/&lt;/A&gt; ?&lt;/P&gt;
&lt;P&gt;This should trigger an direct request with the URL DB team to verify a url manually.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2015 13:15:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-db-re-categorization-requests/m-p/64791#M38777</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-09-18T13:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-DB Re-Categorization Requests</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-db-re-categorization-requests/m-p/64792#M38778</link>
      <description>&lt;P&gt;So far I only had a couple of requests for sites that were marked as malware to be re-evaluated. And PA were really quick to check and change to some safe category.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2015 13:18:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-db-re-categorization-requests/m-p/64792#M38778</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2015-09-18T13:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-DB Re-Categorization Requests</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-db-re-categorization-requests/m-p/64795#M38780</link>
      <description>&lt;P&gt;Yes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We do the initial "automated process" either through URL logs or direct on the site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can recount at least 5 times where people at my company "suggest" a site as "malware" or "phishing" only to have the canned response thanks but no thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So we submit an case, which is what I did in this instance as well. &amp;nbsp;We're now going on 8 days with no resolution for the case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This screen shot was included in the support case...How is this not an automatic action...Tip...I don't work for "swlacomps.com" they shouldn't be asking my users to put their credentials in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/386iD44C1C5FC6F78C21/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Phishing.JPG" title="Phishing.JPG" /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2015 13:28:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-db-re-categorization-requests/m-p/64795#M38780</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-09-18T13:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-DB Re-Categorization Requests</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-db-re-categorization-requests/m-p/64796#M38781</link>
      <description>&lt;P&gt;I had a problem convincing PA a certain file to be malware. The file in question is&amp;nbsp;IZArc_Setup.exe with SHA-256 hash&amp;nbsp;4d5882c57875b86cd6095e3bf2c64785cb878fd9d836d2091c9585198e2b4c75&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;15/55 AV vendors on VirusTotal recognise it as virus. (&lt;A href="https://www.virustotal.com/en/file/4d5882c57875b86cd6095e3bf2c64785cb878fd9d836d2091c9585198e2b4c75/analysis/)" target="_blank"&gt;https://www.virustotal.com/en/file/4d5882c57875b86cd6095e3bf2c64785cb878fd9d836d2091c9585198e2b4c75/analysis/)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It&amp;nbsp;downloads&amp;nbsp;a file (SHA256: ffaf52d2f7c34df344c21a532a52711dbebcbb77a5e00b8aad46d6c247ed8718) from a domain which is marked as malware domain by PA DB and BrightCloud (sub.dunhiri.com/installers/bi_downloader/1433912751207/setup.exe).&lt;/P&gt;&lt;P&gt;The file it downloads is marked as benign by WF portal, but &amp;nbsp;26/56 AV vendors according to VirusTotal mark it as virus (&lt;A href="https://www.virustotal.com/en/file/ffaf52d2f7c34df344c21a532a52711dbebcbb77a5e00b8aad46d6c247ed8718/analysis/)" target="_blank"&gt;https://www.virustotal.com/en/file/ffaf52d2f7c34df344c21a532a52711dbebcbb77a5e00b8aad46d6c247ed8718/analysis/)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to change verdict for this 3 times but I was never succesful. So yeah it's a mission to convince PA some file is actually malware. A bit dissapointing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2015 13:46:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-db-re-categorization-requests/m-p/64796#M38781</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2015-09-18T13:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-DB Re-Categorization Requests</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-db-re-categorization-requests/m-p/64892#M38824</link>
      <description>&lt;P&gt;Going on 11 days now...Still no action in the categorization request.&lt;BR /&gt;&lt;BR /&gt;Geeze I sure hope no other companies user credentials have been stolen in this time.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2015 18:50:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-db-re-categorization-requests/m-p/64892#M38824</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-09-21T18:50:36Z</dc:date>
    </item>
  </channel>
</rss>

