Allowing ms-update on app-default, File blocking PE and therefore no windows updates

New PAN implementation and blocking per PA best practice (PE, multi-level, etc..) and allowing ms-update on application default.  However the WSUS server is not able to download any updates and its classifying a PE file as a threat.  The file in question is am_delta_patch_1.249.1313.0_52b04aae0eb450654fc89884b43d10b7ed5 and threat-id is 52060 but nothing matches in the Threat Vault.  


Do I need a specific rule allowing windows updates that allows PE files?  



