Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

False Positive

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

False Positive

L0 Member
22 REPLIES 22

Hi @DmitryGR ,

 

This is community forum, although there are a lot of Palo Alto employees here. I would expect to much visibility for your request.

 

If you have active Palo Alto customer support account you can follow the process of submitting a false positive

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClSBCA0

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm3aCAC

L5 Sessionator

Here's another knowledge base article. The false positive is due to the incorrect WildFire verdict.


- WildFire report incorrect verdict (virus false positive or false negative)
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm7KCAS

 

I submitted the verdict change request on behalf.

L1 Bithead

Hello Palo Alto ,

 

Please fix false positive detection: 

spdt.exe (MaxSecure, NANO-Antivirus)
Virus Total Scanning Result: https://www.virustotal.com/gui/file/4c7f8799057351033bbe782cb065b5dfeec2762afccfbb7645380913eaa3a934
File Download link: https://www.sendspace.com/file/ow4rdb

Thanks!

Hi ITopVPN,

 

As you can see on VirusTotal, Palo Alto Networks shows it as "Undetected" e.g. WildFire verdict is benign.
MaxSecure, NANO-Antivirus are other security companies. 😉

L1 Bithead

Hello Ymiyashita,

Thanks for your reply. 

Sorry, I have submitted the wrong information. Please check this one:

InfoHelp.dll (Palo Alto Networks)
Virus Total Scanning Result: https://www.virustotal.com/gui/file/658f466839bc9c6b5ed38ec2710108d7bc2335e252a47d578e14390b2315d3a2
File Download link: https://www.sendspace.com/file/jg5wup

Thanks for your help.

L5 Sessionator

Hi ITopVPN,

 

Sorry for my late response. Somehow I got the email notification today.

 

The verdict of the sample was already fixed on July 2 PDT. It's benign now.
https://threatvault.paloaltonetworks.com/?query=658f466839bc9c6b5ed38ec2710108d7bc2335e252a47d578e14...

L1 Bithead

Hello Palo Alto ,

 

Please fix false positive detection: 

Virus Total Scanning Result: https://www.virustotal.com/gui/file/8783ba0cceaa8b80547f906fc6b3f6a3af07cf4a87832b26c5c75bc5b13b5ebe
File Download link: https://www.dropbox.com/s/ewj516lansfkrgk/Paloalto.zip?dl=1

 

Thanks!

L5 Sessionator

The verdict change request can be submitted on the WildFire portal.

 

Reference:
- WildFire report incorrect verdict (virus false positive or false negative)
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm7KCAS

 

I submitted it on behalf.

L1 Bithead

Hello Ymiyashita,

Our product installation file and the download link have been flagged as threat again. The download link and VirusTotal report are listed below:

Product installation file: https://download.itopvpn.com/ installer/iTopVPN_setup_Free. exe
VirusTotal report: https://www.virustotal.com/gui/file/75baa00ec0da5b086bdd2408e4fbd7ea81c32d0e1f50af97699227ba08796a85

 

Please kindly fix it.


I'm looking forward to hearing back from you.

L1 Bithead

Hello Palo Alto,

Please fix false positive detection: 

Virus Total Scanning Result: https://www.virustotal.com/gui/file/75baa00ec0da5b086bdd2408e4fbd7ea81c32d0e1f50af97699227ba08796a85
File Download link:  https://download.itopvpn.com/installer/iTopVPN_setup_Free.exe

Thanks!

Hello, our file is getting false flagged by your engine too. I couldn’t reach you via email so I found this. VT: https://www.virustotal.com/gui/file/eb3ccf806ced05f5048be6530aa0c3276a0f217d9fd5240ac180b2c48bc9ff84... and downloadable via: https://verify.timeless-ac.com/download/Timeless.exe

best regards

Hi @bysadex

Please kindly open a support case.

  • 17414 Views
  • 22 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!