Hello Wolfrene, PA is using a combination of the category of the URL, Known CVE IDs that may be associated with a domain. The Palo Alto content team constantly keeps monitoring and reevaluating the malicious or benign nature of such URLs. The best way to get a domain clean that has been categorized as Malware is to have a TAC case opened up with pcaps of the threat traffic ( this can be done by enabling pcap on the threat profile that triggered this threat log), screen shot of the threat log and the tech support file. The TAC will have this domain re-evaluated by the Content team and if changes are made to this threat signature then push the change with the next content release.
... View more