It appears to be because there is no associated filename, the vulnerability alert is for a FTP login attempt (not necessarily a successful login). Vulnerability threat IDs 58203 and 58216-58242 are for:
A FTP login attempt from a device was detected with a compromised password. A compromised password is a user credential that has been previously stolen, collected and used for unauthorized logins with an intention to perform a malicious act.
So the PaloAlto detected an attempt to log into a FTP server with a known compromised password and alerted (the exact passwords and criteria are not listed in the vulnerability, but I would guess it detected a known hardcoded backdoor password). As it was in the authentication stage of the FTP connection, there is no file name yet.
... View more