False Positive Detection Problem

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

False Positive Detection Problem

L1 Bithead


I represent a security software company, and our clients who use our software reported that their software was flagged as malware, but this result is a false positive. Can you please help us?


Virus total report: https://www.virustotal.com/gui/file/3ef991ee68c97dae9e757015104849a71e825571e4e0a047de80b90536392660...


Best Regards



L4 Transporter

Please review the pinned post and then provide the necessary information.


Thank you 

L1 Bithead


Please help us remove a false positive, given to "AOK_Desktop_itsc_prod.exe"
The program is clean and doesn't contain any unwanted behavior.


File Hash:3ef991ee68c97dae9e757015104849a71e825571e4e0a047de80b90536392660

Link to Virustotal report for the file:https://www.virustotal.com/gui/file/3ef991ee68c97dae9e757015104849a71e825571e4e0a047de80b90536392660...

Current VirustTotal Verdict: 0/70

Description:  Our customer saw this issue "Cortex XDR has blocked a harmful activity!"  -- "Description of the countermeasure: Suspicious executable detected"


We want to solve this problem as soon as possible. Thank you for your help.
Best regards

L1 Bithead

Hi @DaBone 

Are there any update for our customer issue?

Can we send our customer logs?  The logs are large and encrypted by Palo Alto. What else would you suggest to us to solve this problem?

Best Regards

If your customer is seeing this issue, then they should open a support case with TAC.  This is not the location for Palo Alto Networks customers to open interactions with TAC.  This forum is for non-customers to request file verdicts for review. 

  • 4 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!