False positive submission - Generic.ml - Trauma Zer0 Disclosure v5.5.1.5

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

False positive submission - Generic.ml - Trauma Zer0 Disclosure v5.5.1.5

L0 Member

Hello Palo Alto Networks Threat Research Team,

We are requesting a false-positive review and WildFire verdict reconsideration for a legitimate, digitally signed corporate application currently detected by Palo Alto Networks on VirusTotal as:

Generic.ml

File information:

File name: Agent_Win_Disclosure.exe
Product: Trauma Zer0
File version: 5.5.1.5
File size: 6,451,160 bytes
MD5: C55B8E88B91252FE41726B1214CC7D49
SHA-1: 0AD1040D55A837E53523D9DD2A76E1ECCBDECCA6
SHA-256: 619021DD50D72076EAE91D058AF7D04B3D8AE06AA624E449B5FAC45386F98B66

VirusTotal report:

https://www.virustotal.com/gui/file/619021dd50d72076eae91d058af7d04b3d8ae06aa624e449b5fac45386f98b66

Publisher and signature information:

Publisher: Ingite Consultoria Tecnologica Ltda
Brazilian company registration (CNPJ): 38.288.757/0001-03
Digital signature status: Valid
Certificate issuer: DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Certificate validity: July 4, 2026 to July 23, 2027
Trusted timestamp: Present

Trauma Zer0 is a legitimate Brazilian corporate endpoint-management platform deployed and managed by authorized customer IT administrators.

Its documented functions include:

  • Hardware and software asset inventory

  • Endpoint security and policy enforcement

  • Productivity auditing

  • Secure remote administration

  • Software distribution

  • Operational auditing

  • Digital forensic investigation

The application’s monitoring, persistence, Windows API integration, telemetry collection, auditing, and self-protection capabilities are intentional product features required for authorized corporate use.

After installation, the application creates these expected processes:

  • Awtask.exe — protection and security component

  • Wwtask.exe — endpoint monitoring component

It also uses:

C:\Windows\networkclient

The same SHA-256 may appear in external analysis services under the name “wwtask.exe”. The original file analyzed by us is named “Agent_Win_Disclosure.exe”; it is the signed installer responsible for deploying the expected Trauma Zer0 components.

Official product documentation:

https://www.traumazero.com/en/products/

We believe the Generic.ml verdict is an incorrect machine-learning classification caused by legitimate endpoint-monitoring and administration capabilities.

We respectfully request:

  1. Manual review of SHA-256 619021DD50D72076EAE91D058AF7D04B3D8AE06AA624E449B5FAC45386F98B66;

  2. Reconsideration of the WildFire verdict;

  3. Reclassification of the file as benign;

  4. Removal of the associated Generic.ml detection;

  5. Confirmation when the corrected verdict is propagated to WildFire and VirusTotal.

We can provide the original signed installer, certificate-chain information, installed Awtask.exe and Wwtask.exe components, installation logs, or technical architecture documentation if required.

We do not currently have access to a licensed WildFire customer portal, so we are requesting assistance through the LIVEcommunity VirusTotal section.

Thank you for your assistance.

Best regards,

André Rodzinski
Trauma Zer0
https://www.traumazero.com/

0 REPLIES 0
  • 14 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!