- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-30-2018 06:56 AM
10-02-2018 01:37 PM
In many of the cases it is the way you write your code. In this file for instance, you have the file copies itself ,contacts unregistered dns server , Uses http direct ip connection, uses http with no ua ,uses http requests with short headers. Along with many other pieces that are common in malware.
10-01-2018 02:00 PM
Hello Roipaz,
We are looking at the possibility of the False positive on this case, I will update you when we are finished with our research.
Thanks
Himani
10-02-2018 10:51 AM - edited 10-02-2018 11:42 AM
Hi
The verdict for "f40e85443f50cb78db68c343bc53d7fc30d05f6f4ac58ad59d492e7088478be5" is no longer listed as malicious. VirusTotal is been updated, the AntiVirus next release will have updated information.
Thanks
Himani
10-02-2018 11:04 AM
10-02-2018 11:48 AM - edited 10-02-2018 11:48 AM
Hello Roipaz,
We are not able to call or support non customers.
I have checked with engineering and they declined to add your files to the trusted signer white list.
If you disagree with a verdict for a file, you will have to ask for evaluation on a file by file basis.
Thank you
Don, Palo Alto Threat Specialist
10-02-2018 12:17 PM
10-02-2018 01:37 PM
In many of the cases it is the way you write your code. In this file for instance, you have the file copies itself ,contacts unregistered dns server , Uses http direct ip connection, uses http with no ua ,uses http requests with short headers. Along with many other pieces that are common in malware.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!