False-positive submission

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

False-positive submission

L2 Linker
Hi, Please find false-positive detection. VirusTotal link: https://www.virustotal.com/#/file/f40e85443f50cb78db68c343bc53d7fc30d05f6f4ac58ad59d492e7088478be5/d... SHA-256 f40e85443f50cb78db68c343bc53d7fc30d05f6f4ac58ad59d492e7088478be5 The file can be downloaded from: https://cdn4.hola.org/static/Hola-Setup-x64-1.108.133.exe Would appreciate your clearance of the false-positive detection ASAP and please verify that Hola Networks digital signature was added to trusted signer list, please see paloalto live community recent discussions. Thanks, Roi
1 accepted solution

Accepted Solutions

In many of the cases it is the way you write your code.  In this file for instance, you have the file copies itself ,contacts unregistered dns server , Uses http direct ip connection, uses http with no ua ,uses http requests with short headers. Along with many other pieces that are common in malware.

View solution in original post

6 REPLIES 6

L4 Transporter

Hello Roipaz,

 

We are looking at the possibility of the False positive on this case, I will update you when we are finished with our research.

 

Thanks

Himani

Himani Singh

L4 Transporter

Hi

 

The verdict for "f40e85443f50cb78db68c343bc53d7fc30d05f6f4ac58ad59d492e7088478be5"  is no longer listed as malicious. VirusTotal is been updated, the AntiVirus next release will have updated information.

 

Thanks

Himani

Himani Singh

Thank you Haimani, When it will be a convenient time for you to have a short call to discuss how to prevent the repeating false-positive? Thanks, Roi

Hello Roipaz,

 

We are not able to call or support non customers. 

I have checked with engineering and they declined to add your files to the trusted signer white list.

If you disagree with a verdict for a file, you will have to ask for evaluation on a file by file basis. 

 

Thank you

Don, Palo Alto Threat Specialist

Hi Don, What cause the false-positive detection? Is there something we can do from our side to prevent such cases to happened so frequently? Thanks, Roi

In many of the cases it is the way you write your code.  In this file for instance, you have the file copies itself ,contacts unregistered dns server , Uses http direct ip connection, uses http with no ua ,uses http requests with short headers. Along with many other pieces that are common in malware.

  • 1 accepted solution
  • 5023 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!