False-positive submission

Reply
Highlighted
L2 Linker

False-positive submission

Hi, Please find false-positive detection. VirusTotal link: https://www.virustotal.com/#/file/f40e85443f50cb78db68c343bc53d7fc30d05f6f4ac58ad59d492e7088478be5/d... SHA-256 f40e85443f50cb78db68c343bc53d7fc30d05f6f4ac58ad59d492e7088478be5 The file can be downloaded from: https://cdn4.hola.org/static/Hola-Setup-x64-1.108.133.exe Would appreciate your clearance of the false-positive detection ASAP and please verify that Hola Networks digital signature was added to trusted signer list, please see paloalto live community recent discussions. Thanks, Roi

Accepted Solutions
Highlighted
L5 Sessionator

In many of the cases it is the way you write your code.  In this file for instance, you have the file copies itself ,contacts unregistered dns server , Uses http direct ip connection, uses http with no ua ,uses http requests with short headers. Along with many other pieces that are common in malware.

View solution in original post


All Replies
Highlighted
L4 Transporter

Hello Roipaz,

 

We are looking at the possibility of the False positive on this case, I will update you when we are finished with our research.

 

Thanks

Himani

Himani Singh
Highlighted
L4 Transporter

Hi

 

The verdict for "f40e85443f50cb78db68c343bc53d7fc30d05f6f4ac58ad59d492e7088478be5"  is no longer listed as malicious. VirusTotal is been updated, the AntiVirus next release will have updated information.

 

Thanks

Himani

Himani Singh
Highlighted
L2 Linker

Thank you Haimani, When it will be a convenient time for you to have a short call to discuss how to prevent the repeating false-positive? Thanks, Roi
Highlighted
L5 Sessionator

Hello Roipaz,

 

We are not able to call or support non customers. 

I have checked with engineering and they declined to add your files to the trusted signer white list.

If you disagree with a verdict for a file, you will have to ask for evaluation on a file by file basis. 

 

Thank you

Don, Palo Alto Threat Specialist

Highlighted
L2 Linker

Hi Don, What cause the false-positive detection? Is there something we can do from our side to prevent such cases to happened so frequently? Thanks, Roi
Highlighted
L5 Sessionator

In many of the cases it is the way you write your code.  In this file for instance, you have the file copies itself ,contacts unregistered dns server , Uses http direct ip connection, uses http with no ua ,uses http requests with short headers. Along with many other pieces that are common in malware.

View solution in original post

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!