Reporting false positive for ArcSight Threat Intelligence on VirusTotal.com

Our pastebin, paste.c-net.org, is listed as "suspicious" on VirusTotal. ArcSight is the only engine that thinks this, while the rest agree we are clean.
How can we figure out what ArcSight is reacting to so we can regain an all "Clean" status?

All uploads to the pastebin are scanned using multiple AV engines, and re-scanned whenever updates are released for those engines.
That said, something can slip through the cracks, just as on DropBox, pastebin.com, or MegaUpload.

How can we fix this? How do we get in touch with the ArcSight Threat Intelligence team?
OpenText support close our cases without comment as we're not a customer.

  • 0  

    Hii Oyvind,

    i see those topics rising at the moment and i can only apologize. It seems something in the process between VT and OT is broken. We are investigating this and meanwhile i provided the URL from your post above to my research team.

    Hang on with me while the team is looking at it.

    I will post any updates here.

    MS

    Sr. Product Line Manager |  ArcSight Threat Intelligence
    OpenText Cybersecurity

  • Verified Answer

    +1  

    Hi Oyvind,

    i can confirm that your evaluation of paste.c-net.org has been corrected.

    Please let me know if it shows correctly on your end and tag/mark the threat here accordingly.

    Sorry for the inconvenience again and have a great day.
    MS

    Sr. Product Line Manager |  ArcSight Threat Intelligence
    OpenText Cybersecurity