<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic URLs of Google and Microsoft (windowsupdate.com and gvt1.com) in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/URLs-of-Google-and-Microsoft-windowsupdate-com-and-gvt1-com/m-p/112220#M21127</link>
    <description>&lt;P&gt;Hello team,&lt;/P&gt;&lt;P&gt;We are facing an issue with Threat Emulation which detected URLs belong to Google and Microsoft (windowsupdate.com and gvt1.com) that checkpoint classified it as&amp;nbsp;malicious or threat. Why Checkpoint&amp;nbsp;detect it as malicious or a threat? Please kindly help us to resolve this issue.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Threat Emulation - Microsoft URL" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10720iF51CCE2062DB1A6B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MicrosoftTeams-image.png" alt="Threat Emulation - Microsoft URL" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Threat Emulation - Microsoft URL&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;Ravoth&lt;/P&gt;</description>
    <pubDate>Tue, 02 Mar 2021 03:00:07 GMT</pubDate>
    <dc:creator>Ravoth</dc:creator>
    <dc:date>2021-03-02T03:00:07Z</dc:date>
    <item>
      <title>URLs of Google and Microsoft (windowsupdate.com and gvt1.com)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/URLs-of-Google-and-Microsoft-windowsupdate-com-and-gvt1-com/m-p/112220#M21127</link>
      <description>&lt;P&gt;Hello team,&lt;/P&gt;&lt;P&gt;We are facing an issue with Threat Emulation which detected URLs belong to Google and Microsoft (windowsupdate.com and gvt1.com) that checkpoint classified it as&amp;nbsp;malicious or threat. Why Checkpoint&amp;nbsp;detect it as malicious or a threat? Please kindly help us to resolve this issue.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Threat Emulation - Microsoft URL" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10720iF51CCE2062DB1A6B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MicrosoftTeams-image.png" alt="Threat Emulation - Microsoft URL" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Threat Emulation - Microsoft URL&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;Ravoth&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 03:00:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/URLs-of-Google-and-Microsoft-windowsupdate-com-and-gvt1-com/m-p/112220#M21127</guid>
      <dc:creator>Ravoth</dc:creator>
      <dc:date>2021-03-02T03:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: URLs of Google and Microsoft (windowsupdate.com and gvt1.com)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/URLs-of-Google-and-Microsoft-windowsupdate-com-and-gvt1-com/m-p/112322#M21145</link>
      <description>&lt;P&gt;In that log message, it says the file that was downloaded was a forbidden type.&lt;BR /&gt;Has nothing to do with where it came from.&lt;BR /&gt;You should be able to just the Threat Prevention profile accordingly to allow it or add an exception.&lt;BR /&gt;Do you have other examples?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 22:02:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/URLs-of-Google-and-Microsoft-windowsupdate-com-and-gvt1-com/m-p/112322#M21145</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-02T22:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: URLs of Google and Microsoft (windowsupdate.com and gvt1.com)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/URLs-of-Google-and-Microsoft-windowsupdate-com-and-gvt1-com/m-p/112332#M21146</link>
      <description>&lt;DIV&gt;Dear &lt;SPAN&gt;PhoneBoy&lt;/SPAN&gt;,&lt;BR /&gt;First of all, we would like to know whether the domain/URL is belong to Microsoft and Google or not. If it really belongs to them why checkpoint detected it as malicious or threat or is it really malicious? Please advise us what we can do to not let checkpoint detected as malicious if it is the legit file. We have checked the domain on whois and X-force Exchange, it says belongs to Microsoft and Google.&lt;BR /&gt;&lt;BR /&gt;Thank you!&lt;BR /&gt;This is an example of a Google update and Windows Update.&lt;/DIV&gt;&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Google Update - Redirected" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10729i022937C63B9047EE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Redirect.PNG" alt="Google Update - Redirected" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Google Update - Redirected&lt;/span&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Threat Emulation - Windows Updated" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10730i4439F363DC9AB557/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Threat Emulation.png" alt="Threat Emulation - Windows Updated" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Threat Emulation - Windows Updated&lt;/span&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 03 Mar 2021 03:01:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/URLs-of-Google-and-Microsoft-windowsupdate-com-and-gvt1-com/m-p/112332#M21146</guid>
      <dc:creator>Ravoth</dc:creator>
      <dc:date>2021-03-03T03:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: URLs of Google and Microsoft (windowsupdate.com and gvt1.com)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/URLs-of-Google-and-Microsoft-windowsupdate-com-and-gvt1-com/m-p/112340#M21147</link>
      <description>&lt;P&gt;I assume Google and Microsoft respectively own the domains because that's what their WHOIS records say.&lt;/P&gt;
&lt;P&gt;The Google update&amp;nbsp;has nothing to do with where it came from, but your Threat Prevention profile, as I said with the previous example.&lt;BR /&gt;You probably have a rule blocking .EXE files and that message is consistent with that.&lt;/P&gt;
&lt;P&gt;The Microsoft update is probably a false positive.&lt;BR /&gt;You can work around it with an exception, but I recommend engaging with the TAC.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 04:41:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/URLs-of-Google-and-Microsoft-windowsupdate-com-and-gvt1-com/m-p/112340#M21147</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-03T04:41:01Z</dc:date>
    </item>
  </channel>
</rss>

