Details:Occasionally a file sample will be needed in order to further investigate support requests on:
- False positives (FP)
- False negatives (FN)
- General questions on detection coverage
This article provides a guideline for customers to safely handle a potentially malicious file sample before uploading it to the VMware Support Request.
Steps:
- If the file is publicly available, do not send the file on the Support Request. Search for the hash on www.virustotal.com (VT):
- If the hash is known to VT, a sample can be downloaded by VMware Technical Support. If available on VT, provide the support engineer the file hash details on the Support Request and skip steps 2-3
- Put the file in question in an encrypted ZIP archive with the password "infected" - any other password you prefer can also be used, but please share it with the support engineer
- Upload the password-protected archive to the Support Request
- In the Support Request, please provide additional details on your FP/FN assessment or threat issue.
Important:
Do not upload any malicious files without taking the above steps