To prevent an MD5 that was detected as a false-positive event from being marked as malicious, use the file-analysis suppress command in enable mode.
This command prevents an MD5 checksum that was identified as a false-positive event from being marked as malicious. All malware records with a matching MD5 checksum will be marked as non-malicious.
For more information, see the File Protect User Guide.
Syntax
file-analysis suppress md5 <md5ID>
User role
Operator or Admin
Supported appliances
Command available in File Protect releases.
Parameters
md5ID
MD5 checksum to suppress.
Example
The following example suppresses the specified MD5 checksum. The output lists the IDs of the matching malware records.
hostname # file-analysis suppress md5 94978a14a9a3329b28a0735c8992d75a
Malware(s) {633,632,634,685,686,688,1246,1197,1198,1199,1248,1247,1230,1231,1232,1256,1257,1255,1265,1264,1266} suppressed for md5sum 94978a14a9a3329b28a0735c8992d75a