Woah, talk about burying the lede? This sentence makes it sound like their private key was compromised, in which case it makes total sense to revoke the cert. Unless I'm misunderstanding what they're trying to say here.
Woah, talk about burying the lede? This sentence makes it sound like their private key was compromised, in which case it makes total sense to revoke the cert. Unless I'm misunderstanding what they're trying to say here.
I doubt the CA would lie about the existence of such a file, although perhaps they are mistaken about the signature (it could be a case of a 570 MB file concatenated with a legitimately signed winrar executable - signatures don't always cover all parts of the file)
I don't think virustotal accepts files larger than 500 MB.
1. VT has an upload limit of 128 MB. (Maybe the private API allows more, not sure.)
2. VT allows sample download if you have a VT Intelligence account - so if this was a file shared with VT, the CA should be able to provide the file.