All alerts that have iv_alert.alertType = 7 are File Reputation alerts. The iv_alert_data.typeSpecific data has the following format.
Note
The port-type mapping bit is not currently used but allocated for future use.
The details of the alert are as follows:
| Number of bytes | Value |
|---|---|
| Variable | Port type |
| Variable | Malware classification |
| Variable | The level of malicious content in the file |
| Variable | File type |
| Variable | MD5 hash value of the file |
The following table describes file type mapping.
| Value | File type |
|---|---|
| 1 | exe |
| 2 | dll |
| 3 | cpl |
| 4 | ocx |
| 5 | sys |
| 6 | scr |
| 7 | drv |
| 8 | com |
| 9 | doc |
| 10 | docx |
| 11 | ppt |
| 12 | pptx |
| 13 | xls |
| 14 | xlsx |
| 15 |
The following table describes dirtiness level mapping.
| Value | Dirtiness level |
|---|---|
| 0 | Not applicable |
| 2 | Hash denotes a heuristic score less than 10 |
| 4 | Hash denotes a heuristic score between 10 and 39 |
| 8 | Hash denotes a heuristic score between 40 and 74 |
| 16 | Hash denotes a heuristic score between 75 and 100 |
| 32 | Hash denotes a heuristic score above 100 |
| 64 | Hash is assumed clean |
The following table describes classification mapping.
| Value | Classification |
|---|---|
| 0 | No classification |
| 2 | Application |
| 4 | Virus |
| 8 | Trojan |
| 16 | Application |