All alerts that have iv_alert.alertType = 7 are File Reputation alerts. The iv_alert_data.typeSpecific data has the following format.
.png)
Note
The port-type mapping bit is not currently used but allocated for future use.
The details of the alert are as follows:
Number of bytes | Value |
|---|---|
Variable | Port type |
Variable | Malware classification |
Variable | The level of malicious content in the file |
Variable | File type |
Variable | MD5 hash value of the file |
The following table describes file type mapping.
Value | File type |
|---|---|
1 | exe |
2 | dll |
3 | cpl |
4 | ocx |
5 | sys |
6 | scr |
7 | drv |
8 | com |
9 | doc |
10 | docx |
11 | ppt |
12 | pptx |
13 | xls |
14 | xlsx |
15 |
The following table describes dirtiness level mapping.
Value | Dirtiness level |
|---|---|
0 | Not applicable |
2 | Hash denotes a heuristic score less than 10 |
4 | Hash denotes a heuristic score between 10 and 39 |
8 | Hash denotes a heuristic score between 40 and 74 |
16 | Hash denotes a heuristic score between 75 and 100 |
32 | Hash denotes a heuristic score above 100 |
64 | Hash is assumed clean |
The following table describes classification mapping.
Value | Classification |
|---|---|
0 | No classification |
2 | Application |
4 | Virus |
8 | Trojan |
16 | Application |