This URL gets the executable information for given hash value.
Resource URL
GET /<nbaid>/endpointintelligence/<hash>/executableinformation? duration=<duration>
Request Parameters
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| duration | Duration
|
String | No |
| hash | Hash | String | Yes |
| nbaId | NTBA monitors id | String | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| EndpointExecutableList | List of endpoint executables | Array |
Details of EndpointExecutableList:
| Field Name | Description | Data Type |
|---|---|---|
| properties | Executable properties | Object |
| heuristics | Heuristics data | Object |
| libraryProcesses | Process using this library | Object |
| parentProcesses | Parent process | Object |
| suspiciousLibraries | Suspicious libraries | Object |
Details of properties:
| Field Name | Description | Data Type |
|---|---|---|
| hash | Executable hash | String |
| binaryType | Binary type | String |
| binaryName | Binary name | String |
| productName | Product name | String |
| productVersion | Product version | String |
| overallMalwareConfidence | Overall malware confidence | String |
| eiaAgentMalwareConfidence | EIA agent malware confidence | String |
| classification | Classification | String |
| classifier | Classifier | String |
| classified | Classified | String |
| filesize | File size | Long |
Details of heuristics:
| Field Name | Description | Data Type |
|---|---|---|
| digitallySigned | Digitally signed | String |
| certificateStatus | Certificate status | String |
| packed | Packed | String |
| resourceSection | Resource section | String |
| smallerThan500KB | Smaller than 500 KB | String |
| embeddedUI | Embedded UI | String |
| obfuscatedFileExtention | Obfuscated file extension | String |
| recentlyModified | Recently modified | String |
| gtiReputation | GTI reputation | String |
Details of parentProcesses:
| Field Name | Description | Data Type |
|---|---|---|
| hash | Hash value | String |
| name | Name | String |
Details of suspiciousLibraries and libraryProcesses:
| Field Name | Description | Data Type |
|---|---|---|
| hash | Hash value | String |
| name | Name | String |
| malwareConfidence | Malware confidence | String |
Example
Request
Response
{
"properties":
{"hash":"1aaaaaaaaaaaaaaaaaaaaaaaaaaaaa23",
"binaryType":"Process",
"binaryName":"abc.exe",
"productName":"",
"productVersion":"file_version",
"overallMalwareConfidence":"Medium",
"eiaAgentMalwareConfidence":"Medium",
"classification":"unclassified",
"classifier":"---","filesize":2566795},
"heuristics":{},
"suspiciousLibraries":[{
"hash":"1aaaaaaaaaaaaaaaaaaaaaaaaaaaaab1",
"name":"abc_dll.dll",
"malwareConfidence":"High"}]
}
Error Information
Following error codes are returned by this URL:
| S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 400 | 3601 | Invalid duration |
| 2 | 400 | 4901 | Invalid hash/failed retrieve |