The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Malware Alerts

Prev Next

This URL get the list malware alerts for the malware file hash.

Resource URL

GET /domain/<domain_id>/malwaredownloads/ filehash/<filehash>?duration=<duration>&resultType=<resultType>&confidenceType=<confidenceType>&includeChildDomain=<includeChildDomain>

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
domain Domain id Number Yes
duration Duration can be:
  • LAST_5_MINUTES
  • LAST_1_HOUR
  • LAST_6_HOURS
  • LAST_12_HOURS
  • LAST_24_HOURS
  • LAST_48_HOURS
  • LAST_7_DAYS
  • LAST_14_DAYS
String No
resultType Result type can be:
  • ANY_RESULT
  • BLOCKED
  • UNBLOCKED
String No
confidenceType Confidence type can be:
  • ANY_MALWARE_CONFIDENCE
  • VERY_HIGH_MALWARE_CONFIDENCE
  • HIGH_MALWARE_CONFIDENCE
  • LOW_MALWARE_CONFIDENCE
  • MEDIUM_MALWARE_CONFIDENCE
  • VERY_LOW_MALWARE_CONFIDENCE
String No

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
malwareAlertDetailsList List of malware alert detail defined in the domain Array

Details of object in MalwareAlertDetail:

Field Name Description Data Type
time Time stamp String
attacker IP details Object
target IP details Object
result Result String
protocol Protocol String
confidence Confidence can be: "VERY_LOW"/"LOW"/"MEDIUM"/ "HIGH"/"VERY_HIGH"/"UNKNOWN" String
fileName File name String
engine Engine String
attackDescription Attack description Object

Details of object in attacker/target:

Field Name Description Data Type
ipAddress IP address String
country Country String

Details of object in attackDescription:

Field Name Description Data Type
attackName Attack name String
result Result can be: "ATTACK_SUCCESSFUL"/"INCONCLUSIVE"/" ATTACK_FAILED"/"ATTACK_BLOCKED"/" NOT_APPLICABLE"/" DOS_BLOCKING_ACTIVATED"/" BLOCKING_SIMULATED_ATTACK_SUCCESSFUL"/ "BLOCKING_SIMULATED_INCONCLUSIVE"/" BLOCKING_SIMULATED_ATTACK_FAILED"/" BLOCKING_SIMULATED_NOT_APPLICABLE" String
direction Direction can be: "INBOUND"/" OUTBOUND"/" UNKNOWN"/" BOTH"

Example

Request

GET https://<NSM_IP>/domain/0/malwaredownloads/filehash/4e1b0fab3e49832570eedeb7a54c4d11

Response

 {
    "malwareAlertDetailsList": [
        {
            "time": "Dec 27 13:24 IST",
            "attacker": {
                "ipAddress": "1.1.1.2",
                "country": "---"
            },
            "target": {
                "ipAddress": "1.1.1.1",
                "country": "---"
            },
            "result": "Inconclusive",
            "protocol": "smtp",
            "confidence": "VERY_HIGH",
            "fileName": "",
            "engine": "Trellix IPS Analysis",
            "attackDescription": {
                "attackName": "MALWARE: Malicious PDF file transfer detected",
                "result": "INCONCLUSIVE",
                "direction": "INBOUND"
            }
        },
        {
            "time": "Dec 27 13:22 IST",
            "attacker": {
                "ipAddress": "1.1.1.2",
                "country": "---"
            },
            "target": {
                "ipAddress": "1.1.1.1",
                "country": "---"
            },
            "result": "Inconclusive",
            "protocol": "smtp",
            "confidence": "VERY_HIGH",
            "fileName": "",
            "engine": "Trellix IPS Analysis",
            "attackDescription": {
                "attackName": "MALWARE: Malicious PDF file transfer detected",
                "result": "INCONCLUSIVE",
                "direction": "INBOUND"
            }
        },
    ]
} 
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 500 1001 Internal error
2 404 1105 Invalid domain
3 404 3401 Invalid file hash value
4 400 3801 Invalid result filter value
5 400 3802 Invalid duration filter value