This URL get the list malware alerts for the malware file hash.
Resource URL
GET /domain/<domain_id>/malwaredownloads/ filehash/<filehash>?duration=<duration>&resultType=<resultType>&confidenceType=<confidenceType>&includeChildDomain=<includeChildDomain>
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Domain id | Number | Yes |
| Duration can be:
| String | No |
| Result type can be:
| String | No |
| Confidence type can be:
| String | No |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| List of malware alert detail defined in the domain | Array |
Details of object in MalwareAlertDetail:
Field Name | Description | Data Type |
|---|---|---|
| Time stamp | String |
| IP details | Object |
| IP details | Object |
| Result | String |
| Protocol | String |
| Confidence can be: "VERY_LOW"/"LOW"/"MEDIUM"/ "HIGH"/"VERY_HIGH"/"UNKNOWN" | String |
| File name | String |
| Engine | String |
| Attack description | Object |
Details of object in attacker/target:
Field Name | Description | Data Type |
|---|---|---|
| IP address | String |
| Country | String |
Details of object in attackDescription:
Field Name | Description | Data Type |
|---|---|---|
| Attack name | String |
| Result can be: "ATTACK_SUCCESSFUL"/"INCONCLUSIVE"/" ATTACK_FAILED"/"ATTACK_BLOCKED"/" NOT_APPLICABLE"/" DOS_BLOCKING_ACTIVATED"/" BLOCKING_SIMULATED_ATTACK_SUCCESSFUL"/ "BLOCKING_SIMULATED_INCONCLUSIVE"/" BLOCKING_SIMULATED_ATTACK_FAILED"/" BLOCKING_SIMULATED_NOT_APPLICABLE" | String |
| Direction can be: "INBOUND"/" OUTBOUND"/" UNKNOWN"/" BOTH" |
Example
Request
GET https://<NSM_IP>/domain/0/malwaredownloads/filehash/4e1b0fab3e49832570eedeb7a54c4d11
Response
{
"malwareAlertDetailsList": [
{
"time": "Dec 27 13:24 IST",
"attacker": {
"ipAddress": "1.1.1.2",
"country": "---"
},
"target": {
"ipAddress": "1.1.1.1",
"country": "---"
},
"result": "Inconclusive",
"protocol": "smtp",
"confidence": "VERY_HIGH",
"fileName": "",
"engine": "Trellix IPS Analysis",
"attackDescription": {
"attackName": "MALWARE: Malicious PDF file transfer detected",
"result": "INCONCLUSIVE",
"direction": "INBOUND"
}
},
{
"time": "Dec 27 13:22 IST",
"attacker": {
"ipAddress": "1.1.1.2",
"country": "---"
},
"target": {
"ipAddress": "1.1.1.1",
"country": "---"
},
"result": "Inconclusive",
"protocol": "smtp",
"confidence": "VERY_HIGH",
"fileName": "",
"engine": "Trellix IPS Analysis",
"attackDescription": {
"attackName": "MALWARE: Malicious PDF file transfer detected",
"result": "INCONCLUSIVE",
"direction": "INBOUND"
}
},
]
}
Error Information
Following error codes are returned by this URL:
No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 500 | 1001 | Internal error |
2 | 404 | 1105 | Invalid domain |
3 | 404 | 3401 | Invalid file hash value |
4 | 400 | 3801 | Invalid result filter value |
5 | 400 | 3802 | Invalid duration filter value |