The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Malware Downloads

Prev Next

This URL gets the list malware downloads from the Manager.

Resource URL

GET /domain/<domain_id>/malwaredownloads?duration=<duration>&resultType=<resultType>&confidenceType=<confidenceType>&includeChildDomain=<includeChildDomain>

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
domain Domain id Number Yes
duration Duration can be:
  • LAST_5_MINUTES
  • LAST_1_HOUR
  • LAST_6_HOURS
  • LAST_12_HOURS
  • LAST_24_HOURS
  • LAST_48_HOURS
  • LAST_7_DAYS
  • LAST_14_DAYS
String No
resultType Result type can be:
  • ANY_RESULT
  • BLOCKED
  • UNBLOCKED
String No
confidenceType Confidence type can be:
  • ANY_MALWARE_CONFIDENCE
  • VERY_HIGH_MALWARE_CONFIDENCE
  • HIGH_MALWARE_CONFIDENCE
  • LOW_MALWARE_CONFIDENCE
  • MEDIUM_MALWARE_CONFIDENCE
  • VERY_LOW_MALWARE_CONFIDENCE
String No

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
MalwareSummaryDetailList List of malware summary detail defined in the domain Array

Details of object in MalwareSummaryDetailList:

Field Name Description Data Type
filehash File hash String
overAllConfidence Over all confidence can be: "VERY_LOW"/"LOW"/"MEDIUM"/ "HIGH"/"VERY_HIGH"/"UNKNOWN" Boolean
individualEngineConfidence Individual engine confidence Object
lastDownload Last download time String
totalDownloads Total downloads Number
fileSize File size String
lastFileName Last file name String
lastResult Last result String
comment Comment String

Details of object in individualEngineConfidence:

Field Name Description Data Type
CustomFingerPrints Custom finger prints can be: "VERY_LOW"/"LOW"/"MEDIUM"/ "HIGH"/"VERY_HIGH"/"UNKNOWN" String
GTIFileReputation GTI file reputation can be: "VERY_LOW"/"LOW"/"MEDIUM"/ "HIGH"/"VERY_HIGH"/"UNKNOWN" String
PDFEmulation PDF emulation can be: "VERY_LOW"/"LOW"/"MEDIUM"/ "HIGH"/"VERY_HIGH"/"UNKNOWN" String
GatewayAntiMalware Gateway Anti-Malware can be: "VERY_LOW"/"LOW"/"MEDIUM"/ "HIGH"/"VERY_HIGH"/"UNKNOWN" String

Example

Request

GET https://<NSM_IP>/domain/0/malwaredownloads

Response

{
  "malwareSummaryDetailList": [
    {
      "filehash": "493d146a59a155ed2eb890f5fd3bb182",
      "overAllConfidence": "LOW",
      "individualEngineConfidence": {
        "CustomFingerPrints": "UNKNOWN",
        "GTIFileReputation": "VERY_LOW",
        "PDFEmulation": "UNKNOWN",
        "GatewayAntiMalware": "LOW"
      },
      "lastDownload": "Mon Mar 10 17:37:49 IST 2014",
      "totalDownloads": 2,
      "fileSize": "1024"
    }
  ]
} 
 

Error Information

Following error codes are returned by this URL:

No HTTP Error Code SDK API errorId SDK API errorMessage
1 500 1001 Internal error
2 404 1105 Invalid domain
3 400 3801 Invalid result filter value
4 400 3802 Invalid duration filter value