The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Malware Downloads

Prev Next

This URL gets the list malware downloads from the Manager.

Resource URL

GET /domain/<domain_id>/malwaredownloads?duration=<duration>&resultType=<resultType>&confidenceType=<confidenceType>&includeChildDomain=<includeChildDomain>

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

domain

Domain id

Number

Yes

duration

Duration can be:

  • LAST_5_MINUTES

  • LAST_1_HOUR

  • LAST_6_HOURS

  • LAST_12_HOURS

  • LAST_24_HOURS

  • LAST_48_HOURS

  • LAST_7_DAYS

  • LAST_14_DAYS

String

No

resultType

Result type can be:

  • ANY_RESULT

  • BLOCKED

  • UNBLOCKED

String

No

confidenceType

Confidence type can be:

  • ANY_MALWARE_CONFIDENCE

  • VERY_HIGH_MALWARE_CONFIDENCE

  • HIGH_MALWARE_CONFIDENCE

  • LOW_MALWARE_CONFIDENCE

  • MEDIUM_MALWARE_CONFIDENCE

  • VERY_LOW_MALWARE_CONFIDENCE

String

No

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

MalwareSummaryDetailList

List of malware summary detail defined in the domain

Array

Details of object in MalwareSummaryDetailList:

Field Name

Description

Data Type

filehash

File hash

String

overAllConfidence

Over all confidence can be: "VERY_LOW"/"LOW"/"MEDIUM"/ "HIGH"/"VERY_HIGH"/"UNKNOWN"

Boolean

individualEngineConfidence

Individual engine confidence

Object

lastDownload

Last download time

String

totalDownloads

Total downloads

Number

fileSize

File size

String

lastFileName

Last file name

String

lastResult

Last result

String

comment

Comment

String

Details of object in individualEngineConfidence:

Field Name

Description

Data Type

CustomFingerPrints

Custom finger prints can be: "VERY_LOW"/"LOW"/"MEDIUM"/ "HIGH"/"VERY_HIGH"/"UNKNOWN"

String

GTIFileReputation

GTI file reputation can be: "VERY_LOW"/"LOW"/"MEDIUM"/ "HIGH"/"VERY_HIGH"/"UNKNOWN"

String

PDFEmulation

PDF emulation can be: "VERY_LOW"/"LOW"/"MEDIUM"/ "HIGH"/"VERY_HIGH"/"UNKNOWN"

String

GatewayAntiMalware

Gateway Anti-Malware can be: "VERY_LOW"/"LOW"/"MEDIUM"/ "HIGH"/"VERY_HIGH"/"UNKNOWN"

String

Example

Request

GET https://<NSM_IP>/domain/0/malwaredownloads

Response

{
  "malwareSummaryDetailList": [
    {
      "filehash": "493d146a59a155ed2eb890f5fd3bb182",
      "overAllConfidence": "LOW",
      "individualEngineConfidence": {
        "CustomFingerPrints": "UNKNOWN",
        "GTIFileReputation": "VERY_LOW",
        "PDFEmulation": "UNKNOWN",
        "GatewayAntiMalware": "LOW"
      },
      "lastDownload": "Mon Mar 10 17:37:49 IST 2014",
      "totalDownloads": 2,
      "fileSize": "1024"
    }
  ]
} 

Error Information

Following error codes are returned by this URL:

No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

500

1001

Internal error

2

404

1105

Invalid domain

3

400

3801

Invalid result filter value

4

400

3802

Invalid duration filter value