This URL gets the list malware downloads from the Manager.
Resource URL
GET /domain/<domain_id>/malwaredownloads?duration=<duration>&resultType=<resultType>&confidenceType=<confidenceType>&includeChildDomain=<includeChildDomain>
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Domain id | Number | Yes |
| Duration can be:
| String | No |
| Result type can be:
| String | No |
| Confidence type can be:
| String | No |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| List of malware summary detail defined in the domain | Array |
Details of object in MalwareSummaryDetailList:
Field Name | Description | Data Type |
|---|---|---|
| File hash | String |
| Over all confidence can be: "VERY_LOW"/"LOW"/"MEDIUM"/ "HIGH"/"VERY_HIGH"/"UNKNOWN" | Boolean |
| Individual engine confidence | Object |
| Last download time | String |
| Total downloads | Number |
| File size | String |
| Last file name | String |
| Last result | String |
| Comment | String |
Details of object in individualEngineConfidence:
Field Name | Description | Data Type |
|---|---|---|
| Custom finger prints can be: "VERY_LOW"/"LOW"/"MEDIUM"/ "HIGH"/"VERY_HIGH"/"UNKNOWN" | String |
| GTI file reputation can be: "VERY_LOW"/"LOW"/"MEDIUM"/ "HIGH"/"VERY_HIGH"/"UNKNOWN" | String |
| PDF emulation can be: "VERY_LOW"/"LOW"/"MEDIUM"/ "HIGH"/"VERY_HIGH"/"UNKNOWN" | String |
| Gateway Anti-Malware can be: "VERY_LOW"/"LOW"/"MEDIUM"/ "HIGH"/"VERY_HIGH"/"UNKNOWN" | String |
Example
Request
GET https://<NSM_IP>/domain/0/malwaredownloads
Response
{
"malwareSummaryDetailList": [
{
"filehash": "493d146a59a155ed2eb890f5fd3bb182",
"overAllConfidence": "LOW",
"individualEngineConfidence": {
"CustomFingerPrints": "UNKNOWN",
"GTIFileReputation": "VERY_LOW",
"PDFEmulation": "UNKNOWN",
"GatewayAntiMalware": "LOW"
},
"lastDownload": "Mon Mar 10 17:37:49 IST 2014",
"totalDownloads": 2,
"fileSize": "1024"
}
]
}
Error Information
Following error codes are returned by this URL:
No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 500 | 1001 | Internal error |
2 | 404 | 1105 | Invalid domain |
3 | 400 | 3801 | Invalid result filter value |
4 | 400 | 3802 | Invalid duration filter value |