This URL gets the list of zombies for an active botnet.
Resource URL
GET /domain/<domain_id>/activebotnetzombies/<bot_id>?includeChildDomain=<includeChildDomain>&&duration=<duration>
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Domain id | Number | Yes |
includeChildDomain | Should the child domains be included | Boolean | No |
duration | Duration can be:
| String | No |
Response Parameters
Following fields are returned.
Field Name | Description | Data Type |
|---|---|---|
| List of zombies for the botnet | ObjectList |
Details of fields in zombiesDetailList:
Field Name | Description | Data Type |
|---|---|---|
| IP address | String |
| DNS name | String |
| C&C communication | String |
| Number of events | Number |
| Time of last event | String |
| Comment | String |
Example
Request
GET https://<NSM_IP>/sdkapi/domain/0/activebotnetzombies/6
Response
{
"zombiesDetailList":
[
{
"ipAddress": "192.168.2.2",
"dnsName": "",
"ccCommunication": "UN_BLOCKED",
"events": 2,
"lastEvent": "Jan 31 16:53 IST",
"comment": ""
}
]
}
Error Information
Following error codes are returned by this URL:
No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 404 | 1105 | Invalid domain |
2 | 404 | 4201 | Invalid duration filter |
3 | 404 | 4202 | Invalid botnet id |