HTTP/1.1 [Response Code] [Response Message] Date: [Date] Content-Type: [Content-Type] X-FeApi-Token: [API-Token] X-FeClient-Token: [Client-Token]
Response fields
Response Code—A standard HTML response code.
200—Request successful.
400—Request unsuccessful because the filter value was invalid.
Response Message—A standard HTML response message.
OK—Request successful.
Bad Request—Request unsuccessful because the filter value was invalid.
Date—Standard HTML date format.
Content-Type—(Optional) You can request responses in one of two formats:
application/xml—(Default).application/json—Must be specified using theAcceptheader.
API-Token—This token authenticates the session. By default, the session times out after 15 minutes of inactivity.Client-Token—(Optional) This client token is provided by Trellix. For more information about the client token, contact your sales representative.
Example response—Central Management System
HTTP/1.1 200 OK Date: Fri, 19 Oct 2018 09:00:00 GMT
Body:
Line breaks have been added for readability.
{
"alert": [
{
"explanation": {
"malwareDetected": {
"malware": [
{
"md5Sum":"fe4d8f227520e2468dd1019496ef0604",
"sha256":"b71e3012e93f11a7b0b179ea54eeb0e787d02acc48705833e
414a5e57a6a2032",
"name":"Malware.Binary.FEC2",
"originalInfectionId":3181,
"originalInfectionType":"MALWARE_OBJECT",
"originalInfectionUrl":"https://10.11.113.143/botnets/events_for_bot?ma_id=3181"
},
{
"md5Sum":"fe4d8f227520e2468dd1019496ef0604",
"sha256":"b71e3012e93f11a7b0b179ea54eeb0e787d02acc48705833e
414a5e57a6a2032",
"application":"application:57",
"httpHeader":"GET http://getapac.com/75.html HTTP/1.1\r\nUser-Agent: Mozilla/4.0 (Windows XP 5.1) Java/1.6.0_16\r\nHost: getapac.com\r\nAccept: text/html, image/gif, image/jpeg, *; q=.2, */*; q=.2\r\nProxy-Connection: keep-alive\r\n\r\n HTTP/1.0 200 OK\r\nDate: Tue, 16 Apr 2013 23:53:28 GMT\r\nServer: Apache\r\nExpires: Mon, 20 Aug 2002 02:00:00 GMT\r\nPragma: no-cache\r\nCache-Control: no-cache\r\nContent-Transfer-Encoding: binary\r\nContent-Disposition: inline; filename=setup.exe\r\nContent-Length: 39296\r\nContent-Type: application/octet-stream\r\nX-Cache: MISS from localhost\r\nX-Cache-Lookup: MISS from localhost:80\r\nVia: 1.0 localhost (squid/3.1.19)\r\nConnection: keep-alive\r\n\r\n",
"original":"setup.exe",
"name":"Malware.Binary.FEC2",
"originalInfectionId":3181,
"originalInfectionType":"MALWARE_OBJECT",
"originalInfectionUrl":"https://10.11.113.143/botnets/events_for_bot?ma_id=3181",
"sid":"0",
"type":"exe",
"stype":"avs"
},
{
"md5Sum":"fe4d8f227520e2468dd1019496ef0604",
"sha256":"b71e3012e93f11a7b0b179ea54eeb0e787d02acc48705833e
414a5e57a6a2032",
"application":"application:57",
"httpHeader":"GET http://getapac.com/75.html HTTP/1.1\r\nUser-Agent: Mozilla/4.0 (Windows XP 5.1) Java/1.6.0_16\r\nHost: getapac.com\r\nAccept: text/html, image/gif, image/jpeg, *; q=.2, */*; q=.2\r\nProxy-Connection: keep-alive\r\n\r\n HTTP/1.0 200 OK\r\nDate: Tue, 16 Apr 2013 23:53:28 GMT\r\nServer: Apache\r\nExpires: Mon, 20 Aug 2002 02:00:00 GMT\r\nPragma: no-cache\r\nCache-Control: no-cache\r\nContent-Transfer-Encoding: binary\r\nContent-Disposition: inline; filename=setup.exe\r\nContent-Length: 39296\r\nContent-Type: application/octet-stream\r\nX-Cache: MISS from localhost\r\nX-Cache-Lookup: MISS from localhost:80\r\nVia: 1.0 localhost (squid/3.1.19)\r\nConnection: keep-alive\r\n\r\n",
"original":"setup.exe",
"name":"JavaExploit.EncryptedPayload",
"originalInfectionId":3181,
"originalInfectionType":"MALWARE_OBJECT",
"originalInfectionUrl":"https://10.11.113.143/botnets/events_for_bot?ma_id=3181",
"type":"exe"
}
]
},
"osChanges": [
{
"application": {"app-name":"Windows Explorer"},
"os": {
"name":"windows",
"arch":"x64",
"version":"6.1.7601",
"sp":1
},
"file_informational": [
{
"mode":"close",
"fid": {
"ads":"",
"content": 3377699720613027
},
"sha1sum":"ba5a1564d46348272f970f3c836a9f038528017d",
"md5sum":"8f66978e66faf1262eca66984f9ee056",
"processinfo": {
"imagepath":"C:\\Windows\\System32\\taskhost.exe",
"md5sum":"639774c9acd063f028f6084abf5593ad",
"pid":3020
},
"sha256sum":"3169bac13d2b500e9deb43c9cbcc27eadfba4d94870c
f7698cb58297d111212b",
"ntstatus":"0x0",
"filesize":24576,
"no_extend":true,
"value":"C:\\Windows\\System32\\config\\RegBack\\SECURITY",
"CreateOptions":"0x0",
"timestamp":2243
},
{
"mode":"close",
"fid": {
"ads":"",
"content":1125899906949946
},
"processinfo": {
"imagepath":"C:\\Windows\\System32\\taskhost.exe",
"md5sum":"639774c9acd063f028f6084abf5593ad",
"pid":3020
},
"ntstatus":"0x0",
"no_extend":true,
"value":"C:\\Windows\\System32\\config\\RegBack\\SECURITY.
LOG1",
"CreateOptions":"0x0",
"timestamp":2300
},
{
"mode":"close",
"fid": {
"ads":"",
"content":1125899906949947
},
"processinfo": {
"imagepath":"C:\\Windows\\System32\\taskhost.exe",
"md5sum":"639774c9acd063f028f6084abf5593ad",
"pid":3020
},
"ntstatus":"0x0",
"no_extend":true,
"value":"C:\\Windows\\System32\\config\\RegBack\\SECURITY
.LOG2",
"CreateOptions":"0x0",
"timestamp":2315
},
{
"mode":"close",
"fid": {
"ads":"",
"content":281474976922429
},
"sha1sum":"4e9c5284532d348c4845014c349aa88c231e96e4",
"md5sum":"240fb08bc218a72a1bc6a245d52e7314",
"processinfo": {
"imagepath":"C:\\Program Files\\Windows Defender\\MpCmdRun.exe",
"md5sum":"6bd4d7f68924301051c22e8a951aecba",
"pid":3136
},
"sha256sum":"a31dcd30c693424b189878d5bd5201cd150578dd906b
547613a709dccce7978a",
"ntstatus":"0x0",
"filesize":6662,
"no_extend":true,
"value":"C:\\Windows\\Temp\\MpCmdRun.log",
"CreateOptions":"0x0",
"timestamp":10183
},
{
"mode":"close",
"fid": {
"ads":"",
"content":4222124650748166
},
"sha1sum":"af9075a443b76bbe741eceb4188847ac93ff6d6b",
"md5sum":"f857040c35dc58409500336994a0ef2a",
"processinfo": {
"imagepath":"N/A",
"pid":4
},
"sha256sum":"97cc6174ef09d68f1693e2821a5e71a24578a86f64c
662a030da93509e483066",
"ntstatus":"0x0",
"filesize":196608,
"no_extend":true,
"value":"C:\\Windows\\Logs\\SystemRestore\\PropertyPage
.0.etl",
"CreateOptions":"0x0",
"timestamp":11184
},
{
"mode":"close",
"fid": {
"ads":"",
"content":3659174697325736
},
"sha1sum":"15e828174e57fd35b4675d6e06c9c1c01830d2ca",
"md5sum":"e1ac844fc640df3517f42b32c31b3c05",
"processinfo": {
"imagepath":"C:\\Windows\\System32\\taskhost.exe",
"md5sum":"639774c9acd063f028f6084abf5593ad",
"pid":3020
},
"sha256sum":"d0af7af8ff3c3ba6bbb4289dc4e5b2ea1410d72e8615
3d747473e9faead853b1",
"ntstatus":"0x0",
"filesize":62521344,
"no_extend":true,
"value":"C:\\Windows\\System32\\config\\RegBack
\\SOFTWARE",
"CreateOptions":"0x0",
"timestamp":11467
},
{
"mode":"close",
"fid": {
"ads":"",
"content":1125899906949948
},
"processinfo": {
"imagepath":"C:\\Windows\\System32\\taskhost.exe",
"md5sum":"639774c9acd063f028f6084abf5593ad",
"pid":3020
},
"ntstatus":"0x0",
"no_extend":true,
"value":"C:\\Windows\\System32\\config\\RegBack
\\SOFTWARE.LOG1",
"CreateOptions":"0x0",
"timestamp":12375
},
{
"mode":"close",
"fid": {
"ads":"",
"content":1125899906949949
},
"processinfo": {
"imagepath":"C:\\Windows\\System32\\taskhost.exe",
"md5sum":"639774c9acd063f028f6084abf5593ad",
"pid": 3020
},
"ntstatus":"0x0",
"no_extend": true,
"value":"C:\\Windows\\System32\\config\\RegBack
\\SOFTWARE.LOG2",
"CreateOptions":"0x0",
"timestamp": 12381
}
],
"uac": [
{
"mode":"service",
"buffered":true,
"no_extend":true,
"value":"Volume Shadow Copy",
"timestamp":10905,
"status":"running"
},
{
"mode":"service",
"buffered":true,
"no_extend":true,
"value":"Microsoft Software Shadow Copy Provider",
"timestamp":12887,
"status":"running"
}
],
"end-of-report":"",
"process_informational": [
{
"fid":{
"ads":"",
"content":281474976725189
},
"parentname":"C:\\Program Files\\Windows Defender
\\MpCmdRun.exe",
"sha256sum":"9afd12eede0db98a35aba52f53041efa4a2f2a0367
3672c7ac530830b7152392",
"pid":2192,
"filesize":190976,
"ppid":3136,
"mode":"started",
"cmdline":"\"c:\\program files\\windows defender\\
MpCmdRun.exe\" Scan -ScheduleJob -WinTask -RestrictPrivilegesScan -Reinvoke",
"sha1sum":"2ae2a6b863616b61ccb550fc1a145ae025896de1",
"md5sum":"6bd4d7f68924301051c22e8a951aecba",
"no_extend":true,
"value":"C:\\Program Files\\Windows Defender\\MpCmdRun.exe",
"timestamp":10153
},
{
"fid": {
"ads":"",
"content":281474976780111
},
"parentname":"C:\\Windows\\System32\\services.exe",
"sha256sum":"N/A",
"pid":1492,
"filesize":1600512,
"ppid":480,
"mode":"started",
"cmdline":"C:\\Windows\\system32\\vssvc.exe",
"sha1sum":"1d6f5a5de7154b75144c6a033c36fd86ff2bbe9b",
"md5sum":"b60ba0bc31b0cb414593e169f6f21cc2",
"no_extend":true,
"value":"C:\\Windows\\System32\\VSSVC.exe",
"timestamp":10547
},
{
"fid": {
"ads":"",
"content":281474976737050
},
"parentname":"C:\\Windows\\System32\\services.exe",
"sha256sum":"N/A",
"pid":3632,
"filesize":27136,
"ppid":480,
"mode":"started",
"cmdline":"C:\\Windows\\System32\\svchost.exe -k swprv",
"sha1sum":"619652b42afe5fb0e3719d7aeda7a5494ab193e8",
"md5sum":"c78655bc80301d76ed4fef1c1ea40a7d",
"no_extend":true,
"value":"C:\\Windows\\System32\\svchost.exe",
"timestamp":10836
}
],
"os_monitor": {
"date":"Sep 19 2018",
"build":795854,
"time":"12:59:48",
"version":"17R1.7"
},
"malicious-alert": [
{
"classtype":"static_log",
"display-msg":"Static Analysis Malware.Binary.FEC2"
},
{
"classtype":"Static-Analysis",
"display-msg":"Static Analysis Malware.Binary.FEC2"
},
{
"classtype":"static_log",
"display-msg":"Static Analysis JavaExploit.EncryptedPayload"
},
{
"classtype":"Static-Analysis",
"display-msg":"Static Analysis JavaExploit.EncryptedPayload"
},
{
"classtype":"sa_only",
"display-msg":"Heuristic"
}
],
"analysis": {
"mode":"malware",
"product":"MPS",
"ftype":"exe",
"version":1.3977
}
},
{
"process": {
"mode":"started",
"fid": {
"ads":"",
"content":1688849860268247
},
"parentname":"C:\\WINDOWS\\explorer.exe",
"cmdline":"\"C:\\WINDOWS\\system32\\ntvdm.exe\" -f -i1",
"sha1sum":"df36cf59f700fc0b3b60c009b8b877d6233fdd72",
"md5sum":"681b807e53bdada337735c28c0e48a1b",
"sha256sum":"a0be52e7d076ed8e33a4b5ab309cd23ad0272570c7e87
fe6e3444712ad467d62",
"pid":3456,
"filesize":420864,
"value":"C:\\WINDOWS\\system32\\ntvdm.exe",
"timestamp":3478,
"ppid": 1864
},
"application": {"app-name":"Windows Explorer"},
"os": {
"name":"windows",
"arch":"x86",
"version":"5.1.2600",
"sp":3
},
"file_informational": [
{
"mode":"close",
"fid": {
"ads":"",
"content":844424930200765
},
"sha1sum":"863bbf5f7f4114a1307c6bad5dd89224d511fed5",
"md5sum":"4a587187d760161311010b03417b3c3f",
"processinfo": {
"imagepath":"C:\\WINDOWS\\system32\\ntvdm.exe",
"md5sum":"681b807e53bdada337735c28c0e48a1b",
"pid":3456
},
"sha256sum":"b7792de7a6d7abb649a8a22e9048d0468b604ca98b
8978bdd1171356af6d5f49",
"ntstatus":"0x0",
"filesize":2686,
"no_extend":true,
"value":"C:\\WINDOWS\\Temp\\scs14.tmp",
"CreateOptions":"0x0",
"timestamp":3614
},
{
"mode":"close",
"fid": {
"ads":"",
"content":562949953490275
},
"sha1sum":"8565ed558ad273232104e0b10cd87cff723a1eca",
"md5sum":"71f4b39c5eb73df738ad3e0dacd89057",
"processinfo": {
"imagepath":"C:\\WINDOWS\\system32\\ntvdm.exe",
"md5sum":"681b807e53bdada337735c28c0e48a1b",
"pid":3456
},
"sha256sum":"d504b1c272cd0c92c4a365086cf884a4889653c89d56
02b6dadeffb33b83951d",
"ntstatus":"0x0",
"filesize":1670,
"no_extend":true,
"value":"C:\\WINDOWS\\Temp\\scs15.tmp",
"CreateOptions":"0x0",
"timestamp":3943
}
],
"end-of-report":"",
"os_monitor": {
"date":"Sep 19 2018",
"build":795854,
"time":"12:59:48",
"version":"17R1.7"
},
"malicious-alert": [
{
"classtype":"static_log",
"display-msg":"Static Analysis Malware.Binary.FEC2"
},
{
"classtype":"Static-Analysis",
"display-msg":"Static Analysis JavaExploit.EncryptedPayload"
},
{
"classtype":"static_log",
"display-msg":"Static Analysis JavaExploit.EncryptedPayload"
},
{
"classtype":"Static-Analysis",
"display-msg":"Static Analysis Malware.Binary.FEC2"
},
{
"classtype":"NTVDM-Process-Launch-Activity",
"display-msg":"Startup behavior anomalies observed"
},
{
"classtype":"sa_only",
"display-msg":"Heuristic"
}
],
"analysis": {
"mode":"malware",
"product":"MPS",
"ftype":"exe",
"version":1.3977
}
}
]
},
"src": {
"ip":"157.204.181.231",
"mac":"00:20:18:11:ff:45",
"port": 0
},
"alertUrl":"https://qa-cm7500-4-9-20/event_stream/events_for_bot?ma_id=261146",
"action":"notified",
"occurred":"2018-10-18 16:46:41 +0000",
"dst": {
"mac":"02:14:17:da:c9:2f",
"port": 0,
"ip":"249.207.161.251"
},
"applianceId":"000BABCD66F2",
"id": 261146,
"rootInfection": 3181,
"sensorIp":"10.11.113.155",
"name":"MALWARE_OBJECT",
"severity":"MAJR",
"uuid":"c9391258-1a79-4b54-be8e-144ddb5f118f",
"ack":"yes",
"product":"WEB_MPS",
"sensor":"cms-nx2500-3",
"vlan": 0,
"malicious":"yes"
}
],
"appliance":"CMS",
"version":"CMS (CMS) 8.4.0.805144",
"msg":"normal",
"alertsCount": 1
}Note
The "uuid" and "ack" fields are only supported in v2.0.0.