Alert response

Prev Next
HTTP/1.1 [Response Code] [Response Message]
Date: [Date]
Content-Type: [Content-Type]
X-FeApi-Token: [API-Token]
X-FeClient-Token: [Client-Token]

Response fields

  • Response Code—A standard HTML response code.

    • 200—Request successful.

    • 400—Request unsuccessful because the filter value was invalid.

  • Response Message—A standard HTML response message.

    • OK—Request successful.

    • Bad Request—Request unsuccessful because the filter value was invalid.

  • Date—Standard HTML date format.

  • Content-Type—(Optional) You can request responses in one of two formats:

    • application/xml—(Default).

    • application/json—Must be specified using the Accept header.

  • API-Token—This token authenticates the session. By default, the session times out after 15 minutes of inactivity.

  • Client-Token—(Optional) This client token is provided by Trellix. For more information about the client token, contact your sales representative.

Example response—Central Management System

HTTP/1.1 200 OK
Date: Fri, 19 Oct 2018 09:00:00 GMT

Body:

Line breaks have been added for readability.

{
  "alert": [
    {
      "explanation": {
        "malwareDetected": {
          "malware": [
            {
              "md5Sum":"fe4d8f227520e2468dd1019496ef0604",
              "sha256":"b71e3012e93f11a7b0b179ea54eeb0e787d02acc48705833e
414a5e57a6a2032",
              "name":"Malware.Binary.FEC2",
              "originalInfectionId":3181,
              "originalInfectionType":"MALWARE_OBJECT",
              "originalInfectionUrl":"https://10.11.113.143/botnets/events_for_bot?ma_id=3181"
            },
            {
              "md5Sum":"fe4d8f227520e2468dd1019496ef0604",
              "sha256":"b71e3012e93f11a7b0b179ea54eeb0e787d02acc48705833e
414a5e57a6a2032",
              "application":"application:57",
              "httpHeader":"GET http://getapac.com/75.html HTTP/1.1\r\nUser-Agent: Mozilla/4.0 (Windows XP 5.1) Java/1.6.0_16\r\nHost: getapac.com\r\nAccept: text/html, image/gif, image/jpeg, *; q=.2, */*; q=.2\r\nProxy-Connection: keep-alive\r\n\r\n HTTP/1.0 200 OK\r\nDate: Tue, 16 Apr 2013 23:53:28 GMT\r\nServer: Apache\r\nExpires: Mon, 20 Aug 2002 02:00:00 GMT\r\nPragma: no-cache\r\nCache-Control: no-cache\r\nContent-Transfer-Encoding: binary\r\nContent-Disposition: inline; filename=setup.exe\r\nContent-Length: 39296\r\nContent-Type: application/octet-stream\r\nX-Cache: MISS from localhost\r\nX-Cache-Lookup: MISS from localhost:80\r\nVia: 1.0 localhost (squid/3.1.19)\r\nConnection: keep-alive\r\n\r\n",
              "original":"setup.exe",
              "name":"Malware.Binary.FEC2",
              "originalInfectionId":3181,
              "originalInfectionType":"MALWARE_OBJECT",
              "originalInfectionUrl":"https://10.11.113.143/botnets/events_for_bot?ma_id=3181",
              "sid":"0",
              "type":"exe",
              "stype":"avs"
            },
            {
              "md5Sum":"fe4d8f227520e2468dd1019496ef0604",
              "sha256":"b71e3012e93f11a7b0b179ea54eeb0e787d02acc48705833e
414a5e57a6a2032",
              "application":"application:57",
              "httpHeader":"GET http://getapac.com/75.html HTTP/1.1\r\nUser-Agent: Mozilla/4.0 (Windows XP 5.1) Java/1.6.0_16\r\nHost: getapac.com\r\nAccept: text/html, image/gif, image/jpeg, *; q=.2, */*; q=.2\r\nProxy-Connection: keep-alive\r\n\r\n HTTP/1.0 200 OK\r\nDate: Tue, 16 Apr 2013 23:53:28 GMT\r\nServer: Apache\r\nExpires: Mon, 20 Aug 2002 02:00:00 GMT\r\nPragma: no-cache\r\nCache-Control: no-cache\r\nContent-Transfer-Encoding: binary\r\nContent-Disposition: inline; filename=setup.exe\r\nContent-Length: 39296\r\nContent-Type: application/octet-stream\r\nX-Cache: MISS from localhost\r\nX-Cache-Lookup: MISS from localhost:80\r\nVia: 1.0 localhost (squid/3.1.19)\r\nConnection: keep-alive\r\n\r\n",
              "original":"setup.exe",
              "name":"JavaExploit.EncryptedPayload",
              "originalInfectionId":3181,
              "originalInfectionType":"MALWARE_OBJECT",
              "originalInfectionUrl":"https://10.11.113.143/botnets/events_for_bot?ma_id=3181",
              "type":"exe"
            }
          ]
        },
        "osChanges": [
          {
            "application": {"app-name":"Windows Explorer"},
            "os": {
              "name":"windows",
              "arch":"x64",
              "version":"6.1.7601",
              "sp":1
            },
            "file_informational": [
              {
                "mode":"close",
                "fid": {
                  "ads":"",
                  "content": 3377699720613027
                },
                "sha1sum":"ba5a1564d46348272f970f3c836a9f038528017d",
                "md5sum":"8f66978e66faf1262eca66984f9ee056",
                "processinfo": {
                  "imagepath":"C:\\Windows\\System32\\taskhost.exe",
                  "md5sum":"639774c9acd063f028f6084abf5593ad",
                  "pid":3020
                },
                "sha256sum":"3169bac13d2b500e9deb43c9cbcc27eadfba4d94870c
f7698cb58297d111212b",
                "ntstatus":"0x0",
                "filesize":24576,
                "no_extend":true,
                "value":"C:\\Windows\\System32\\config\\RegBack\\SECURITY",
                "CreateOptions":"0x0",
                "timestamp":2243
              },
              {
                "mode":"close",
                "fid": {
                  "ads":"",
                  "content":1125899906949946
                },
                "processinfo": {
                  "imagepath":"C:\\Windows\\System32\\taskhost.exe",
                  "md5sum":"639774c9acd063f028f6084abf5593ad",
                  "pid":3020
                },
                "ntstatus":"0x0",
                "no_extend":true,
                "value":"C:\\Windows\\System32\\config\\RegBack\\SECURITY.
LOG1",
                "CreateOptions":"0x0",
                "timestamp":2300
              },
              {
                "mode":"close",
                "fid": {
                  "ads":"",
                  "content":1125899906949947
                },
                "processinfo": {
                  "imagepath":"C:\\Windows\\System32\\taskhost.exe",
                  "md5sum":"639774c9acd063f028f6084abf5593ad",
                  "pid":3020
                },
                "ntstatus":"0x0",
                "no_extend":true,
                "value":"C:\\Windows\\System32\\config\\RegBack\\SECURITY
.LOG2",
                "CreateOptions":"0x0",
                "timestamp":2315
              },
              {
                "mode":"close",
                "fid": {
                  "ads":"",
                  "content":281474976922429
                },
                "sha1sum":"4e9c5284532d348c4845014c349aa88c231e96e4",
                "md5sum":"240fb08bc218a72a1bc6a245d52e7314",
                "processinfo": {
                  "imagepath":"C:\\Program Files\\Windows Defender\\MpCmdRun.exe",
                  "md5sum":"6bd4d7f68924301051c22e8a951aecba",
                  "pid":3136
                },
                "sha256sum":"a31dcd30c693424b189878d5bd5201cd150578dd906b
547613a709dccce7978a",
                "ntstatus":"0x0",
                "filesize":6662,
                "no_extend":true,
                "value":"C:\\Windows\\Temp\\MpCmdRun.log",
                "CreateOptions":"0x0",
                "timestamp":10183
              },
              {
                "mode":"close",
                "fid": {
                  "ads":"",
                  "content":4222124650748166
                },
                "sha1sum":"af9075a443b76bbe741eceb4188847ac93ff6d6b",
                "md5sum":"f857040c35dc58409500336994a0ef2a",
                "processinfo": {
                  "imagepath":"N/A",
                  "pid":4
                },
                "sha256sum":"97cc6174ef09d68f1693e2821a5e71a24578a86f64c
662a030da93509e483066",
                "ntstatus":"0x0",
                "filesize":196608,
                "no_extend":true,
                "value":"C:\\Windows\\Logs\\SystemRestore\\PropertyPage
.0.etl",
                "CreateOptions":"0x0",
                "timestamp":11184
              },
              {
                "mode":"close",
                "fid": {
                  "ads":"",
                  "content":3659174697325736
                },
                "sha1sum":"15e828174e57fd35b4675d6e06c9c1c01830d2ca",
                "md5sum":"e1ac844fc640df3517f42b32c31b3c05",
                "processinfo": {
                  "imagepath":"C:\\Windows\\System32\\taskhost.exe",
                  "md5sum":"639774c9acd063f028f6084abf5593ad",
                  "pid":3020
                },
                "sha256sum":"d0af7af8ff3c3ba6bbb4289dc4e5b2ea1410d72e8615
3d747473e9faead853b1",
                "ntstatus":"0x0",
                "filesize":62521344,
                "no_extend":true,
                "value":"C:\\Windows\\System32\\config\\RegBack
\\SOFTWARE",
                "CreateOptions":"0x0",
                "timestamp":11467
              },
              {
                "mode":"close",
                "fid": {
                  "ads":"",
                  "content":1125899906949948
                },
                "processinfo": {
                  "imagepath":"C:\\Windows\\System32\\taskhost.exe",
                  "md5sum":"639774c9acd063f028f6084abf5593ad",
                  "pid":3020
                },
                "ntstatus":"0x0",
                "no_extend":true,
                "value":"C:\\Windows\\System32\\config\\RegBack
\\SOFTWARE.LOG1",
                "CreateOptions":"0x0",
                "timestamp":12375
              },
              {
                "mode":"close",
                "fid": {
                  "ads":"",
                  "content":1125899906949949
                },
                "processinfo": {
                  "imagepath":"C:\\Windows\\System32\\taskhost.exe",
                  "md5sum":"639774c9acd063f028f6084abf5593ad",
                  "pid": 3020
                },
                "ntstatus":"0x0",
                "no_extend": true,
                "value":"C:\\Windows\\System32\\config\\RegBack
\\SOFTWARE.LOG2",
                "CreateOptions":"0x0",
                "timestamp": 12381
              }
            ],
            "uac": [
              {
                "mode":"service",
                "buffered":true,
                "no_extend":true,
                "value":"Volume Shadow Copy",
                "timestamp":10905,
                "status":"running"
              },
              {
                "mode":"service",
                "buffered":true,
                "no_extend":true,
                "value":"Microsoft Software Shadow Copy Provider",
                "timestamp":12887,
                "status":"running"
              }
            ],
            "end-of-report":"",
            "process_informational": [
              {
                "fid":{
                  "ads":"",
                  "content":281474976725189
                },
                "parentname":"C:\\Program Files\\Windows Defender
\\MpCmdRun.exe",
                "sha256sum":"9afd12eede0db98a35aba52f53041efa4a2f2a0367
3672c7ac530830b7152392",
                "pid":2192,
                "filesize":190976,
                "ppid":3136,
                "mode":"started",
                "cmdline":"\"c:\\program files\\windows defender\\
MpCmdRun.exe\" Scan -ScheduleJob -WinTask -RestrictPrivilegesScan -Reinvoke",
                "sha1sum":"2ae2a6b863616b61ccb550fc1a145ae025896de1",
                "md5sum":"6bd4d7f68924301051c22e8a951aecba",
                "no_extend":true,
                "value":"C:\\Program Files\\Windows Defender\\MpCmdRun.exe",
                "timestamp":10153
              },
              {
                "fid": {
                  "ads":"",
                  "content":281474976780111
                },
                "parentname":"C:\\Windows\\System32\\services.exe",
                "sha256sum":"N/A",
                "pid":1492,
                "filesize":1600512,
                "ppid":480,
                "mode":"started",
                "cmdline":"C:\\Windows\\system32\\vssvc.exe",
                "sha1sum":"1d6f5a5de7154b75144c6a033c36fd86ff2bbe9b",
                "md5sum":"b60ba0bc31b0cb414593e169f6f21cc2",
                "no_extend":true,
                "value":"C:\\Windows\\System32\\VSSVC.exe",
                "timestamp":10547
              },
              {
                "fid": {
                  "ads":"",
                  "content":281474976737050
                },
                "parentname":"C:\\Windows\\System32\\services.exe",
                "sha256sum":"N/A",
                "pid":3632,
                "filesize":27136,
                "ppid":480,
                "mode":"started",
                "cmdline":"C:\\Windows\\System32\\svchost.exe -k swprv",
                "sha1sum":"619652b42afe5fb0e3719d7aeda7a5494ab193e8",
                "md5sum":"c78655bc80301d76ed4fef1c1ea40a7d",
                "no_extend":true,
                "value":"C:\\Windows\\System32\\svchost.exe",
                "timestamp":10836
              }
            ],
            "os_monitor": {
              "date":"Sep 19 2018",
              "build":795854,
              "time":"12:59:48",
              "version":"17R1.7"
            },
            "malicious-alert": [
              {
                "classtype":"static_log",
                "display-msg":"Static Analysis Malware.Binary.FEC2"
              },
              {
                "classtype":"Static-Analysis",
                "display-msg":"Static Analysis Malware.Binary.FEC2"
              },
              {
                "classtype":"static_log",
                "display-msg":"Static Analysis JavaExploit.EncryptedPayload"
              },
              {
                "classtype":"Static-Analysis",
                "display-msg":"Static Analysis JavaExploit.EncryptedPayload"
              },
              {
                "classtype":"sa_only",
                "display-msg":"Heuristic"
              }
            ],
            "analysis": {
              "mode":"malware",
              "product":"MPS",
              "ftype":"exe",
              "version":1.3977
            }
          },
          {
            "process": {
              "mode":"started",
              "fid": {
                "ads":"",
                "content":1688849860268247
              },
              "parentname":"C:\\WINDOWS\\explorer.exe",
              "cmdline":"\"C:\\WINDOWS\\system32\\ntvdm.exe\" -f -i1",
              "sha1sum":"df36cf59f700fc0b3b60c009b8b877d6233fdd72",
              "md5sum":"681b807e53bdada337735c28c0e48a1b",
              "sha256sum":"a0be52e7d076ed8e33a4b5ab309cd23ad0272570c7e87
fe6e3444712ad467d62",
              "pid":3456,
              "filesize":420864,
              "value":"C:\\WINDOWS\\system32\\ntvdm.exe",
              "timestamp":3478,
              "ppid": 1864
            },
            "application": {"app-name":"Windows Explorer"},
            "os": {
              "name":"windows",
              "arch":"x86",
              "version":"5.1.2600",
              "sp":3
            },
            "file_informational": [
              {
                "mode":"close",
                "fid": {
                  "ads":"",
                  "content":844424930200765
                },
                "sha1sum":"863bbf5f7f4114a1307c6bad5dd89224d511fed5",
                "md5sum":"4a587187d760161311010b03417b3c3f",
                "processinfo": {
                  "imagepath":"C:\\WINDOWS\\system32\\ntvdm.exe",
                  "md5sum":"681b807e53bdada337735c28c0e48a1b",
                  "pid":3456
                },
                "sha256sum":"b7792de7a6d7abb649a8a22e9048d0468b604ca98b
8978bdd1171356af6d5f49",
                "ntstatus":"0x0",
                "filesize":2686,
                "no_extend":true,
                "value":"C:\\WINDOWS\\Temp\\scs14.tmp",
                "CreateOptions":"0x0",
                "timestamp":3614
              },
              {
                "mode":"close",
                "fid": {
                  "ads":"",
                  "content":562949953490275
                },
                "sha1sum":"8565ed558ad273232104e0b10cd87cff723a1eca",
                "md5sum":"71f4b39c5eb73df738ad3e0dacd89057",
                "processinfo": {
                  "imagepath":"C:\\WINDOWS\\system32\\ntvdm.exe",
                  "md5sum":"681b807e53bdada337735c28c0e48a1b",
                  "pid":3456
                },
                "sha256sum":"d504b1c272cd0c92c4a365086cf884a4889653c89d56
02b6dadeffb33b83951d",
                "ntstatus":"0x0",
                "filesize":1670,
                "no_extend":true,
                "value":"C:\\WINDOWS\\Temp\\scs15.tmp",
                "CreateOptions":"0x0",
                "timestamp":3943
              }
            ],
            "end-of-report":"",
            "os_monitor": {
              "date":"Sep 19 2018",
              "build":795854,
              "time":"12:59:48",
              "version":"17R1.7"
            },
            "malicious-alert": [
              {
                "classtype":"static_log",
                "display-msg":"Static Analysis Malware.Binary.FEC2"
              },
              {
                "classtype":"Static-Analysis",
                "display-msg":"Static Analysis JavaExploit.EncryptedPayload"
              },
              {
                "classtype":"static_log",
                "display-msg":"Static Analysis JavaExploit.EncryptedPayload"
              },
              {
                "classtype":"Static-Analysis",
                "display-msg":"Static Analysis Malware.Binary.FEC2"
              },
              {
                "classtype":"NTVDM-Process-Launch-Activity",
                "display-msg":"Startup behavior anomalies observed"
              },
              {
                "classtype":"sa_only",
                "display-msg":"Heuristic"
              }
            ],
            "analysis": {
              "mode":"malware",
              "product":"MPS",
              "ftype":"exe",
              "version":1.3977
            }
          }
        ]
      },
      "src": {
        "ip":"157.204.181.231",
        "mac":"00:20:18:11:ff:45",
        "port": 0
      },
      "alertUrl":"https://qa-cm7500-4-9-20/event_stream/events_for_bot?ma_id=261146",
      "action":"notified",
      "occurred":"2018-10-18 16:46:41 +0000",
      "dst": {
        "mac":"02:14:17:da:c9:2f",
        "port": 0,
        "ip":"249.207.161.251"
      },
      "applianceId":"000BABCD66F2",
      "id": 261146,
      "rootInfection": 3181,
      "sensorIp":"10.11.113.155",
      "name":"MALWARE_OBJECT",
      "severity":"MAJR",
      "uuid":"c9391258-1a79-4b54-be8e-144ddb5f118f",
      "ack":"yes",
      "product":"WEB_MPS",
      "sensor":"cms-nx2500-3",
      "vlan": 0,
      "malicious":"yes"
    }
  ],
  "appliance":"CMS",
  "version":"CMS (CMS) 8.4.0.805144",
  "msg":"normal",
  "alertsCount": 1
}

Note

The "uuid" and "ack" fields are only supported in v2.0.0.