ListCompressFileDetectResult

Updated at:

Retrieves the detection results of files within a compressed archive.

Operation description

Only files that have been submitted for detection and identified as compressed archives can be queried through this operation. Detection results are retained for 5 hours and can be queried repeatedly within that period. To submit a file for detection, refer to CreateFileDetect. To retrieve the detection result of the compressed archive file itself, refer to GetFileDetectResult.

All file detection operations include the HashKey parameter, which represents the unique identifier of a file.

In the malicious file detection scenario (Type is 0), only the MD5 or SHA-256 hash of the complete file content is supported. Calculate this value before calling the operation.

In the Skill compressed archive detection scenario (Type is 6), obtain the value from the response of the CreateFileDetect operation.

Note that the submission and query operations for a single detection must use the same HashKey. Otherwise, the detection cannot be correctly submitted or the results cannot be correctly queried.

Compressed archive detection workflow

To retrieve the detection results of files within a compressed archive, complete the following four steps in order:

  1. Call the CreateFileDetectUploadUrl operation to obtain a file upload URL.

  2. Upload the file to be detected to OSS.

  3. Call the CreateFileDetect operation to submit the file for detection, and set the Decompress parameter to true.

  4. Call this operation (ListCompressFileDetectResult) to query the detection results of files within the compressed archive.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:ListCompressFileDetectResult

list

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

SourceIp

string

No

The source IP address of the request.

27.9.XX.XX

HashKey

string

No

The unique identifier of the file. This parameter is required in practice. If this parameter is not specified, the API returns ServerError (500). The value must be the MD5 or SHA-256 hash of the file.

0a212417e65c26ff133cfff28f6c****

CurrentPage

integer

Yes

The page number of the current page in a paging query. Default value: 1.

1

PageSize

integer

Yes

The maximum number of entries per page in a paging query. Default value: 20.

20

Response elements

Element

Type

Description

Example

object

RequestId

string

The request ID, which is a unique identifier generated by Alibaba Cloud for the request. You can use this ID to troubleshoot issues.

E10BAF1C-A6C5-51E2-866C-76D5922E****

PageInfo

object

The pagination information.

CurrentPage

integer

The page number of the current page in a paging query.

1

PageSize

integer

The maximum number of entries per page in a paging query.

20

TotalCount

integer

The total number of entries.

55

ResultList

array<object>

The detection results of files within the compressed archive.

object

The file detection result information.

HashKey

string

The file identifier.

0a212417e65c26ff133cfff28f6c****

Result

integer

The file detection result. Valid values:

  • 0: Safe file.

  • 1: Suspicious file.

  • 3: Detection in progress. Wait for the detection to complete.

0

Score

integer

The file detection score. The following list describes the mapping between score ranges and risk levels:

  • 0 to 60: Safe.

  • 61 to 70: Risky.

  • 71 to 80: Suspicious.

  • 81 to 100: Malicious.

Important A higher score indicates a more suspicious file.
Note

This parameter is not supported when Type is 6.

100

VirusType

string

The virus type. Valid values:

  • Trojan: Self-mutating trojan.

  • WebShell: Web shell.

  • Backdoor: Backdoor program.

  • RansomWare: Ransomware.

  • Scanner: Scanner.

  • Stealer: Credential stealer.

  • Malbaseware: Contaminated base software.

  • Hacktool: Hacking tool.

  • Engtest: DPI engine test program.

  • Downloader: Downloader trojan.

  • Virus: File-infecting virus.

  • Miner: Mining programs.

  • Worm: Worms.

  • DDoS: DDoS Trojan.

  • Malware: Malicious program.

  • Backdoor: Reverse shell backdoor.

  • RiskWare: Risky software.

  • Proxytool: Proxy tool.

  • Suspicious: Suspicious program.

  • MalScript: Malicious script.

  • Rootkit: Rootkit.

  • Exploit: Vulnerability exploits.

Note

This parameter is invalid when Result is 0 or 3.

WebShell

Ext

string

The extended information of the detection result.

{ "HighLight": [ [ 23245, 23212 ] ], "FileLabel": [ "PE32", "Zip", "SFX", "encrypted" ] }

Path

string

The path of the file within the compressed archive.

/root/1.zip/test****

Examples

Success response

JSON format

{
  "RequestId": "E10BAF1C-A6C5-51E2-866C-76D5922E****",
  "PageInfo": {
    "CurrentPage": 1,
    "PageSize": 20,
    "TotalCount": 55
  },
  "ResultList": [
    {
      "HashKey": "0a212417e65c26ff133cfff28f6c****",
      "Result": 0,
      "Score": 100,
      "VirusType": "WebShell",
      "Ext": "{\n    \"HighLight\":\n    [\n        [\n            23245,\n            23212\n        ]\n    ],\n    \"FileLabel\":\n    [\n        \"PE32\",\n        \"Zip\",\n        \"SFX\",\n        \"encrypted\"\n    ]\n}",
      "Path": "/root/1.zip/test****"
    }
  ]
}

Error codes

HTTP status code

Error code

Error message

Description

400 RequestTooFrequently Request too frequently, please try again later
400 GetResultFail Get result fail, found no detect record for this file or result has been expired
400 InvalidApiDetectType Unsupported Api Detect Type. The file type is not supported.
500 ServerError ServerError
500 SystemBusy System busy, please try again later.
403 NoPermission caller has no permission You are not authorized to do this operation.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.