ListCompressFileDetectResult
Retrieves the detection results of files within a compressed archive.
Operation description
Only files that have been submitted for detection and identified as compressed archives can be queried through this operation. Detection results are retained for 5 hours and can be queried repeatedly within that period. To submit a file for detection, refer to CreateFileDetect. To retrieve the detection result of the compressed archive file itself, refer to GetFileDetectResult.
All file detection operations include the HashKey parameter, which represents the unique identifier of a file.
In the malicious file detection scenario (Type is 0), only the MD5 or SHA-256 hash of the complete file content is supported. Calculate this value before calling the operation.
In the Skill compressed archive detection scenario (Type is 6), obtain the value from the response of the CreateFileDetect operation.
Note that the submission and query operations for a single detection must use the same HashKey. Otherwise, the detection cannot be correctly submitted or the results cannot be correctly queried.
Compressed archive detection workflow
To retrieve the detection results of files within a compressed archive, complete the following four steps in order:
Call the CreateFileDetectUploadUrl operation to obtain a file upload URL.
Upload the file to be detected to OSS.
Call the CreateFileDetect operation to submit the file for detection, and set the Decompress parameter to true.
Call this operation (ListCompressFileDetectResult) to query the detection results of files within the compressed archive.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:ListCompressFileDetectResult |
list |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| SourceIp |
string |
No |
The source IP address of the request. |
27.9.XX.XX |
| HashKey |
string |
No |
The unique identifier of the file. This parameter is required in practice. If this parameter is not specified, the API returns ServerError (500). The value must be the MD5 or SHA-256 hash of the file. |
0a212417e65c26ff133cfff28f6c**** |
| CurrentPage |
integer |
Yes |
The page number of the current page in a paging query. Default value: 1. |
1 |
| PageSize |
integer |
Yes |
The maximum number of entries per page in a paging query. Default value: 20. |
20 |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| RequestId |
string |
The request ID, which is a unique identifier generated by Alibaba Cloud for the request. You can use this ID to troubleshoot issues. |
E10BAF1C-A6C5-51E2-866C-76D5922E**** |
| PageInfo |
object |
The pagination information. |
|
| CurrentPage |
integer |
The page number of the current page in a paging query. |
1 |
| PageSize |
integer |
The maximum number of entries per page in a paging query. |
20 |
| TotalCount |
integer |
The total number of entries. |
55 |
| ResultList |
array<object> |
The detection results of files within the compressed archive. |
|
|
object |
The file detection result information. |
||
| HashKey |
string |
The file identifier. |
0a212417e65c26ff133cfff28f6c**** |
| Result |
integer |
The file detection result. Valid values:
|
0 |
| Score |
integer |
The file detection score. The following list describes the mapping between score ranges and risk levels:
Important A higher score indicates a more suspicious file. Note
This parameter is not supported when Type is 6. |
100 |
| VirusType |
string |
The virus type. Valid values:
Note
This parameter is invalid when Result is 0 or 3. |
WebShell |
| Ext |
string |
The extended information of the detection result. |
{ "HighLight": [ [ 23245, 23212 ] ], "FileLabel": [ "PE32", "Zip", "SFX", "encrypted" ] } |
| Path |
string |
The path of the file within the compressed archive. |
/root/1.zip/test**** |
Examples
Success response
JSON format
{
"RequestId": "E10BAF1C-A6C5-51E2-866C-76D5922E****",
"PageInfo": {
"CurrentPage": 1,
"PageSize": 20,
"TotalCount": 55
},
"ResultList": [
{
"HashKey": "0a212417e65c26ff133cfff28f6c****",
"Result": 0,
"Score": 100,
"VirusType": "WebShell",
"Ext": "{\n \"HighLight\":\n [\n [\n 23245,\n 23212\n ]\n ],\n \"FileLabel\":\n [\n \"PE32\",\n \"Zip\",\n \"SFX\",\n \"encrypted\"\n ]\n}",
"Path": "/root/1.zip/test****"
}
]
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | RequestTooFrequently | Request too frequently, please try again later | |
| 400 | GetResultFail | Get result fail, found no detect record for this file or result has been expired | |
| 400 | InvalidApiDetectType | Unsupported Api Detect Type. | The file type is not supported. |
| 500 | ServerError | ServerError | |
| 500 | SystemBusy | System busy, please try again later. | |
| 403 | NoPermission | caller has no permission | You are not authorized to do this operation. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.