Downloaded files list

The Downloaded files list displays a list of distinct, unique files that have been downloaded by hosts in the network.

The quick search field above the list provides fast, as-you-type search. It filters the rows in the list, displaying only those rows that have text, in any field, that matches the query string.

The columns to be displayed in the list can be customized by clicking the additional content icon.

Customize the number of rows to be displayed. The default is 20 entries. Use the left arrow (back) and right arrow (forward) icons to navigate through multiple pages.

Each row is a summary of a downloaded file. Click the plus icon (or anywhere on an entry row) to access a detailed view of the downloaded file.

The list is sorted by score and includes the following fields:

MD5

The MD5 hash of the downloaded file.

Type

The high-level file type of the downloaded file. Supported types are currently:

  • Archive Archive formats such as ZIP or RAR

  • Document Includes other types of Office documents

  • Executable Binary program formats such as Windows Portable Executable

  • Java Java application or applet

  • Media Macromedia (Adobe) Flash file

  • Other Other recognized file format

  • PDF Portable Document Format files

  • Script An executable script such as JavaScript, Python, and others

  • Unknown Unknown file type

Size

Size in bytes of the downloaded file.

Downloads

Number of times that the file was downloaded by hosts in the network.

The displayed number and details icon provide a link to the detailed downloads page. The link passes an Analyst UUID filter that restricts the view to downloads of this specific file.

AV Class

A label defining the antivirus class of the downloaded file. If the label has a tag icon, you can click that for a pop-up description.

Malware

A label defining the malware type of the downloaded file. If the label has a tag icon, you can click that for a pop-up description.

Score

The score assigned to the downloaded file by the analysis indicates the critical level of the detected threat and ranges from 0 to 100:

  • Threats that are 70 or above are considered to be critical.

  • Threats that are between 30 and 69 are considered to be medium-risk.

  • Threats that are between 1 and 30 are considered to be benign.

For details, see Maliciousness score and Risk estimate.

If the stop icon appears, it indicates the artifact has been blocked.

The list is sorted by decreasing order (most critical threats at the top). Click the angle up icon to sort the list in increasing order (least critical threats at the top), then click the angle down icon to toggle back to the default.