Callback Overview Statistics

Retrieve aggregate statistics for callback IPs including counts by
attack stage, file analysis status, scanner associations, and top
threat names.

Body Params

Common filter fields for callback IP queries.

boolean

Filter by stage 1 status. true = file downloaded from this IP.

boolean

Filter by stage 2 status. true = suspected C2 based on VT/sandbox analysis.

date

Only include IPs first seen after this date (YYYY-MM-DD).

date

Only include IPs first seen before this date (YYYY-MM-DD).

date

Only include IPs last seen after this date (YYYY-MM-DD).

date

Only include IPs last seen before this date (YYYY-MM-DD).

boolean

If true, only include IPs with associated malware files. If false, only IPs without files.

string

Filter by file MIME type (e.g. "application/x-executable").

string

Filter by file name substring match.

string

Filter by file SHA256 hash.

scanner_ips
array of strings

Filter to IPs associated with these scanner IPs.

scanner_ips
ips
array of strings

Filter to this specific set of callback IPs.

ips
Responses

Language
Credentials
Header
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json