使用SophosLabs Intelix静态文件分析API持续返回BAD REQUEST问题
调用Sophos静态文件分析API始终返回400 BAD REQUEST的问题
尝试调用Sophos静态文件分析API,但每次都收到400 BAD REQUEST响应。以下是请求细节和异常信息:
请求示例
$headers Name Value ---- ----- Authorization <Auth token> Content-Type multipart/form-data $formData Name Value ---- ----- file C:\Temp\mexnixzv.gsk\outlook.exe name file filename outlook.exe report_format json $uri https://de.api.labs.sophos.com/analysis/file/static/v1/ Invoke-WebRequest -URI $uri -Method POST -Headers $headers -Form $formData -UseDefaultCredentials
异常信息
$_.Exception Response : StatusCode: 400, ReasonPhrase: 'BAD REQUEST', Version: 1.1, Content: System.Net.Http.HttpConnectionResponseContent, Headers: { Connection: keep-alive Date: Wed, 25 Sep 2024 07:16:05 GMT Access-Control-Allow-Headers: Authorization, X-Correlation-ID, * Server: Sophos Intelix Content-Security-Policy: default-src https:; script-src https: 'unsafe-inline'; style-src https: 'unsafe-inline' Referrer-Policy: same-origin Strict-Transport-Security: max-age=31536000; includeSubDomains X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Request-ID: db629807-65b5-4937-940e-0e62bd548320 X-Rate-Limit-Value: 30 X-Rate-Limit-Period: 60 X-Rate-Limit-Requests-Left: 29 X-Rate-Limit-End: 0.0 Access-Control-Allow-Origin: * Access-Control-Allow-Credentials: true Access-Control-Allow-Methods: GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS X-Cache: Error from cloudfront Via: 1.1 cf058b286fa80390c08073fa68269f12.cloudfront.net (CloudFront) X-Amz-Cf-Pop: TXL50-P1 X-Amz-Cf-Id: 5vr6sgHb7DeHswIg9F9WAqwzhSesGbw8CvudJEqP7husRI2gKUKVIg== Content-Type: application/json Content-Length: 120 } HttpRequestError : Unknown StatusCode : BadRequest TargetSite : Void ThrowTerminatingError(System.Management.Automation.ErrorRecord) Message : Response status code does not indicate success: 400 (BAD REQUEST). Data : {} InnerException : HelpLink : Source : System.Management.Automation HResult : -2146233088 StackTrace : at System.Management.Automation.MshCommandRuntime.ThrowTerminatingError(ErrorRecord errorRecord)
已尝试的排查步骤
- 更换不同文件格式(Excel、CSV、JPG)
- 测试不同大小的文件(几字节到数MB)
- 使用不同工具调用(PowerShell、curl、官网直接调用)
所有尝试均返回相同的400 BAD REQUEST响应,请问是操作有误还是API端故障?
问题排查与解决建议
修正Authorization令牌格式
确保Auth token以Bearer前缀开头(格式为Bearer <your-token>),多数400错误源于缺少该前缀。移除手动设置的Content-Type头
PowerShell的-Form参数会自动生成带boundary的multipart/form-data头,手动设置会导致格式错误,直接从$headers中删除Content-Type项即可。修正file参数的传递方式
file参数需要传入文件内容而非路径,可通过以下方式读取文件:$fileContent = Get-Content "C:\Temp\mexnixzv.gsk\outlook.exe" -Raw -Encoding Byte再将
$fileContent赋值给formData中的file字段。获取具体错误详情
400响应的JSON内容包含具体错误原因,可通过以下代码提取:try { Invoke-WebRequest -URI $uri -Method POST -Headers $headers -Form $formData -UseDefaultCredentials } catch { $errorDetails = $_.Exception.Response.Content.ReadAsStringAsync().Result Write-Host $errorDetails }验证端点区域匹配性
确认de.api.labs.sophos.com端点与你的令牌所属区域一致,若令牌属于其他区域,需切换对应端点。
内容的提问来源于stack exchange,提问作者mvdtm
相关产品推荐
相关产品推荐

