Well I have to say, it wasn't really a good idea to put malwares files directly on your business domain, even for research purposes and with encryption.
Send a link to an external host next time !
They're just clicking the decline button, and its affecting our business.
Does your api use theses paths as well ?
Only the path '/download' seems affected. I don't understand why your api would use that though.