Malware Analysis 10.0.2 Release Notes

Prev Next

This is the latest release of Trellix Malware Analysis

General enhancements

This section describes the enhancements which are a part of the Trellix Malware Analysis release 10.0.2.

  • A new CLI is introduced to search for intel feed information. The CLI displays the signature , source and other details of an SHA-256 hash file, URL, or MD5 checksum.

  • A new CLI is added to configure the alert retention period and the deletion cron execution time in AX appliances.

  • The HTM file type is now enabled by default, for pre-filtering.

  • The triage bundle and log archive password is changed to Trellix Customer Support Archive.

New CLI commands

The CLI commands in this section were added in this release.

CLIs to search details of intel feeds

Use the following CLIs to search the details of the corresponding intel feeds.

  • show analysis intel url <URL> : Displays intel information for the mentioned URL.

  • show analysis intel sha256 <sha256> : Displays intel information for the mentioned sha256.

  • show analysis intel md5 <md5> : Displays intel information for the mentioned md5.

CLIs to configure alert retention period and the deletion cron execution time

Use the following CLIs to configure alert retention period and the deletion cron execution time

  • fedb data-retention alert duration-days <1 - 3650>

  • fedb data-retention alert schedule-time <00-23:00-59>

CLI to enable HTM file type

Use the following CLI to enable HTM file type. Use the 'no' form of the command to disable it.

  • filter-analysis filetype htm enable

Resolved issues

The following issues were resolved in the Malware Analysis 10.0.2 release.

Tracking number

Summary

CMS-17212

Fixes an issue where a managed appliance, such as NX, could not reconnect to CMS after a client-initiated connection was interrupted.

CMS-17133

Fixes submissions hierarchy issues.

COM-30655

Fixes the issue of prolonged processing of database backup when alert purge is in progress.

COM-30659

Fixes the issue of missing alert details in the report generated during alert purging.

COM-31326

Fixes an issue where the WebUI failed to accept PEM bundles with MS-DOS <CR><LF> line endings.

COM-31673

Java libraries are upgraded to address CVEs.

COM-62169

Fixes an issue where the user was not able to include additional custom sha256 hashes to their blacklist after reaching 300 entries approx.

COM-62177

Fixes an issue where the Malware Analysis appliance was trying to reach port 8.8.8.8 through the IP which was not configured as the DNS Server.

COM-62263

Fixes an issue where enabling NTP affects backup, reset, and restore functionality due to restrictions on the timezone changes.

COM-62368

Fixes an issue where adding a root CA was failing in rare cases.

MAS-3990

Fixes the issue of missing fields in the alert notifications.

MAS-4035

Fixes issues faced while downloading large PCAP files.

Known issues

The following issues are known in the Malware Analysis 10.0.2 release.

Tracking number

Summary

MAS-4022

File samples submitted via the API are not analyzed and are stuck in queued state. The issue is observed in multiple boxes.

Upgrade support

The Trellix Malware Analysis 10.0.2 release requires a reboot for the update to take effect. You can upgrade your AX appliance to 10.0.2 from release 9.0.0 or later.

After an upgrade to version 10.0.2, the dashboard will not retain prior data for Analysis Statistics and File Analysis Statistics.

After an upgrade to version 10.0.2, the dashboard statistics may not be accurate for the first three hours. Scan statistics are not affected.

Created Log archive files will not be preserved on upgrade to 10.0.2. Please have a backup of logs before upgrade.

Important

When you upgrade an Malware Analysis appliance to 10.0.2, FireEye Advanced URL Defense Engine (FAUDE) is enabled even if they were previously disabled. See "Enabling or Disabling Advanced URL Defense" in the

Malware Analysis User Guide

.

Note

After an upgrade to version 10.0.2, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.2.

Downloading content from the DTI offline update portal

If you download Malware Analysis 10.0.2 security content from the DTI Offline Update Portal, use the SCNET-8.0 channel of the portal.

Caution

Downloading security content from a different channel will result in a loss of detection.

For details, see the Trellix DTI Offline Update Portal User Guide.

Upgrading IPMI 3.11 and BIOS 1.9 firmware for specific platforms

The AX 5550 model requires an upgrade to IPMI 3.11 and BIOS 1.9. You must install the IPMI upgrade before you upgrade the BIOS. (COM-25469)

For detailed instructions about upgrading IPMI, see the

System Administration Guide

.

To upgrade IPMI to version 3.11:

Note

IPMI network and password settings revert to factory defaults after this upgrade, and IPMI logs are deleted. Make a note of your settings and back up your IPMI logs.

Do not shut down or remove power from the appliance during the upgrade.

  1. Go to CLI configuration mode.

    hostname > enable

    hostname # configure terminal

  2. Begin the upgrade:

    hostname (config) # ipmi firmware update latest

  3. Confirm the upgrade:

    hostname (config) # show ipmi

If the upgrade fails, try the steps again.

If IPMI functions are not fully restored, perform a full power cycle (cold shutdown) on the appliance:

  1. Stop the reload process:

    hostname (config) # reload halt

  2. Disconnect all power cables for 2 minutes.

  3. After 2 minutes, reconnect power cables and restart the appliance.

To upgrade the BIOS to version 1.9:

  1. Go to CLI configuration mode.

    hostname > enable

    hostname # configure terminal

  2. Begin the upgrade:

    hostname (config) # system bios firmware update latest

    Note

    Do not shut down or remove power from the appliance during the upgrade.

  3. Confirm the upgrade:

    hostname (config) # show system bios

  4. Stop the reload process:

    hostname (config) # reload halt

  5. Disconnect all power cables for 2 minutes.

  6. After 2 minutes, reconnect power cables and restart the appliance.

YARA rules supported versions

YARA rules support version 4.3.2.

Important

Before you upgrade an Malware Analysis appliance to the 10.0.2 release, modify any custom YARA rules to YARA 4.3.2. For details about YARA 4.3.2, see YARA's Documentation, Release 4.3.2 by Victor Alvarez.

Enabling access to intel context

Advanced Threat Intelligence (ATI) is a cloud-based data collection and threat intelligence distribution feature that provides actionable information about MVX-verified events on appliances. The threat intelligence tells you who is the threat actor behind an attack, what has been targeted or breached, and (if known) how to mitigate the threat. The Trellix Research Labs team continually uploads the latest threat intelligence to the Trellix Dynamic Threat Intelligence (DTI) cloud. When an MVX-verified event triggers an alert, the appliance queries the DTI server for threat intelligence and stores the additional information in its database. When you display an ATI alert, the alert details include the threat intelligence.

Appliances now need access to the Amazon Web Services (AWS) cloud for ATI communication. The intel context service is hosted in multiple AWS regions and resolves to multiple IP addresses based on geographic location. To determine the IP addresses for your location, go to https://dnschecker.org. See the AWS IP address range documentation for information about adding the IP addresses to the allow list.