Malware Analysis 10.0.4 Release Notes

Prev Next

Note

Release 10.0.4 is the current release after 10.0.2 for Malware Analysis.

Resolved issues

The following issues were resolved in the Malware Analysis 10.0.4 release.

Tracking number

Summary

COM-62557

To further harden the security of our products, we have upgraded Apache HTTPd to version 2.4.62, the latest stable release.

COM-31727

To mitigate the Terrapin Vulnerability (CVE-2023-48795), the chacha20 cipher is removed from our high-security list for non-FIPS/non-CC customers using the high-security list. Now, the Trellix platform is not vulnerable to Terrapin Vulnerability (CVE-2023-48795) with default configuration. We plan to upgrade to the latest stable version of OpenSSH in the upcoming 11.0 major release to further harden and resolve the vulnerable option related to the Terrapin Vulnerability.

Known issues

The following issues are known in the Malware Analysis 10.0.4 release.

Tracking number

Summary

MAS-4022

File samples submitted via the API are not analyzed and are stuck in queued state. The issue is observed in multiple boxes.

Upgrade support

The Trellix Malware Analysis 10.0.4 release requires a reboot for the update to take effect. You can upgrade your AX appliance to 10.0.4 from release 9.0.0 or later.

After an upgrade to version 10.0.4, the dashboard will not retain prior data for Analysis Statistics and File Analysis Statistics.

After an upgrade to version 10.0.4, the dashboard statistics may not be accurate for the first three hours. Scan statistics are not affected.

Created Log archive files will not be preserved on upgrade to 10.0.4. Please have a backup of logs before upgrade.

Important

When you upgrade an Malware Analysis appliance to 10.0.4, FireEye Advanced URL Defense Engine (FAUDE) is enabled even if they were previously disabled. See "Enabling or Disabling Advanced URL Defense" in the

Malware Analysis User Guide

.

Note

After an upgrade to version 10.0.4, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.4.

Downloading content from the DTI offline update portal

If you download Malware Analysis 10.0.4 security content from the DTI Offline Update Portal, use the SCNET-8.0 channel of the portal.

Caution

Downloading security content from a different channel will result in a loss of detection.

For details, see the Trellix DTI Offline Update Portal User Guide.

YARA rules supported versions

YARA rules support version 4.3.2.

Important

Before you upgrade an Malware Analysis appliance to the 10.0.4 release, modify any custom YARA rules to YARA 4.3.2. For details about YARA 4.3.2, see YARA's Documentation, Release 4.3.2 by Victor Alvarez.

Enabling access to intel context

Advanced Threat Intelligence (ATI) is a cloud-based data collection and threat intelligence distribution feature that provides actionable information about MVX-verified events on appliances. The threat intelligence tells you who is the threat actor behind an attack, what has been targeted or breached, and (if known) how to mitigate the threat. The Trellix Research Labs team continually uploads the latest threat intelligence to the Trellix Dynamic Threat Intelligence (DTI) cloud. When an MVX-verified event triggers an alert, the appliance queries the DTI server for threat intelligence and stores the additional information in its database. When you display an ATI alert, the alert details include the threat intelligence.

Appliances now need access to the Amazon Web Services (AWS) cloud for ATI communication. The intel context service is hosted in multiple AWS regions and resolves to multiple IP addresses based on geographic location. To determine the IP addresses for your location, go to https://dnschecker.org. See the AWS IP address range documentation for information about adding the IP addresses to the allow list.