New Badfellas 2.6.488 to spot malware and botnets
Hey Trisul users, please update your Badfellas plugin to the latest version released today.
Major updates in this release.
- The popular abuse.ch Malware Database has been discontinued and Palevo Tracker is introduced. Badfellas now holds up your traffic against known Palevo C&C Domains and IPs.
- The Malware Domains DNS Blackhole lists was not working with earlier versions of Badfellas due to incorrect parsing of some entries. This is now fixed.
- Enhanced catching of malware (see below)
Donate to these lists Please consider donating to the good folks who run the above lists.
Enhanced catching
Trisul 2.6 further enhances detection by parsing DNS records and picking out additional answer AA and CNAME entries for checking with these lists. Even if a compromised system on your network tried to unsuccessfully resolve one of these C&C hosts, Trisul Badfellas will flag that.
Current users please note
If you are installing Badfellas for the first time, you may skip this section.
Existing users of Badfellas need to follow these steps to update.
- Stop Trisul
- Uninstall Badfellas (rpm -e)
- Install new (rpm -Uvh)
- Delete the old config file
/usr/local/etc/trisul/PI-9FE*
It will be recreated afresh. - Start Trisul
The new lists will take effect within 5 minutes.
New to Trisul ?
Download Trisul and Badfellas today. Its free for a rolling 3-day window.