Files
malware-watch/README.md
T
2026-09-03 11:24:18 +09:00

2.9 KiB

malware-watch installer

English | 한국어

malware-watch combines process/network behavior detection, abuse.ch ThreatFox/MalwareBazaar IOC feeds, confirmed-threat automatic quarantine, persistent IOC firewall blocking, and optional ClamAV scanning.

Files

  • install.sh — installs malware-watch, abuse.ch feed updater, automatic quarantine, IOC firewall restore, systemd timers, and optional official ClamAV.
  • verify.sh — verifies that the installation is healthy.
  • .env — installer configuration. Replace the placeholder values locally before installation.

The repository version of .env contains placeholders only. Never commit a real Discord webhook or abuse.ch Auth-Key.

Install

git clone https://github.com/javara999/malware-watch.git
cd malware-watch
chmod +x install.sh verify.sh
nano .env
sudo ./install.sh

Required .env values:

DISCORD_WEBHOOK='디스코드웹훅URL'
ABUSECH_AUTH_KEY='abuse.ch api 키'

Replace both placeholder strings with your real values only on the server where you are installing.

The installer is safe to rerun after a partial/failed installation. Existing malware-watch files are backed up under /root/security-evidence/malware-watch/install-backup-* before replacement.

Verify installation

sudo ./verify.sh

It checks required files/permissions, malware-watch and abuse.ch timers, ThreatFox/MalwareBazaar feeds, ClamAV installation/account/signature DB/timers, and a real one-shot execution of malware-watch.py.

A healthy installation ends with:

Summary: PASS=<number> WARN=0 FAIL=0

A WARN for the ClamAV signature DB immediately after installation can be normal: freshclam may still be waiting for its first successful download. FAIL means something should be fixed.

To also send a harmless Discord verification message:

sudo ./verify.sh --test-discord

Manual status checks

systemctl status malware-watch.timer --no-pager
systemctl status malware-feed-update.timer --no-pager
systemctl status clamav-freshclam-local.timer --no-pager
systemctl status clamav-risk-scan.timer --no-pager
systemctl status clamav-deep-scan.timer --no-pager
systemctl list-timers --all --no-pager | grep -E 'malware-watch|malware-feed-update|clamav-'

Useful logs:

journalctl -u malware-watch.service -n 100 --no-pager
journalctl -u malware-feed-update.service -n 100 --no-pager
journalctl -u clamav-risk-scan.service -n 100 --no-pager
journalctl -u clamav-deep-scan.service -n 100 --no-pager
journalctl -u clamav-freshclam-local.service -n 100 --no-pager

Security notes

  • Confirmed threats are quarantined; ordinary heuristic/high-score findings are not automatically deleted.
  • Quarantine/evidence is stored under /root/security-evidence/.
  • .env should be mode 600 on an installed server.
  • Keep real webhook/API credentials out of Git history.