cPanel ClamAV Antivirus: Hunting Webshells & Malware (2026)

Configure ClamAV scanner in cPanel and WHM to detect PHP webshells, eliminate clamd out-of-memory crashes, and automate background malware quarantine in Pakistan.

cPanel ClamAV Antivirus: Hunting Webshells & Malware (2026)

Web applications running WordPress, Joomla, or custom PHP scripts on Pakistani hosting environments are frequent targets for automated vulnerability scanners, credential stuffers, and backdoor injection bots. Once an unpatched plugin or theme vulnerability is exploited, attackers upload obfuscated PHP webshells (such as c99, b374k, or WSO) or inject illicit crypto-drainers and malicious SEO redirects directly into public_html.

While premium suites like Imunify360 or CXS are standard on enterprise nodes, ClamAV (Clam AntiVirus) remains the premier, lightweight, open-source antivirus engine integrated natively into cPanel & WHM. However, default ClamAV installations frequently suffer from memory bloat, high CPU spikes, and false-positive quarantine loops if not tuned properly.

In this systems manual, we configure ClamAV within WHM, eliminate clamd out-of-memory (OOM) kernel kills, enrich detection with custom YARA and webshell signatures, and automate scheduled quarantine scans via cron.


1. How ClamAV Operates in the cPanel Ecosystem

Under cPanel/WHM, ClamAV provides dual-layer protection:

                            Inbound File Transmission
                                       │
                 ┌─────────────────────┴─────────────────────┐
                 ▼                                           ▼
         FTP Upload Stream                           cPanel User / Cron
       (pure-ftpd / mod_clamav)                  (clamscan / clamdscan CLI)
                 │                                           │
                 └─────────────────────┬─────────────────────┘
                                       │
                                       ▼
                     ┌──────────────────────────────────┐
                     │    ClamAV Scanning Daemon        │
                     │           (clamd)                │
                     │  - Daily Signature Database      │
                     │  - Custom YARA WebShell Rules    │
                     └─────────────────┬────────────────┘
                                       │
                         ┌─────────────┴─────────────┐
                         ▼                           ▼
                 Clean File Detected          Signature Match (Infected)
                         │                           │
                         ▼                           ▼
                  [ Saved to Disk ]           [ Execute Action ]
                                              ├─ Move to Quarantine Vault
                                              ├─ Alert System Administrator
                                              └─ Strip Execute Permissions (chmod 0000)
  1. Passive On-Demand Scanning (clamscan / clamdscan): End users trigger scans across their Home Directory, Mail Directory, or Public FTP space directly from the cPanel interface.
  2. Proactive Daemon Service (clamd): A persistent resident daemon in RAM that scans incoming email attachments via Exim and files uploaded over FTP before they touch persistent storage.

2. Installing and Configuring ClamAV in WHM

Step 1: Install the ClamAV Plugin

  1. Log into your WebHost Manager (WHM) as root.
  2. In the search box, type Manage Plugins.
  3. Locate ClamAV for cPanel and click Install.
  4. Once installation completes, navigate to Plugins > Configure ClamAV Scanner.

Step 2: Global Scanner Configuration

Configure your default scanning policies:

  • Scan Entire Globally: Toggle on if you wish to allow root scans across all user accounts.
  • Scan Mail: Enabled (intercepts infected attachments in Exim spool before mailbox delivery).
  • Scan Web (public_html): Enabled.
  • Scan Public FTP: Enabled.
  • Quarantine Directory: Define a secure vault outside web roots, such as /home/quarantine/clamav/.

3. Resolving the clamd Out-of-Memory (OOM) Issue

The ClamAV signature database (daily.cld and main.cvd) contains over 8.5 million signatures. Loading this database into RAM requires approximately 1.2 GB to 1.8 GB of resident memory. On budget virtual servers with 2 GB RAM, the Linux Out-Of-Memory (OOM) Killer will abruptly terminate clamd:

kernel: [ 4812.391024] Out of memory: Kill process 12481 (clamd) score 412 or sacrifice child
kernel: [ 4812.391055] Killed process 12481 (clamd) total-vm:1894212kB, anon-rss:1412032kB

The Solution: Tuning clamd.conf and Systemd Limits

Edit /etc/clamd.d/scan.conf (or /usr/local/cpanel/3rdparty/etc/clamd.conf on cPanel systems):

# Prevent excessive child worker fork spawning
MaxThreads 2
MaxQueue 10

# Limit maximum file size scanned to prevent archive bombs
MaxFileSize 25M
MaxScanSize 50M
MaxRecursion 10

# Disable scanning of memory-heavy archive formats if not needed
ScanArchive yes
AlertBrokenExecutables no

Adjust the systemd slice memory limits (/etc/systemd/system/clamd.service.d/override.conf):

[Service]
MemoryAccounting=true
MemoryHigh=2200M
MemoryMax=2500M
OOMScoreAdjust=-500

Apply and restart:

systemctl daemon-reload
systemctl restart clamd@scan

4. Expanding Detection: Loading Custom YARA Webshell Signatures

Default ClamAV signatures prioritize desktop Windows/macOS trojans. To detect PHP webshells, base64 eval loaders, and WordPress backdoors common in Pakistan, integrate community YARA webshell signatures:

# Create local signature directory
mkdir -p /var/lib/clamav-signatures
cd /var/lib/clamav-signatures

# Download validated PHP webshell and backdoor YARA rules
curl -sSL https://raw.githubusercontent.com/Yara-Rules/rules/master/malicious_documents/malicious_php.yar -o php_webshells.yar

# Test compilation of rules with clamscan
clamscan -d php_webshells.yar --dry-run /root

# Copy verified rules into the active ClamAV database directory
cp php_webshells.yar /var/lib/clamav/
systemctl reload clamd@scan

5. Automated Midnight Scanning Script with Quarantine Isolation

Execute an automated root cron job that scans all /home/*/public_html directories during off-peak hours (e.g., 03:00 PKT), strips execute permissions, and quarantines malicious files:

#!/bin/bash
# /usr/local/bin/daily_malware_sweep.sh
# Automated off-peak malware hunting for cPanel servers

LOG_FILE="/var/log/clamav_nightly_sweep.log"
QUARANTINE_DIR="/root/quarantine_vault/$(date +%F)"

mkdir -p "${QUARANTINE_DIR}"

echo "[$(date '+%Y-%m-%d %H:%M:%S')] Starting ClamAV scan across /home/*/public_html..." >> "${LOG_FILE}"

# Execute clamdscan with multi-threading and quarantine movement
clamdscan --multiscan \
          --fdpass \
          --infected \
          --move="${QUARANTINE_DIR}" \
          --log="${LOG_FILE}" \
          /home/*/public_html

# Scan result telemetry
INFECTED_COUNT=$(grep -c "FOUND" "${LOG_FILE}")
echo "[$(date '+%Y-%m-%d %H:%M:%S')] Scan completed. Isolated files: ${INFECTED_COUNT}" >> "${LOG_FILE}"

if [ "${INFECTED_COUNT}" -gt 0 ]; then
    # Secure quarantine permissions
    chmod -R 0000 "${QUARANTINE_DIR}"
    echo "Malware detected and isolated on server. Review ${LOG_FILE}" | mail -s "[SECURITY ALERT] Malware Detected on cPanel Node" [email protected]
fi

Schedule in crontab (crontab -e):

0 3 * * * /usr/local/bin/daily_malware_sweep.sh >/dev/null 2>&1

For large hosting portfolios in Pakistan hosting thousands of client websites, running continuous antivirus scanning and real-time behavioral malware detection on entry-level shared plans causes severe CPU throttling. Migrating to enterprise-grade Dedicated Servers or low-latency Dedicated Servers in Pakistan provides multi-core Xeon and AMD EPYC silicon with dedicated RAM buffers to process heavy antivirus workloads without impacting visitor response times.

SERVER SECURITY & ANTIMALWARE

Deploy Hardened Hosting Infrastructure in Pakistan

Protect your digital enterprise against malicious exploits and zero-day webshells. Nextgen bare-metal dedicated servers and Cloud VPS instances feature hardware-level isolation and enterprise DDoS mitigation.