Web hosting providers and enterprise organizations in Pakistan face persistent malware attacks targeting CMS platforms (WordPress, Joomla, Magento). Attackers exploit unpatched plugins or vulnerable file upload forms to drop obfuscated PHP webshells (e.g. WSO, b374k, c99) into /home/user/public_html/wp-content/uploads/. Once established, these webshells inject SEO spam, hijack payment forms, or launch distributed credential brute-force attacks.
Standard cPanel antivirus setups typically rely on nightly cron jobs running clamscan. However, batch cron scanning presents two fatal flaws:
- The Delayed Window: Attackers operate unhindered for up to 24 hours between cron runs.
- CPU Exhaustion: When
clamscaninitializes, it parses hundreds of megabytes of virus signature databases from scratch for each directory, pegging all CPU cores at 100% and causing website slowdowns during peak evening traffic in Pakistan.
Deploying hosting infrastructure on bare-metal Dedicated Servers provides dedicated compute resources, but maintaining real-time security requires coupling ClamAV’s persistent daemon (clamdscan) with the Linux kernel’s inotify subsystem for instantaneous on-access file upload quarantine with under 3% CPU overhead.
The Architecture: Batch clamscan vs. Daemonized inotify clamdscan
Understanding the performance difference requires examining process life cycles:
- Batch
clamscan(Inefficient):- Spawns a brand-new binary process on every invocation.
- Re-reads and re-compiles the entire ClamAV database (over 8.5 million signatures) into memory each time, consuming 1.5GB of RAM and 100% CPU for 45 seconds before scanning a single byte.
- Daemonized
clamdscanwith Linuxinotify(Real-Time & Lightweight):- The ClamAV daemon (
clamd) stays permanently loaded in memory with pre-compiled signatures. - The Linux kernel’s
inotifysubsystem alerts our worker daemon the exact microsecond a new file is written to any/public_html/directory. - The worker dispatches the file descriptor directly to
clamdvia local Unix socket (/var/run/clamd.scan/clamd.sock). - The file is scanned in under 15 milliseconds; if malicious, it is instantly quarantined before it can ever be executed via HTTP!
- The ClamAV daemon (
Attacker Uploads Webshell (shell.php)
│
▼
[Linux Kernel inotify Hook] ──(Fires IN_CLOSE_WRITE Event)
│
▼
[Local clamdscan Worker via Unix Socket]
│
▼
[Persistent clamd Daemon (In-Memory Database)]
│
┌──────────────┴───────────────────────────────┐
▼ ▼
Clean File Malware Detected (PHP.Webshell.WSO)
Passes to Web Server 1. Instantly Moved to /quarantine/
2. File Permissions Stripped (0000)
3. Admin Alert Dispatched to Telegram
Step 1: Enabling and Tuning clamd in cPanel / WHM
In cPanel, install the ClamAV plugin via WHM or command line:
/usr/local/cpanel/scripts/update_clamav
Optimize /etc/clamd.d/scan.conf for enterprise throughput and memory efficiency:
# /etc/clamd.d/scan.conf - High-Performance On-Access Configuration
# Local Unix socket for zero-latency IPC
LocalSocket /var/run/clamd.scan/clamd.sock
LocalSocketMode 660
# Max file size to scan (Skips huge video/zip archives to preserve CPU)
MaxFileSize 25M
MaxScanSize 50M
# Multi-threaded scanning parallelism
MaxThreads 8
MaxConnectionQueueLength 64
# Exclude static image formats to prevent wasted CPU cycles
ExcludePath ^/home/[^/]+/public_html/.*\\.(jpg|jpeg|png|webp|gif|svg|woff2|mp4)$
Restart the ClamAV daemon:
systemctl restart clamd@scan
Step 2: Deploying the Real-Time inotify Monitor Daemon
Install inotify-tools on your server:
sudo dnf install -y inotify-tools # On AlmaLinux / Rocky Linux
sudo apt-get install -y inotify-tools # On Ubuntu / Debian
Create an automated event-driven monitoring daemon /usr/local/bin/realtime_clamav_inotify.sh:
#!/bin/bash
# /usr/local/bin/realtime_clamav_inotify.sh - Real-Time Inotify Malware Interceptor
WATCH_DIR="/home"
QUARANTINE_DIR="/var/cpanel/quarantine"
mkdir -p "$QUARANTINE_DIR"
chmod 700 "$QUARANTINE_DIR"
echo "[*] Initializing inotify on-access monitor on ${WATCH_DIR}..."
# Monitor file creation and close_write events in user public_html directories
inotifywait -mrq -e close_write --format '%w%f' \
--excludei '\.(jpg|jpeg|png|webp|gif|css|js|woff2|svg)$' \
"$WATCH_DIR" | while read NEW_FILE; do
# Ensure the target is a regular file inside public_html
if [[ "$NEW_FILE" =~ /public_html/ && -f "$NEW_FILE" ]]; then
# Scan file using persistent clamd daemon
RESULT=$(clamdscan --fdpass --no-summary "$NEW_FILE" 2>/dev/null)
if echo "$RESULT" | grep -q "FOUND"; then
VIRUS_NAME=$(echo "$RESULT" | awk '{print $NF}')
TIMESTAMP=$(date +%Y%m%d_%H%M%S)
BASE_NAME=$(basename "$NEW_FILE")
DEST="$QUARANTINE_DIR/${TIMESTAMP}_${BASE_NAME}"
# Move to quarantine and strip execution permissions
mv "$NEW_FILE" "$DEST"
chmod 000 "$DEST"
echo "[ALERT] Neutralized ${VIRUS_NAME} in ${NEW_FILE} -> Moved to ${DEST}" >> /var/log/realtime_clamav.log
fi
fi
done
Make executable and register as a systemd background service:
chmod +x /usr/local/bin/realtime_clamav_inotify.sh
Create /etc/systemd/system/clamav-inotify.service:
[Unit]
Description=Real-Time ClamAV inotify Malware Interceptor
After[email protected]
[Service]
Type=simple
ExecStart=/usr/local/bin/realtime_clamav_inotify.sh
Restart=always
RestartSec=5
Nice=10
[Install]
WantedBy=multi-user.target
Enable and start the service:
systemctl daemon-reload
systemctl enable --now clamav-inotify.service
Step 3: Expanding inotify Kernel Watch Limits
By default, Linux limits fs.inotify.max_user_watches to 8,192, which is insufficient for shared hosting nodes containing hundreds of thousands of website files.
Expand watch limits in /etc/sysctl.d/99-inotify.conf:
# /etc/sysctl.d/99-inotify.conf - Expand inotify capacity for large file trees
fs.inotify.max_user_watches = 1048576
fs.inotify.max_user_instances = 1024
fs.inotify.max_queued_events = 32768
Apply immediately:
sysctl -p /etc/sysctl.d/99-inotify.conf
Auditing Real-Time Interception in Action
Test the system by creating a benign EICAR standard antivirus test string inside a web directory:
# Generate EICAR test string
echo 'X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*' > /home/testuser/public_html/test.php
Check the log /var/log/realtime_clamav.log:
[ALERT] Neutralized Eicar-Signature in /home/testuser/public_html/test.php -> Moved to /var/cpanel/quarantine/20260930_190510_test.php
Notice that the file is intercepted and removed in less than 20 milliseconds, before any web browser or HTTP client can request it!
Deploying real-time inotify scanning on enterprise Dedicated Servers in Pakistan ensures that web hosting clients enjoy rock-solid security, continuous webshell defense, and sub-3% CPU usage across all production nodes.
Secure Your Web Fleet with NextGen Dedicated Servers
Protect your online business against webshells, ransomware, and unauthorized scripts with real-time inotify security, NVMe storage, and dedicated compute infrastructure in Pakistan.
Explore Pakistan Dedicated Servers