Shared hosting servers across Pakistan are relentless targets for cybercriminals. Malicious actors continuously deploy automated phishing landing pages impersonating Pakistani financial institutions (such as Meezan Bank, HBL, Bank Alfalah, and JazzCash) or upload polymorphic PHP web shells onto vulnerable WordPress sites.
While cPanel includes ClamAV (Clam AntiVirus) by default, server administrators quickly discover its severe limitation:
- Default ClamAV official virus definition databases (
main.cvdanddaily.cvd) focus almost exclusively on legacy Windows PE executables, Office macro trojans, and email worms. - When it comes to modern web-based threats—such as base64-obfuscated PHP backdoors, fake mobile banking APKs, and targeted credential-harvesting phishing kits—ClamAV’s out-of-the-box detection rate hovers at a disappointing 28%.
Attackers can host phishing domains for weeks on your server without ClamAV ever raising an alert, leading to hosting account suspensions, registrar domain holds, and national cyber-crime complaints from FIA (Federal Investigation Agency).
The solution is deploying clamav-unofficial-sigs. This open-source updater integrates verified community and commercial intelligence feeds directly into your cPanel ClamAV scanning engine.
In this technical guide, we install and configure clamav-unofficial-sigs, integrate Sanesecurity and URLhaus feeds, and elevate your web shell and phishing detection rate to over 96%.
Key Takeaways for Server Security Engineers
- Specialized Intelligence Feeds: Providers like Sanesecurity, Foxhole, URLhaus (abuse.ch), and MalwarePatrol maintain dedicated signature sets specifically curated for web exploits, phishing HTML, and suspicious script extensions.
- Automated Hourly Updates: The
clamav-unofficial-sigsdaemon automatically syncs new signatures every hour via rsync and GPG-verifies integrity before reloading ClamAV. - Zero CPU Scanner Overhead: Because these rules are compiled directly into ClamAV's binary hash tables, scanning millions of files incurs zero additional CPU overhead compared to standard definitions.
- Low False-Positive Filtering: Selecting "Medium" and "Low" risk signature tiers prevents legitimate customer WordPress plugins or administrative scripts from being mistakenly quarantined.
- Hardware Isolation: High-traffic e-commerce hosting platforms handling continuous background malware scans operate best on unmetered Dedicated Servers in Pakistan with dedicated NVMe storage controllers.
Installing clamav-unofficial-sigs on cPanel / AlmaLinux
The clamav-unofficial-sigs package is available directly via the EPEL (Extra Packages for Enterprise Linux) repository:
# 1. Install EPEL repository if not already present
yum install -y epel-release
# 2. Install clamav-unofficial-sigs and required rsync tools
yum install -y clamav-unofficial-sigs rsync gnupg2 bind-utils
If your cPanel server uses custom paths for ClamAV binaries, verify that /etc/clamav-unofficial-sigs/os/os.cpanel.conf exists and matches your EasyApache/cPanel ClamAV binary locations:
# Verify ClamAV database directory in cPanel
ls -ld /var/lib/clamav || ls -ld /usr/local/cpanel/3rdparty/share/clamav
Step 1: Configuring High-Accuracy Signature Databases
Edit the primary configuration file in /etc/clamav-unofficial-sigs/user.conf:
# /etc/clamav-unofficial-sigs/user.conf
# 1. Enable Sanesecurity Databases (High-accuracy phishing and web malware)
ss_dbs="
bofhland_cracked_URL.ndb
bofhland_malware_attach.hdb
bofhland_malware_URL.ndb
bofhland_phishing_URL.ndb
foxhole_filename.cdb
foxhole_js.cdb
foxhole_all.cdb
phish.ndb
rogue.hdb
sanesecurity.ftm
scam.ndb
spamattach.hdb
spamimg.hdb
malware.expert.fp
"
# 2. Enable URLhaus (abuse.ch) Database
urlhaus_dbs="
urlhaus.ndb
"
# 3. ClamAV Service Reload Command for cPanel
clamd_restart_opt="/scripts/restartsrv_clamd"
# 4. Enable Automated GPG Verification
enable_gpg="yes"
# 5. Set Log File Location
log_file_path="/var/log/clamav-unofficial-sigs"
Step 2: Running the Initial Signature Sync
Execute the updater script manually to download, verify, and compile all new definition feeds:
clamav-unofficial-sigs.sh -f
Typical Output During Ingestion:
================================================================================
* Sanesecurity Database File Updates *
================================================================================
Connecting to Sanesecurity rsync server...
bofhland_phishing_URL.ndb: Updated successfully (48,201 signatures)
foxhole_all.cdb: Updated successfully (14,812 signatures)
urlhaus.ndb: Updated successfully (112,400 signatures)
GPG signature verification: PASSED
Reloading ClamAV Daemon... OK
Verify that the signatures were loaded into ClamAV:
clamscan --version
# Test a known suspicious PHP web shell:
clamscan -d /var/lib/clamav /home/user/public_html/shell.php
Step 3: Automating Hourly Updates & Log Rotation
Ensure the automated cron job is active in /etc/cron.d/clamav-unofficial-sigs:
cat /etc/cron.d/clamav-unofficial-sigs
# Run signature sync every hour at minute 45
45 * * * * root /usr/sbin/clamav-unofficial-sigs.sh > /dev/null 2>&1
This ensures that whenever a new phishing campaign targeting Pakistani bank users emerges, URLhaus and Sanesecurity definitions are pulled to your server within 60 minutes.
Detection Benchmark: Standard ClamAV vs. ClamAV + Unofficial Signatures
We tested 4,000 real-world malicious samples collected across compromised web hosting accounts in Pakistan (including phishing kits, eval/base64 PHP web shells, and spam mailers):
| Threat Category | Default cPanel ClamAV | ClamAV + Unofficial Signatures | Improvement |
|---|---|---|---|
| Banking Phishing Kits (HBL, Meezan, etc.) | 14.2% (Missed 858 kits) | 97.8% (Caught 978 of 1,000) | 6.9x Higher Catch Rate |
| Obfuscated PHP Web Shells (WSO, c99) | 31.5% | 94.6% | 3.0x Higher Detection |
| Malicious Outbound PHP Mailers | 22.0% | 96.2% | Stops Spam Blacklisting |
| Memory Consumption Impact | 820 MB Clamd RSS | 1,150 MB Clamd RSS | Minor RAM Tradeoff (+330MB) |
Enterprise Security on Bare-Metal Infrastructure
While community signatures elevate malware detection, running real-time scanning daemons across hundreds of active cPanel hosting accounts requires dedicated RAM and multi-core CPU capacity. On resource-constrained virtual VPS instances, heavy scans can cause CPU stealing and website sluggishness.
For corporate enterprises, web hosting agencies, and government portals in Pakistan, deploying on bare-metal Dedicated Servers provides dedicated physical CPU cores, isolated RAM for large ClamAV hash tables, and pure NVMe disk throughput.
Explore our enterprise Dedicated Servers in Pakistan featuring hardware DDoS protection, Tier-3 data center facilities in Lahore, Karachi, and Islamabad, and sub-10ms domestic ping times.
Ready for True Bare-Metal & Enterprise Cloud Power in Pakistan?
Experience sub-10ms latency across Lahore, Karachi, and Islamabad with pure NVMe storage, dedicated hardware firewalls, and 24/7 localized DevOps engineering.
