This article assumes you’ll be using Ubuntu Server 20.04 or 24.04.
Motivation
Scan for viruses and malware regularly and directly on the server while consuming low resources.
Alternatives
LMD (maldet) on your server or the WordPress plugins Wordfence and NinjaScanner are good options.
Install ClamAV
ClamAV is part of WordOps Stack and can be installed with (we need to also install two additional packages):
wo stack install --clamav
sudo apt install clamav-daemon clamdscan -y
You can also install it in Ubuntu with APT:
sudo apt update
sudo apt install clamav clamav-daemon clamdscan -y
Add custom database signatures
To enhance malware and virus detection capabilities, you can optionally incorporate the database signatures offered by RFXN’s Linux Malware Detect (LMD), commonly referred to as maldet. Append the following configuration to the end of the /etc/clamav/freshclam.conf file:
DatabaseCustomURL https://www.rfxn.com/downloads/rfxn.ndb
DatabaseCustomURL https://www.rfxn.com/downloads/rfxn.hdb
DatabaseCustomURL https://www.rfxn.com/downloads/rfxn.yara
Perform a full scan of your files
Let’s now manually update the virus database before running it (it may be required to stop the clamav-freshclam service so that we can run it manually):
sudo systemctl stop clamav-freshclam.service
sudo freshclam
And run a complete scan on our sites directory:
sudo clamscan -r /var/www
Enable ClamAV as a service and schedule a cron job
There are two ways of running ClamAV, with the standalone command clamscan or with the alternative clamdscan, which access the service daemon and stores the virus database direct on memory, with a much better performance. Let’s start and enable the required daemons with the following:
sudo systemctl start clamav-freshclam.service
sudo systemctl enable clamav-freshclam.service
sudo systemctl start clamav-daemon.service
sudo systemctl enable clamav-daemon.service
The following command is designed to scan only new or modified files within the last 25 hours. You can install it in your sudo crontab. Additionally, you have the option to configure your email at the beginning to receive notifications following each scan.
MAILTO="al****@*****le.com"
0 2 * * * find /var/www -type f -mmin -1500 -print0 | xargs -0 clamdscan --fdpass --multiscan --infected
Resources:
Leave a Reply