
Boost your malware detection rates in shared hosting environments
with our specialized ClamAV signatures. They are ideal for detecting
real-world PHP malware targeting WordPress, Joomla, other popular
CMS platforms, and custom PHP applications.
Signatures
Malware Signature Database
6,020
unique malware signatures
Latest addition: +13 signatures
Database updated: August 6, 2026
- Unlimited servers
- ClamAV compatible
- Updated signatures
malware.expert.ndb contains generic hexadecimal
patterns for detecting PHP malware. Because it includes generic
patterns such as eval and base64, some false-positive detections may
occur, although the false-positive rate is very low. We recommend
scanning all PHP files and manually reviewing any detected files.
Problematic signatures can be whitelisted when necessary.
malware.expert.yara contains textual and binary
patterns for detecting PHP malware. It provides a very low
false-positive rate, but detected PHP files should still be manually
reviewed.
malware.expert.hdb contains static MD5 file hashes.
Because these signatures match complete file hashes, they should not
produce false-positive detections.
malware.expert.hsb contains static SHA1 and SHA256
file hashes. These signatures should not produce false-positive
detections.
malware.expert.ldb contains logical ClamAV signatures
that use multiple patterns to identify malware in files.
Read more about LDB signatures.
malware.expert.fp contains whitelisted files and
patterns that are known to cause false-positive malware detections.
Are You a Shared Hosting Provider?
Our ClamAV signatures integrate seamlessly with your existing
security measures, making them ideal for shared hosting environments
running WordPress, Joomla, and other PHP-based applications.
Do not leave your customers’ websites vulnerable. Improve your
malware detection capabilities with our specialized and regularly
updated ClamAV signatures.