More ClamAV Signatures via DatabaseCustomURL

poetry

Active Member
May 28, 2020
206
63
33
Hello,
Opening this thread to start a discussion about more ClamAV Signatures via DatabaseCustomURL. In another thread https://forum.proxmox.com/threads/clamav-signatures-from-securiteinfo-90-detection-rate.91072/ securiteinfo was mentioned and after testing the paid version our detection rate is as the site says at least 90% but there is still that 10% that goes through.

Anyone has any more quality signatures sources that we can use to improve the detection?
Here are some but they are not really official https://wiki.gentoo.org/wiki/ClamAV_Unofficial_Signatures

As said on the gentoo wiki there are only a few downsides to using freshclam:
  1. Freshclam can't rename the downloaded file, so if the source file is incorrectly named, freshclam will fail to validate it (because clamav won't know how to read it).
  2. Freshclam only supports http(s), so you're out of luck if your database is only served over rsync.
 
Just want to give an update on this. I have added rfxn.com and mirror.rollernet.us and as far as testing goes it seems to work fine. Make sure you check yourself before adding anything. I have added all sanesecurity signatures with low and medium false positive probability. Don't think it makes sense to add anything with high false positive.

https://sanesecurity.com/usage/signatures/
https://malware.expert/howto/extending-clamav-signatures-with-rfxn-database-for-php-malwares/

Won't give you the whole list that I added. Here are the two mirrors that are available but they are not official. Keep in mind that this mirrors can die anytime. I am thinking about making my own mirrors for myself to keep the reliability up and they can also be faster with updating.
https://mirror.rollernet.us/sanesecurity/
https://ftp.swin.edu.au/sanesecurity/

1627414322275.png
 
Last edited:
  • Like
Reactions: hata_ph

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!