We have introduced a new malware detection system for all of our Premium Cpanel servers, named Maldetect. It is an anti-malware project that has proved to be an effective solution against the use of virii/malware on servers. We have initiated full scans on the servers and have detected some malware files on current user accounts. We have incorporated the maldetect software to check apache (web) and ftp uploads. During the uploading of files to the servers, either via ftp or apache (web), maldetect software will scan the file(s) and it will not allow the upload if a file has a signature matching a virus/malware.

Why do we need maldetect ?

Our servers have many different types of software installed by our users, such as wordpress, joomla, other CMS and even custom made scripts. All of this software may become vulnerable over the course of time, and these need to be updated by clients in a timely manner in-order to prevent vulnerabilities. However, many users fail to update their software in a timely manner and these become a threat to the server security. Hackers can then use the vulnerability associated with the software to execute or upload virus/malware. This is where maldetect steps in! Even if a hacker tries to upload a virus file using an affected site, maledetect will usually prevent it.

Example Situation:

FTP case: There can be situations where a clients computer can be infected with a virus and the saved user/passwords in the ftp client software installed on the user computer may be leaked. When a hacker gets this information, he will try to upload virus/malware to the server for execution. Here also, the maldetect becomes handy, preventing the hacker from uploading viruii/malware to the server.

In addition to scanning files on upload, we also have an automated scanner that will go through all web accessible files on the server which have been modified in the past 2 days.

What is maldetect in technical terms?

Regarding technical details of maledetect, Linux Malware Detect (LMD) is a malware scanner for Linux , that is designed around the threats faced in shared hosted environments. It uses threat data from network edge intrusion detection systems to extract malware that is actively being used in attacks and generates signatures for detection.

