Print this Page


Sanesecurity produces add-ons signatures to help improve the ClamAV detection rate on Zero-Day malware and even on Zero-Hour malware.

Since 2006 we have provided professional quality ClamAV signatures to protect against the following email types:

Macro malware, Zip malware, Rar malware, Javascript malware, 7z malware, Phishing, Spear phishing and other types of common emailed malware and spam.

Sanesecurity 3rd Party ClamAV signatures can also help prevent TeslaCrypt, Cryptowall, Cryptolocker and other ransomware, who’s source usually starts as a malicious email.

Signatures are updated every hour and and our twitter page reflects that.

While our 3rd Party “competitor” has 1 million plus ClamAV signatures, Sanesecurity signatures users have
reported much higher detection rates and use less resources than SecuriteInfo signatures – due to Sanesecurity only using necessary and current signatures.

In our recent ClamAV Detection rate test….

Sanesecurity signatures :            97.11%
SecuriteInfo  signatures (free) :  19.03%
ClamAV Official only signatures: 13.82%

Number of signatures:

Sanesecurity signatures :  249,766
SecuriteInfo (free)             :  1,110,596
ClamAV Only                      : 4,137,929

Date of oldest malware Sample in test : 06.01.2015
Date of newest malware Sample in test: 05.12.2015

Our Security Blog is also updated frequently, showing the latest word macro malware,
excel macro malware and other email based malware that try to infect your server and systems.
We also look at how well the Anti-Virus companies block them, using various online scanner services.

Permanent link to this article:

Improve ClamAV detection rate up to 90% by adding Sanesecurity signatures

Sanesecurity ClamAV signatures improve ClamAV detection rate on Macro malware, Javascript malware, Phishing, Spam and other emailed Ransomware.

Read more

Foxhole databases

Zero hour (0hr) emailed malware has always been an issue. There are various ways of blocking dangerous attachments within zip files, such as Mailscanner/SpamAssassin/Postfix, however ClamAV can also be used to block these attachments which in some environments may be useful. Foxhole databases use the .cdb extension which uses the ClamAV engine to look inside …

Read more