French cybersecurity company since 2004

Your ClamAV lets through
99.7% of today's malware

Our 4,676,125 additional signatures close that gap. Updated every hour, from malware captured the very same day. 5-minute setup, without changing your antivirus.

Free Basic plan · No credit card required · Compatible with Linux, Windows and macOS

Scroll

The test that changes everything

We ran a collection of 749 real malwares, captured on compromised websites, through ClamAV. Here is the result.

ClamAV alone
0%
0 malwares detected out of 749
ClamAV + SecuriteInfo.com
99.7%
747 malwares detected out of 749
4,676,125 antivirus signatures added to your ClamAV
12,597,707 malwares recognized thanks to these signatures
1 h between updates, 24/7, all year round
20 years of expertise in malware analysis

Figures as of see the detailed statistics, updated daily

ClamAV is an excellent antivirus engine. But an engine is only as good as the signatures you feed it. That is exactly what we have been producing since 2015: additional signatures, with no duplicates of the official database, generated from the malware we capture ourselves, around the clock.

Create my free account

A malware only has a few hours to reach you

Today's ransomware and phishing campaigns last a few hours, sometimes a few minutes. An antivirus database updated once a day always arrives too late. Ours is regenerated every hour, from malware captured the very same day: a malware we catch at 2:03 pm is detected on your systems before 3 pm.

You keep ClamAV. You just move up a level of detection.

No migration, no new agent, no extra server. Our signatures are simple antivirus database files that freshclam downloads just like the official database.

  • 5-minute setup: a few lines to add to your freshclam configuration in a single copy/paste.
  • Zero duplicates with the official ClamAV database: no wasted memory.
  • No impact on your infrastructure: no mandatory cloud, no telemetry.
  • Compatible with ClamAV Linux, ClamAV Windows, ClamShield, and ClamXav on macOS.
Servers protected by ClamAV and SecuriteInfo.com signatures

Signatures built for today's threats

Our captures show where the battle is really being fought. Among the malware we collected last month:

  • 34% ELF binaries — your Linux servers are target number one.
  • 14% shell scripts — droppers and downloaders planted after a compromise.
  • 13% Windows executables — ransomware and trojans.
  • 7% JPG files and 4% VBS — payloads hidden inside harmless-looking attachments.

Mirai variants and Linux downloaders are, by far, what our signatures block most often. If you run servers exposed to the Internet, that is exactly what is slipping past you today.

Analysis of Linux and Windows malware

Four places where these signatures save the day

Wherever ClamAV is already running in your organization, our signatures immediately boost the detection rate, without changing your architecture.

Email gateway
Your email Booby-trapped attachments, ransomware, phishing. Our antispam signatures detect over 90% of spam and phishing attempts.
Web servers
Your websites Webshells, PHP backdoors, injections. This is precisely the ground where ClamAV alone scored 0% detection in our test.
Web proxy
Your proxy Filter your users' malicious downloads before they reach the workstation.
Workstation with three screens
Your workstations Windows, Linux or macOS: the last line of defense against ransomware and trojans.

These signatures are written by someone who knows ClamAV from the inside

Arnaud Jacques, founder and CEO of SecuriteInfo.com for over 20 years and a malware analyst, worked on the ClamAV team from 2005 to 2012. Since 2015, he has been producing the additional signatures you will find here.

SecuriteInfo.com is a French company, founded in 2004, that contributes daily to the worldwide fight against malware: submitting and analyzing malware on VirusTotal since 2015, contributing to Malware Bazaar (Abuse.ch) since 2020. Our signatures do not come out of a black box: they come out of a lab that captures, analyzes and publishes.

Choose your level of protection

Start for free, with no credit card. Upgrade the day you want detection of malware less than a year old — in other words, the malware that is actually circulating right now.

Basic
To discover and test on a single machine.
Free
1 authorized IP address
  • Over 3 million signatures
  • Updated every hour
  • ClamAV Linux, Windows and ClamXav Mac
  • Malware over one year old (2012 to last year)
  • 0-hour malware
  • Fast download
  • Free support
Start for free
Gold
For large fleets and multi-site infrastructures.
€99.00
per year, excl. VAT — 50 IP addresses
  • Everything in the Professional plan
  • 50 IP addresses for downloading
  • 0-hour malware
  • Fast download
  • Free support
  • Commercial use of the signatures
I choose Gold
Reseller
Integrate our signatures into your own products and services.
€1,499.00
per year, excl. VAT — unlimited IPs
  • Everything in the Gold plan
  • Unlimited number of IP addresses
  • Commercial use of our antivirus signatures
  • Integration into your products and services
  • Free support
Become a reseller
Detailed comparison of SecuriteInfo.com antivirus signature subscriptions for ClamAV
Detailed comparison Basic Professional Gold Reseller
Number of IP addresses allowed to download the signatures 1 50 Unlimited
Over four million signatures
Updated every hour
Works with ClamAV Linux, ClamAV Windows and ClamXav Mac
Malware over one year old Malware from 2012 up to last year
0-hour malware All malware, including malware we captured just minutes ago. Choose this plan if you want maximum protection.
Fast download
Free support
Reseller subscription Commercial use of our antivirus signatures. Use them in your own products and services!
Price excl. VAT Free €99.00 / year €1,499.00 / year

All prices are per year, excluding VAT. Not sure which plan fits your infrastructure? Write to us, we reply quickly.

The questions we get asked the most

Do I have to uninstall or replace my current ClamAV?
No. Our signatures are added on top of your existing installation. You add a few lines to your freshclam configuration, and your databases are enriched at the next update. Nothing else changes.
Are there any duplicates with the official ClamAV database?
None. We systematically check that our signatures do not overlap with those of the official database. You pay nothing in memory or scan time for detections you already had.
What is the concrete difference between Basic and Professional?
The Basic plan gives you malware over one year old. The Professional plan adds 0-hour malware: the malware we captured today, sometimes just minutes ago. And that is precisely the malware circulating in ongoing campaigns. It is the difference between an archive and real protection.
How many signatures will I actually add?
4,676,125 signatures as of August 19, 2026, including 105,050 generic signatures that each cover an entire malware family. In total, these signatures recognize 12,597,707 distinct malwares. These figures are updated daily on our statistics page.
What if I have more machines than authorized IP addresses?
The count applies to the IP addresses that download the signatures, not to the machines being protected. In practice, an internal mirror server is enough to cover an entire fleet with a single IP. The Gold plan (50 IPs) covers multi-site infrastructures, and the Reseller plan removes any limit.
Can I integrate your signatures into my own product?
Yes, with the Reseller subscription, which explicitly allows commercial use of our signatures in your products and services, with no limit on IP addresses.

Are your servers really protected?

It takes five minutes to find out. Create a free account, add our signatures to your ClamAV, and run a new scan on your web directories. Most of our customers discover files they had been hosting for months without knowing it.

Create my free account

Already a customer? Go to my account

© 2000-2026 - All rights reserved SecuriteInfo.com