Linux Malware Detect

Multi-engine Linux malware scanner with five detection stages (MD5, HEX pattern, YARA, ClamAV, statistical), real-time inotify monitoring, quarantine, and multi-channel alerting

Cybersecurity & Ethical HackingShellGPL-2.0

Abstract

Linux Malware Detect is an open-source Cybersecurity & Ethical Hacking project. Multi-engine Linux malware scanner with five detection stages (MD5, HEX pattern, YARA, ClamAV, statistical), real-time inotify monitoring, quarantine, and multi-channel alerting. Linux Malware Detect (LMD) is a malware scanner for Linux released under the GNU GPLv2 license, designed around the threats faced in shared hosted environments. It uses threat data from network edge intrusion detection systems to extract malware that is actively being used in attacks and generates signatures for detection. It is built using Shell. The complete source code is publicly available on GitHub under the GNU General Public License v2.0, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.

1. Introduction

Linux Malware Detect (LMD) is a malware scanner for Linux released under the GNU GPLv2 license, designed around the threats faced in shared hosted environments. It uses threat data from network edge intrusion detection systems to extract malware that is actively being used in attacks and generates signatures for detection. In addition, threat data is derived from user submissions with the LMD checkout feature and from malware community resources.

LMD's architecture, detection stages, and supported platforms.

LMD focuses on the malware classes that traditional AV products frequently miss: PHP shells, JavaScript injectors, base64-encoded backdoors, IRC bots, and other web-application-layer threats that target shared hosting user accounts rather than operating system internals.

2. Objective

Multi-engine Linux malware scanner with five detection stages (MD5, HEX pattern, YARA, ClamAV, statistical), real-time inotify monitoring, quarantine, and multi-channel alerting

This project demonstrates how Shell can be applied to a real-world Cybersecurity & Ethical Hacking problem.

4. Technology Stack

Shell

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • Linux / macOS terminal or WSL on Windows
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/rfxn/linux-malware-detect.git
cd linux-malware-detect
  1. Copies files to /usr/local/maldetect
  2. Creates the maldet symlink in /usr/local/sbin/
  3. Installs the cron.daily script to /etc/cron.daily/maldet
  4. Installs the systemd service unit (or SysV init script on older systems)
  5. Links LMD signatures to ClamAV data directories (if ClamAV is installed)
  6. Preserves existing configuration (conf.maldet), custom signatures, and ignore files across upgrades
  7. Install path: /usr/local/maldetect
  8. Binary symlink: /usr/local/sbin/maldet
# Install to /usr/local/maldetect
./install.sh

# Scan all files under a path
maldet -a /home/?/public_html

# Scan files modified in the last 2 days
maldet -r /home/?/public_html 2

# Enable YARA scanning at runtime
maldet -co scan_yara=1 -a /home/?/public_html

# Quarantine all hits from a scan
maldet -q SCANID

# Start real-time inotify monitoring
maldet -m users

# Update signatures
maldet -u
./install.sh

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add logging and alert notifications (email / Telegram)
  • Write a threat model document for the tool
  • Package it with Docker for safe lab testing

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Which threat or attack does this project defend against?
  2. What detection or protection technique is used and what are its limits?
  3. How are false positives and false negatives handled?
  4. Which cryptographic algorithms or security standards are involved?
  5. What legal and ethical rules apply when testing a tool like this?

9. Source Code & License

This project is developed by rfxn and published on GitHub under the GNU General Public License v2.0. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Cybersecurity & Ethical Hacking Internship