EICAR is the standardized EICAR anti-virus test file, created by members of CARO for EICAR in the early 1990s as a safe mechanism to verify that antivirus software is installed and responding. It is not real malware and is primarily intended for installation checks, workflow demonstrations, and limited non-malicious testing scenarios rather than comparative efficacy testing. The file is a defined 68-character ASCII string beginning with "X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*"; when executed, it prints "EICAR-STANDARD-ANTIVIRUS-TEST-FILE!". A revised specification published on May 1, 2003 tightened detection requirements so the file must start with the EICAR string and may contain only limited trailing whitespace, with total length not exceeding 128 characters. The content notes that the original looser definition led to misdetections, including abuse by Bat/Bwg.a@MM, which embedded the EICAR string and was initially misdetected by many products as the EICAR test file. Mentioned indicators include MD5 44d88612fea8a8f36de82e1278abb02f, SHA1 3395856ce81f2b7382dee72602f798b642f14140, and SHA256 275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f. Example detections in the content include an HTTP download via Wget of csm-eicar.gif from 85.215.35.144 to 172.16.3.158, identified as threat name EICAR with file type EICAR and size 68 bytes, characterized as a controlled malware-detection test rather than a real infection. The content also references malformed ZIP "Zombie Zip" samples containing eicar.com to demonstrate antivirus evasion analysis, where forced decompression reveals the embedded EICAR content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Zombie ZIP file ... contains an EICAR file ... Selecting it: That's the EICAR file ... This reveals the EICAR file content.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A benign anti-malware test string/file used to validate detection pipelines; here it is embedded in a malformed 'Zombie Zip' archive to demonstrate AV bypass via ZIP header manipulation.
A standard anti-malware test file/string used to validate detection pipelines; here it is embedded in a malformed 'Zombie Zip' archive to demonstrate analysis and AV bypass behavior.
A benign anti-malware test file used to validate detection workflows by matching known hashes in MISP and generating Wazuh alerts.
EICAR is a benign anti-malware test file used to validate malware detection and security controls, not a real malware family.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.