Verified clean — official build of EICAR test file
MalwareTips staff confirmed this binary is the real, unmodified release.
File verdict·Decided by the MT AI Engine
Our call

Test file

This is the standard EICAR test file (eicar_com.zip), verified clean by our staff as a harmless AV self-test tool that intentionally triggers detections.

Malw Eicar
Trust score1Critical
MT AI confidence · 100%
eicar_com.zip
184 B
2546dcffc5ad854d4d3b6e9eedad
Antivirus engines
62 of 76 flagged
Code signing
Unsigned
Age
First seen 20y ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

100%Confidence
Very high
Reasoning

The file is a well-known ZIP archive named eicar_com.zip, first seen in 2006 with strong positive reputation (495). All 62 malicious detections from engines like Avast, BitDefender, and Kaspersky explicitly name it 'EICAR Test File (not a virus)' or similar, confirming it's a standard test designed to trigger AV alerts without harm. Our admin override marks it verified clean, as it's an EICAR test file. External signals like MalwareBazaar and YARAify also recognize it as EICAR, not real malware. Heuristic engines flag it intentionally, leading to the high false positive likelihood.

Points in its favour
  • Admin override: verified clean by MalwareTips staff, vendor-confirmed EICAR test file.
  • Positive reputation score of 495; first seen 2006 (over 18 years old).
  • Only 1 tier-1 engine clean, but 16 tier-1 malicious are all EICAR-specific detections.
  • File size 184 bytes matches standard eicar_com.zip test archive.
Points against
  • 62 engines flagged it malicious, but all cite EICAR test explicitly (e.g., Avast, AVG: EICAR Test-NOT virus!!!).
  • MalwareBazaar lists it as a researcher-uploaded sample, but unnamed family and admin override confirms test file.
  • YARAify matched 4 EICAR-specific rules (e.g., SUSP_Just_EICAR by Florian Roth).
What to do

This is completely safe; use it to confirm your antivirus is working by scanning it. No deletion or quarantine needed.

Threat family attribution

eicar corroborated by 2 sources

  • 4 YARA rules
    malw_eicar, Multi_EICAR_ac8f42d6, SUSP_Just_EICAR
  • VT (76 engines)
    eicar
External threat intelligence

3 corroborating signals from researcher-curated sources

MalwareBazaar HIT·abuse.ch confirmed sampleView on MalwareBazaar
· zip· first seen 7/3/2024, 9:19:40 AM
zip
YARAify HIT·4 community rules matchedView on YARAify
  • malw_eicarby Marc Rivero | McAfee ATR Team
    Rule to detect the EICAR pattern
  • Multi_EICAR_ac8f42d6by Elastic Security
  • SUSP_Just_EICARby Florian Roth (Nextron Systems)
    Just an EICAR test file - this is boring but users asked for it
  • SUSP_Just_EICAR_RID2C24by Florian Roth
    Just an EICAR test file - this is boring stuff
CIRCL hashlookup HIT·indexed as known-malicious·trust 30/100View on CIRCL
Also flagged as malicious by malshare.com. The reference-DB hit is not a clean signal on its own — the verdict defers to VT, AI, and the abuse.ch sources.
Cross-referenced against MalwareBazaar (abuse.ch), YARAify, and the CIRCL hashlookup reference DB.
Antivirus engine breakdown

62 detections across 76 engines

62 malicious0 suspicious14 clean
Tier-117 engines
16flag
Top commercial AVs (low FP rate)
Tier-238 engines
34flag
Mainstream engines with mixed FP rates
Low-trust21 engines
12flag
Heuristic / generic-AI engines (high FP rate)
Our scoring rated this file safe — detections shown below are weighted as likely false positives.
AhnLab-V3
malicious
Virus/EICAR_Test_File
Alibaba
malicious
Virus:Win32/EICAR.A
alibabacloud
malicious
Engtest:Multi/Eicar
ALYac
malicious
Misc.Eicar-Test-File
Antiy-AVL
malicious
TestFile/Win32.EICAR
Arcabit
malicious
EICAR-Test-File (not a virus)
Avast
malicious
EICAR Test-NOT virus!!!
Avast-Mobile
malicious
Eicar
AVG
malicious
EICAR Test-NOT virus!!!
Avira
malicious
Eicar-Test-Signature
Baidu
malicious
Win32.Test.Eicar.a
BitDefender
malicious
EICAR-Test-File (not a virus)
CAT-QuickHeal
malicious
EICAR.TestFile
ClamAV
malicious
Eicar-Test-Signature
CMC
malicious
Eicar.test.file
CTX
malicious
zip.virus.eicar
Cynet
malicious
Malicious (score: 99)
DrWeb
malicious
EICAR Test File (NOT a Virus!)
Elastic
malicious
eicar
Emsisoft
malicious
EICAR-Test-File (not a virus) (B)
ESET-NOD32
malicious
Eicar test file
F-Secure
malicious
EICAR_Test_File
Fortinet
malicious
EICAR_TEST_FILE
GData
malicious
EICAR_TEST_FILE
Google
malicious
Detected
Gridinsoft
malicious
Trojan.U.EICAR_Test_File.dd
huorong
malicious
TEST/AVEngTestFile!EICAR
Ikarus
malicious
EICAR-Test-File
Jiangmin
malicious
EICAR-Test-File
K7AntiVirus
malicious
EICAR_Test_File
K7GW
malicious
EICAR_Test_File
Kaspersky
malicious
EICAR-Test-File
Kingsoft
malicious
Test.eicar.aa
Lionic
malicious
Test.ZIP.Eicar.y!c
Malwarebytes
malicious
EICAR-AV-Test
MaxSecure
malicious
VIRUS.EICAR.TEST
Microsoft
malicious
Virus:DOS/EICAR_Test_File
MicroWorld-eScan
malicious
EICAR-Test-File
NANO-Antivirus
malicious
Marker.Dos.EICAR-Test-File.dyb
Panda
malicious
EICAR-AV-TEST-FILE
Rising
malicious
Virus.EICARTestFile!1.103DB (CLASSIC)
Sangfor
malicious
EICAR-Test-File (not a virus)
SentinelOne
malicious
Static AI - Malicious Archive
Skyhigh
malicious
EICAR test file
Sophos
malicious
EICAR-AV-Test
SUPERAntiSpyware
malicious
NotAThreat.EICAR[TestFile]
Symantec
malicious
EICAR Test String
SymantecMobileInsight
malicious
AppRisk:Generisk
Tencent
malicious
EICAR.TEST.NOT-A-VIRUS
TrellixENS
malicious
EICAR test file
TrendMicro
malicious
Eicar_test_file
Varist
malicious
EICAR_Test_File
VBA32
malicious
EICAR-Test-File
VIPRE
malicious
EICAR-Test-File (not a virus)
VirIT
malicious
EICAR-Test-File
ViRobot
malicious
BIN.S.Eicar.184
Webroot
malicious
W32.Eicar.Testvirus.Gen
Xcitium
malicious
ApplicUnwnt@#27s8ewoxds1vr
Yandex
malicious
EICAR_test_file
Zillya
malicious
EICAR.TestFile
ZoneAlarm
malicious
EICAR-AV-Test
Zoner
malicious
EICAR.Test.File-NoVirus.250
Hash 2546dcffc5ad… cross-referenced against 76 AV engines via our AV network.
File identity

Forensic fingerprint

File biography
First seen (VT)
5/23/2006, 4:59:42 PM
First seen (MalwareBazaar)
7/3/2024, 9:19:40 AM
Last analysis (VT)
4/20/2026, 6:44:02 AM
Scanned here
4/20/2026, 3:41:25 PM
File name
eicar_com.zip
Size
184 B
MIME type
(unknown)
Detected type
ZIP
SHA-256
2546dcffc5ad854d4ddc64fbf056871cd5a00f2471cb7a5bfd4ac23b6e9eedad
MD5
6ce6f415d8475545be5ba114f208b0ff
SHA-1
d27265074c9eac2e2122ed69294dbc4d7cce9141
First seen (VT)
5/23/2006, 4:59:42 PM
Last analysis (VT)
4/20/2026, 6:44:02 AM
First scan (MalwareTips)
4/20/2026, 6:22:22 AM
Last scan (MalwareTips)
4/20/2026, 3:41:25 PM
Community reputation
+495trusted
Behavior tags
zipdetect-debug-environmentcalls-wmiattachmentsets-process-namechecks-cpu-namevia-tor
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Scanned by
JackStaff
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.