Test file
This is the standard EICAR test file (eicar_com.zip), verified clean by our staff as a harmless AV self-test tool that intentionally triggers detections.
2546dcffc5ad854d4d…3b6e9eedadThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file is a well-known ZIP archive named eicar_com.zip, first seen in 2006 with strong positive reputation (495). All 62 malicious detections from engines like Avast, BitDefender, and Kaspersky explicitly name it 'EICAR Test File (not a virus)' or similar, confirming it's a standard test designed to trigger AV alerts without harm. Our admin override marks it verified clean, as it's an EICAR test file. External signals like MalwareBazaar and YARAify also recognize it as EICAR, not real malware. Heuristic engines flag it intentionally, leading to the high false positive likelihood.
- Admin override: verified clean by MalwareTips staff, vendor-confirmed EICAR test file.
- Positive reputation score of 495; first seen 2006 (over 18 years old).
- Only 1 tier-1 engine clean, but 16 tier-1 malicious are all EICAR-specific detections.
- File size 184 bytes matches standard eicar_com.zip test archive.
- 62 engines flagged it malicious, but all cite EICAR test explicitly (e.g., Avast, AVG: EICAR Test-NOT virus!!!).
- MalwareBazaar lists it as a researcher-uploaded sample, but unnamed family and admin override confirms test file.
- YARAify matched 4 EICAR-specific rules (e.g., SUSP_Just_EICAR by Florian Roth).
This is completely safe; use it to confirm your antivirus is working by scanning it. No deletion or quarantine needed.
eicar corroborated by 2 sources
- 4 YARA rulesmalw_eicar, Multi_EICAR_ac8f42d6, SUSP_Just_EICAR
- VT (76 engines)eicar
3 corroborating signals from researcher-curated sources
- malw_eicarby Marc Rivero | McAfee ATR TeamRule to detect the EICAR pattern
- Multi_EICAR_ac8f42d6by Elastic Security
- SUSP_Just_EICARby Florian Roth (Nextron Systems)Just an EICAR test file - this is boring but users asked for it
- SUSP_Just_EICAR_RID2C24by Florian RothJust an EICAR test file - this is boring stuff
62 detections across 76 engines
Forensic fingerprint
- File name
- eicar_com.zip
- Size
- 184 B
- MIME type
- (unknown)
- Detected type
- ZIP
- SHA-256
- 2546dcffc5ad854d4ddc64fbf056871cd5a00f2471cb7a5bfd4ac23b6e9eedad
- MD5
- 6ce6f415d8475545be5ba114f208b0ff
- SHA-1
- d27265074c9eac2e2122ed69294dbc4d7cce9141
- First seen (VT)
- 5/23/2006, 4:59:42 PM
- Last analysis (VT)
- 4/20/2026, 6:44:02 AM
- First scan (MalwareTips)
- 4/20/2026, 6:22:22 AM
- Last scan (MalwareTips)
- 4/20/2026, 3:41:25 PM
- Community reputation
- +495trusted
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.