Threat LensFile scan report

Is eicar.com-10074 safe?

Verdict
Test file

This 68-byte sample is the standardized EICAR antivirus test pattern, intentionally designed to trigger security products without carrying an operational malware payload.

The sample is the established EICAR antivirus test pattern, corroborated by 66 of 74 engines and four EICAR-specific YARA rules. It is intended to verify that endpoint protection detects and blocks known test content, so protection should remain enabled.

Open with normal care

Keep endpoint protection enabled and remove the file after any authorized detection test. If its presence was unexpected, review how it arrived and confirm no unrelated payload accompanied it.

Read the full analysis
Saved file evidenceAntivirus consensus
66of 74 flagged
Flagged 66No detection 8
Digital specimeneicar.com-10074275a021bbfb6489e54…538aabf651fd0f
Size68 B
Code signingRecognized test file
SandboxRuntime complete
First seen20y ago
Evidence3 priority signals
This is a recognized antivirus test file, not real malware; antivirus detections are expected.

Recommended next actions

01

Before opening

Open it only when its sender or download source is one you independently trust.

02

If you already opened it

Keep normal device protection enabled and stop if the file behaves unexpectedly.

Chapter 02

Intelligence

The saved assessment, checked against the scan evidence and recorded coverage.

MT AI Engine · Verdict analysis

The reasoning behind this verdict

This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.

99%Confidence
Very high
Analyst conclusion

The sample is the established EICAR antivirus test pattern, corroborated by 66 of 74 engines and four EICAR-specific YARA rules. It is intended to verify that endpoint protection detects and blocks known test content, so protection should remain enabled.

Where this verdict could be wrong3 caveats
  • behaviour.offensiveTechniques includes T1055, while triggeredHeuristics also reports possible credential-store access; these observations are atypical for the 68-byte test string and may be environmental noise.
  • behaviour.contactedIps lists 15 addresses, but contactedHosts=null means no complete host-reputation cross-check is available.
  • externalIntel.circl.knownMalicious references malshare.com, although the CIRCL record also identifies eicar.com and a legacy reference-software entry.

These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.

Recommended action

Keep endpoint protection enabled and remove the file after any authorized detection test. If its presence was unexpected, review how it arrived and confirm no unrelated payload accompanied it.

Scan transparency

Coverage & freshness

4 of 5 complete

Complete means the check returned a usable result. It does not mean the file is safe.

  • Antivirus

    Complete

    66 of 74 engines flagged the file.

  • Sandbox

    Complete

    1 isolated runtime environment contributed observations.

  • Network

    Partial

    20 runtime contacts were observed without a completed reputation cross-check.

  • YARA

    Complete

    7 signature or behavior rules matched.

  • External intel

    Complete

    3 of 3 independent reference sources completed.

Chapter 03

Behavior

Plain-English impact first, then the observed runtime evidence.

Runtime flight recorder

Capture complete
  • 1isolated sandbox run
  • 17MITRE ATT&CK techniques
  • 15spawned processes
  • 20network contacts
  • 32filesystem & mutex artifacts
Recorded behavior

Attack story

Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.

ObservedDerived

7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.

Chapter 04

Detection & Forensics

Consensus, attribution, signatures, code structure, prevalence, and identity.

Chapter 05

Safety & FAQ

Complete recovery guidance and answers for the next decision.

What to do now

This file appears low risk based on the evidence available now.

  1. Recovery step 01

    Open it only when its sender or download source is one you independently trust.

  2. Recovery step 02

    A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.

  3. Recovery step 03

    Keep your antivirus and Windows updates switched on so you stay protected.

Safety FAQ

Direct answers grounded in the saved verdict and evidence in this report.

6 evidence-based answers
Is eicar.com-10074 safe?
Evidence-based answer
eicar.com-10074 is a recognized antivirus test file, not real malware. 66 of 74 antivirus engines flagged it, which is the expected result for a test sample. Use it only in a controlled security test and do not send it to people who are not expecting it.
What is eicar.com-10074?
Evidence-based answer
eicar.com-10074 is a file, about 68 bytes. This is a security-industry test sample designed to trigger antivirus products without containing a real malicious payload. A file's name can be reused, so the cryptographic hash below is the reliable identifier.
How many antivirus engines detected eicar.com-10074?
Evidence-based answer
66 of 74 antivirus engines flagged eicar.com-10074, 66 of them as outright malicious. The raw count alone does not establish safety or danger; we also weigh which engines flagged it and corroborating behavior, identity, reputation, and rule evidence.
What is the SHA-256 hash of eicar.com-10074?
Evidence-based answer
The SHA-256 hash of eicar.com-10074 is 275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f, and its MD5 is 44d88612fea8a8f36de82e1278abb02f. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
Is it safe to open eicar.com-10074?
Evidence-based answer
eicar.com-10074 is not real malware, but it is intentionally designed to trigger antivirus alerts. Use it only in a controlled security test, and never send it to someone who is not expecting it.
How up to date is this analysis of eicar.com-10074?
Evidence-based answer
This report reflects the scan run on September 20, 2026. Because a file's hash never changes, the identity of eicar.com-10074 is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Chapter 06

Community

Member reviews and reports for this exact file hash.

The raw file is processed temporarily and is not retained after processing. Its hash and report are public and permanent, so the next person who checks the same file gets an instant answer. Unknown files may be submitted to VirusTotal for analysis. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.