EXPLAINER
What is the EICAR test file?
The safe way to check your malware scanning actually works — without going anywhere near real malware.
You have just wired file scanning into your application. How do you check it works? Uploading real malware to find out is obviously a terrible idea, and downloading a live sample to your laptop is worse.
That is the problem EICAR solves.
What it is
EICAR is a 68-character string of ordinary printable text, agreed decades ago by the European Institute for Computer Antivirus Research. Every antivirus engine deliberately detects it. It is completely harmless — if you run it on Windows it prints a message and exits.
The point is that it gives you a file every scanner agrees is "bad", so you can prove your pipeline works end to end without handling anything dangerous.
How to make one
Save this single line to a file called eicar.com:
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
Two things people get wrong:
- No trailing newline or extra spaces. The string must be exact, or engines may not flag it.
- Your own antivirus will delete it. That is the whole idea, but it makes the file awkward to keep around. Most people generate it at runtime instead of committing it to a repository.
Generating it in code avoids both problems:
printf 'X5O!P%%@AP[4\\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*' > eicar.com
Testing your integration
Send it the way your real uploads arrive:
curl -H "Authorization: Bearer upscan_yourkey" \
-F file=@eicar.com \
https://upscan.desaihome.uk/v1/scans
You should get back a verdict of infected with a signature name. Different engines name it differently — Eicar-Signature, EICAR-Test-File, EICAR_Test_File — so match on the verdict, not the exact string.
Test the archive path too
Most real threats arrive wrapped in a ZIP, so it is worth confirming your scanner unpacks archives:
zip eicar.zip eicar.com
curl -H "Authorization: Bearer upscan_yourkey" \
-F file=@eicar.zip \
https://upscan.desaihome.uk/v1/scans
If that comes back clean, archive scanning is off — which means an attacker only needs to zip their payload to walk straight past you.
What EICAR does not tell you
This matters, and it is where people over-read a passing test.
EICAR proves your integration is connected. It says nothing about detection quality. Every scanner catches EICAR — that is the entire point of it.
A green EICAR test means files reach your scanner and verdicts come back. It does not mean you would catch a novel piece of ransomware. Treat it as a smoke test for your plumbing, not a benchmark of your security.
A checklist worth running
- Clean file →
clean - EICAR →
infected - EICAR inside a ZIP →
infected - Scanner unreachable → your app behaves the way you intended (fails open or closed, deliberately)
- The file is deleted from your temporary storage afterwards
That last one catches a surprisingly common bug: scanning works perfectly, and the uploads quietly pile up on disk forever.
Scan your first file free
100 scans a month, no card required. Files scanned in the UK and deleted the moment scanning finishes.
Start free