EXPLAINER

What is the EICAR test file?

The safe way to check your malware scanning actually works — without going anywhere near real malware.

You have just wired file scanning into your application. How do you check it works? Uploading real malware to find out is obviously a terrible idea, and downloading a live sample to your laptop is worse.

That is the problem EICAR solves.

What it is

EICAR is a 68-character string of ordinary printable text, agreed decades ago by the European Institute for Computer Antivirus Research. Every antivirus engine deliberately detects it. It is completely harmless — if you run it on Windows it prints a message and exits.

The point is that it gives you a file every scanner agrees is "bad", so you can prove your pipeline works end to end without handling anything dangerous.

How to make one

Save this single line to a file called eicar.com:

X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

Two things people get wrong:

Generating it in code avoids both problems:

printf 'X5O!P%%@AP[4\\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*' > eicar.com

Testing your integration

Send it the way your real uploads arrive:

curl -H "Authorization: Bearer upscan_yourkey" \
     -F file=@eicar.com \
     https://upscan.desaihome.uk/v1/scans

You should get back a verdict of infected with a signature name. Different engines name it differently — Eicar-Signature, EICAR-Test-File, EICAR_Test_File — so match on the verdict, not the exact string.

Test the archive path too

Most real threats arrive wrapped in a ZIP, so it is worth confirming your scanner unpacks archives:

zip eicar.zip eicar.com
curl -H "Authorization: Bearer upscan_yourkey" \
     -F file=@eicar.zip \
     https://upscan.desaihome.uk/v1/scans

If that comes back clean, archive scanning is off — which means an attacker only needs to zip their payload to walk straight past you.

What EICAR does not tell you

This matters, and it is where people over-read a passing test.

EICAR proves your integration is connected. It says nothing about detection quality. Every scanner catches EICAR — that is the entire point of it.

A green EICAR test means files reach your scanner and verdicts come back. It does not mean you would catch a novel piece of ransomware. Treat it as a smoke test for your plumbing, not a benchmark of your security.

A checklist worth running

That last one catches a surprisingly common bug: scanning works perfectly, and the uploads quietly pile up on disk forever.

Scan your first file free

100 scans a month, no card required. Files scanned in the UK and deleted the moment scanning finishes.

Start free