{
  "family": "eicardemo",
  "sample_count": 1,
  "category": "advanced_threat",
  "description": "<h3>Executive Summary</h3>\nEICAR Demo (or the EICAR Standard Anti-Virus Test File) is **NOT MALWARE**. It is a safe, standardized, and internationally recognized 68-byte text file developed by the European Institute for Computer Antivirus Research (EICAR) and the Computer Antivirus Research Organization (CARO). Its sole purpose is to safely test and verify the operational status, detection capabilities, and alerting mechanisms of antivirus (AV) software, Endpoint Detection and Response (EDR) solutions, and network security appliances without exposing the network to actual malicious code.\n\n<h3>Technical Capabilities (Safe Testing)</h3>\nThe EICAR test file is literally a short string of printable ASCII characters (`X5O!P%@AP[4\\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*`). It contains no malicious logic, cannot self-replicate, cannot access the network, and cannot harm the system in any way.\n\nHow it functions in a security context:\n<ul>\n<li><strong>Standardized Signature:</strong> All legitimate, commercial antivirus vendors have explicitly programmed their scanning engines to recognize this specific 68-byte string as a \"virus\" for testing purposes.</li>\n<li><strong>Validation of Defense in Depth:</strong> Security administrators deploy the EICAR file in various formats (e.g., plain text, compressed in a `.zip` archive, or embedded in an email) to verify that different layers of their security stack (email gateways, web proxies, endpoint AV) are functioning and successfully blocking malicious signatures.</li>\n<li><strong>Alerting Verification:</strong> It is frequently used during incident response drills to verify that when an endpoint detects malware, the alert successfully traverses the network and appears correctly in the centralized Security Information and Event Management (SIEM) dashboard.</li>\n</ul>\n\n<h3>Threat Assessment</h3>\nThere is absolutely **ZERO THREAT** posed by the EICAR test file itself. However, if an administrator downloads the EICAR file and the local antivirus solution fails to detect it, that represents a critical security failure, indicating the AV engine is broken, disabled, or misconfigured.\n\n<h3>Incident Response and Remediation</h3>\n<ul>\n<li><strong>No Remediation Required (For the File):</strong> If the antivirus successfully detects and quarantines the EICAR file, the system is working as intended. The file can be safely deleted or left in quarantine.</li>\n<li><strong>Investigate Lack of Detection:</strong> If the EICAR file is downloaded and *not* detected, immediate IT intervention is required to troubleshoot the endpoint security software and restore its protective capabilities.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "EICAR_Test_File",
    "Test-File.EICAR",
    "Not-A-Virus:EICAR-Test-Signature"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [],
  "cisa_advisory": null,
  "last_updated": "2026-07-02T07:27:02Z",
  "type": "Test File (Non-Malicious)",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}