EICAR download over HTTPS

eicar_download

Fetches the EICAR test file from the official eicar.org endpoints (an AMTSO test resource) to observe whether the download path — proxy, TLS inspection or on-access scanner — intercepts it.

Severity low how bad it would be if it were real
Expected outcome Something should notice
Platforms 3 macOS, Linux, Windows
Isolation subprocess runs in its own process, so a kill is a measurement

What it needs before it will run

  • runs in --safe

    Observation only. It runs even in the inert mode, because it changes nothing and sends nothing.

  • sends traffic

    Generates outbound traffic. --no-network suppresses it entirely.

Gates are cumulative and none of them is implied by another: see the three gates for why they are separate decisions.

ATT&CK techniques it exercises

MITRE ATT&CK techniques this test maps to.
Technique Name Tactic Across public reports
T1105 Ingress Tool Transfer Command and Control coverage statistics
T1204.002 Malicious File Execution coverage statistics

How often anything notices

Not enough data: fewer than 3 public reports have run this test, so no rate is published for it. Groups below that threshold are withheld everywhere on the site — with one or two contributors an average is one organisation's result with a percent sign after it.

Other antivirus signatures tests

Other tests in the Antivirus signatures category.
Test What it does Severity
Macro-bearing document shapes macro_document_shapes Writes the document shapes phishing campaigns use — a macro-enabled OOXML package with a vbaProject part, an HTA script, a Windows script file and a s… medium
EICAR test file write eicar_file_write Writes the standard 68-byte EICAR anti-malware test file into the sandbox and re-checks it for several seconds to catch asynchronous quarantine. low
EICAR variant battery eicar_variant_battery Writes six on-disk shapes of the EICAR test file (plain, double extension, padded, prefixed, zipped, nested zip) to compare how deeply the scanner ins… low

Catalogue generated from client 0.1.0. A test's behaviour can change between releases; this page describes the version named here.