EICAR and GTUBE Generator - Anti VIrus Results -

Marco Ramilli
Date
22 December 2009
Read
Share
Analyzing the EICAR-GTUBE_Generator using a common multi-anti-virus platform like VirusTotal seems no AVs recognaize the EICAR-GTUBE-Generator as a EICAR generator (so in some way a malware generator): here the proof (click to enlarge)

Now, my question is: Do the AVs truly analyze the EICAR signature or do they apply a simple pattern matching ?
On the other hand, analyzing the resulted file EICAR.com there is more fun:

First of all Prevx.com does not recognize the EICAR file. That's very interesting,to me. They claim to be:
"PC and Internet Security powered by the World's largest real time threat database..."
But they don't recognize one of the most famous string in AV's society. So guys, are you sure to have the world's largest DB ? Maybe you need a little of "back to easy stuff" policy ?
Anyway, the second interesting thing is on Microsoft AV which recognize EICAR but as a VIrus ( in fact at the beginning there is the label Virus:). That is technically wrong. All the other Tested AVs did a good job labeling EICAR as warning and testing file. Why does Microsoft recognize EICAR as virus and not as a standard testing file ? Maybe is this just the pic of a wrong pattern recognition's iceberg, present in Microsoft AV ? I'll check out soon !
Marco Ramilli
Date
22 December 2009
Read
Share
← Go back
Latest Posts

i-SOON Data Leak: Key Points

Introduction i-SOON (上海安洵), a prominent contractor for various Chinese government agencies such […]

Date
26.02.2024
Duration
5 min
Text
Marco Ramilli

X Gold Badges: a new proliferating market

When I saw a threat actor hijacking the X account of Google's […]

Date
08.01.2024
Duration
5 min
Text
Marco Ramilli

Technical Data Sheet: LOCKBIT 3.0

LOCKBIT 3.0 is a notorious Ransomware Group that was first identified on […]

Date
20.12.2023
Duration
5 min
Text
Marco Ramilli
1 2 3 236
Back to Top
magnifier