More on EICAR

Marco Ramilli
Date
4 January 2010
Read
Share
Hi folks, today I wanna show these two easy experiments made by using the new version of "Quick'n Dirty" EICAR-GTUBE-Generator0.1. I know that EICAR file it's only a test file and it is not supposed to be recognized inside other files, BUT for some reasons some AVs do that. Analyzing this file we can analyze the AV's detection chain (as already explained in some past posts ) and maybe find some incompleteness.
Exp 1. Hiding EICAR file in the JPG header

Most AVs (but not all ... ) detect EICAR file even if embedded into the JPG header. Some main AV companies like AVAST, McAfee and Microsoft dont (why they cannot detect it ?).
2) Hiding EICAR file in the JPG tail:

Surprisingly only two AV companies detect it. My best compliments to Authentium and F-Port. So why Authentium and F-Port can detect EICAR even if hidden in the JPG'tail and other AV companies cannot ? What's the difference between their detection chain ?
I'll ask directly to these people during this week, I'll be back with some answers ... hopefully.
Marco Ramilli
Date
4 January 2010
Read
Share
← Go back
Latest Posts

i-SOON Data Leak: Key Points

Introduction i-SOON (上海安洵), a prominent contractor for various Chinese government agencies such […]

Date
26.02.2024
Duration
5 min
Text
Marco Ramilli

X Gold Badges: a new proliferating market

When I saw a threat actor hijacking the X account of Google's […]

Date
08.01.2024
Duration
5 min
Text
Marco Ramilli

Technical Data Sheet: LOCKBIT 3.0

LOCKBIT 3.0 is a notorious Ransomware Group that was first identified on […]

Date
20.12.2023
Duration
5 min
Text
Marco Ramilli
1 2 3 236
Back to Top
magnifier