Check your AV - WICAR.org - Test Your Anti-Malware Solution!

General Security Discussions
16 Replies 437 Views

Dave Russo

Level 23
Verified
Top Poster
Well-known
Forum Veteran
Maybe this is old news but fun to check your Av,browser will probably warn,just proceed to check(there is a warning)gl
 
(link omitted) Maybe this is old news but fun to check your Av,browser will probably warn,just proceed to check(there is a warning)gl


Hi Dave — an oldie, but still useful as a quick sanity check. I would slightly amend “just proceed,” though: if the browser, DNS filter or security suite blocks malware.wicar.org, that is already a successful result. Bypassing the warning deliberately removes one of the layers being tested.

A few interpretation points:

  • The EICAR item is a harmless standard test file, designed to trigger antivirus detection without containing malicious code (EICAR’s explanation).
  • WICAR also hosts actual historical browser-exploit code, mostly for ancient versions of Internet Explorer, Java, Firefox and Flash (test list). Those tests are best kept to a disposable VM, particularly if the machine is old or unpatched.
  • A URL warning may come from the browser’s reputation service, DNS filtering, an extension, network protection or the AV’s web shield. It does not necessarily show which component caught it.
  • An obsolete exploit loading without an AV alert does not automatically mean the AV failed—the current browser or operating system may simply be immune.

For a cleaner modern check, the AMTSO Security Features Check separates phishing, drive-by download and other protection tests while using approved, non-malicious samples.

So: useful for confirming that a protection layer responds, but not an AV benchmark. Passing EICAR proves the product recognises EICAR; it does not award it a black belt in malware detection.

Sources
 
Blocked by Google Safe Browsing as @Marko :) said. In Edge, interestingly, these got blocked by my DNS Quad9 first instead of Smartscreen.
1791011587367.png
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top