AyrA icon

EICAR standard antivirus test file

AyrA | PRO | 09/19/16 12:09:12 PM UTC | 0 ⭐ | 1346 👁️ | Never ⏰ | []
ASM (NASM) |

0 B

|

None

|

0 👍

/

0 👎

;This is an Assembly File to generate the EICAR AntiVirus Test File
 
org 0100h   ;Make this a DOS .com Executable
 
pop  ax     ;AX=0           SS:[SP]=0
xor  ax,214Fh   ;AX=0x214F
push ax     ;SP=0xFFFE      SS:[SP]=0x214F
and  ax,4140h   ;AX=0x0140      ->0x0140=instruction Location after the EICAR String
push ax     ;SP=0xFFFC      SS:[SP]=0x0140
pop  bx     ;BX=0x0140      SP=0xFFFE
xor  al,5Ch ;AX=0x011C      ->0x011C=EICAR String Memory Location
push ax     ;SP=0xFFFC      SS:[SP]=0x011C
pop  dx     ;DX=0x011C      SP=0xFFFE
pop  ax     ;AX=0x214F      SP=0x0
xor  ax,2834h   ;AX=0x097B
push ax     ;SP=0xFFFE      SS:[SP]=0x097B
pop  si     ;SI=0x097B      SP=0x0
sub  [bx],si    ;[0x0140]=0x2B48-0x097B=0x21CD ->Self modify Code: change Instruction at 0x0140 to "int 0x21" (DOS print string call)
inc  bx     ;BX=0x0141
inc  bx     ;BX=0x0142
sub  [bx],si    ;[0x0142]=0x2A48-0x097B=0x20CD ->Change Instruction at 0x0142 to "int 0x20" (DOS exit call)
jge  0140h  ;Jump to the (meanwhile) changed Instruction at 0x0140
;Above is the "Jump if greater or equal" Instruction, but because of the Subtraction
;this Jump is always performed. (ZS Flag is unset after Subtraction)
DB   "EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$"
dec  ax         ;These two Instructions are just here to
sub  cx,[bx+si+2Ah] ;occupy space and are rewritten at Runtime
 
;Conclusion
;==========
;
;We did the folowing:
;
;1. use only ASCII printable chars to output Text
;2. modify the Code at runtme with the non ASCII-printable interrupt calls
;
;We could do instead (if non ASCII-printables is allowed):
;----------------------
;org  0100h     ;Declare this as a DOS .com File -> Statement depends on Assembler used.
;mov  dx,msg    ;Depending on the Assembler, the Modifier "OFFSET" is required before msg
;mov  ax,097Bh  ;Put the Print String Function (0x09) in AH Register (AL is 0x7B but we don't care)
;int  21h       ;Call the Print Function
;int  20h       ;Exit the Application
;msg  DB        "EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$"
;----------------------
;This will generate a smaller .com File that contains non-ASCII-printable chars in it.
;Above Code does not generates the EICAR File
;
;Do we have another Method for generating a valid EICAR File?
;
;Yes:
;Create a new File with only the Folowing line and assemble it.
;----------------------
;DB "X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*"
;----------------------
;Come on, that's silly!
;- But it works!
;  You may also wish to add "org 0100h" as the first line for it to generate valid .com Files

Comments

  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎