Ravindra BagaleCourses & study guides Track your progress

Labs · Cyber Security

Lab: Check a Suspicious File Safely with Hashes and a Reputation Lookup, Without Ever Running It

Beginner30 minWindows Security (Microsoft Defender) · PowerShell Get-FileHash · VirusTotal website (search by hash)

Course: Cyber Security · Chapter 39: Malware Threats

Chapter 39 explains malware threats; this lab practises safe triage: hash, look up, never run.

Chala mitrano! Someone sends you "Invoice_Oct.exe". Do you double-click to see what it is? Never! Today we learn safe triage: let the antivirus check it, take its fingerprint (hash), and ask the world's antivirus engines about that fingerprint. And we test our antivirus with EICAR, a harmless file that every antivirus treats as a virus on purpose. Chala!

Suppose we are…

Suppose we work at the IT helpdesk of Bajaj Finserv. An employee forwards an attachment Invoice_Oct.exe and asks, "Is this safe?" Our process: never run it, check that Defender is active, compute the file's SHA-256, and search that hash on VirusTotal (a free service that checks files against about 70 antivirus engines). We practise with EICAR, an industry-standard harmless test file.

Goal of this lab

By the end you will be able to:

  • Confirm Microsoft Defender real-time protection is on and see it react to the EICAR test file.
  • Read Protection history for the detection name and action.
  • Compute a SHA-256 hash and search it on VirusTotal without uploading anything private.

What you need (all free)

  • Your own Windows 10/11 laptop with Windows Security (Defender) on. Mac/Linux users can do Part 2 with shasum -a 256 / sha256sum.
  • A browser. About 30 minutes.

Safety and ethics

EICAR is not malware; it is a 68-byte text file that antivirus products are designed to detect for testing. Never download or run real malware, never "test" files on someone else's computer, and never upload private or company documents to VirusTotal: uploaded files can be shared with security researchers.

Part 1: test your antivirus with EICAR

  1. Open Windows Security → Virus & threat protection → Manage settings and confirm Real-time protection is On.
  2. Open the official EICAR page https://www.eicar.org → Download Anti Malware Testfile, and download eicar.com.txt (HTTPS).

    What you should see: your browser or Defender blocks or removes the file within seconds, with a notification like "Threats found".

  3. Open Windows Security → Virus & threat protection → Protection history and click the newest entry.

    What you should see: Detected: Virus:DOS/EICAR_Test_File, Status: Quarantined or Removed, the file path, and the time. Your antivirus works.

Part 2: hash and reputation lookup

  1. The known SHA-256 of the EICAR test file is:

    275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f
    
  2. Open https://www.virustotal.com → Search tab → paste the hash → press Enter.

    What you should see: a red score like 60+/70 security vendors flagged this file, names like "EICAR-Test-File", and Details with the same SHA-256, size 68 bytes.

  3. Now check a normal file without uploading it. Use putty.exe from Lab 33 (or any installer from an official site). In PowerShell:

    Get-FileHash .\putty.exe -Algorithm SHA256
    
  4. Copy the hash and search it on VirusTotal (Search tab, not Upload).

    What you should see: 0/70 (or 1–2 low-reputation flags) and a Details page showing the signer (Simon Tatham) and first-seen date. A widely known clean file.

  5. Write the triage note the helpdesk would send: file name, SHA-256, Defender result, VirusTotal score and date checked, verdict (Malicious / Clean / Unknown), action (delete, allow, escalate to security team).

  6. Learn the rule for unknown results ("No matches found"): an unknown hash is not proof of safety. Do not run it; escalate to the security team, who can analyse it in an isolated sandbox.

Ravindra Bagale's Tip

Search by hash first, upload last. A hash reveals nothing private, but an uploaded file (your CV, a client contract) can be seen by others. And remember: .exe hidden as "Invoice.pdf.exe", .scr, .js, .iso and macro Office files are the usual tricks. Double-click nako, hash kara!

Common mistakes

Mistake What happens Fix
Running the file "to see what it does" Real malware infects the laptop Never run; hash and look up
Uploading private files to VirusTotal Confidential data may be shared Search by hash only
Treating "No matches found" as clean New malware has no reputation yet Unknown = escalate, don't run
Turning Defender off to download EICAR Your laptop is unprotected Keep protection on; the block is the test result
Trusting the icon or file name .pdf.exe with a PDF icon fools people Show file extensions in File Explorer

Self-check checklist

0 of 5 done

Try-at-home challenge

Turn on file extensions in File Explorer, then explain how Invoice_Oct.pdf.exe would look with extensions off vs on.

Check your answer

File Explorer → View → Show → tick File name extensions (Windows 10: View tab → File name extensions). With extensions off the file appears as Invoice_Oct.pdf, which looks like a document. With extensions on you see Invoice_Oct.pdf.exe, a program. Always keep extensions on.

Samjla ka? Never run, let Defender check, hash it, look it up, escalate unknowns. Aata pudhe jaauya: Chapter 40 protects availability.