EICAR data ($eicar_hex) found by Red Hat Insights malware scan in tracker/meta.db
Hi to the Red Hat community,
I am running Red Hat Insights malware scans on a regular basis on a RHEL 8-7 workstation and rhe scan ran yesterday came back with a first hit, about data related to the EICAR anti-malware test file [1].
Match Source: /home/user/.cache/tracker/meta.db
Offset:109143803
Match Data: 58 35 4F 21 50 25 40 41 50 5B 34 5C 50 5A 58 35 34 28 50 5E 29 37 43 43 29 37 7D 24 45 49 43 41 52 2D 53 54 41 4E 44 41 52 44 2D 41 4E 54 49 56 49 52 55 53 2D 54 45 53 54 2D 46 49 4C 45 21 24 ...
Match Identifier: $eicar_hex
Match Scan Date: Mon, 03 Apr 2023 20:51:28 GMT
Source Type: file
File Type: SQLite 3.x database, last written using SQLite version 3026000
File Mime Type: application/x-sqlite3; charset=binary
File MD5Sum: 0dd8d7dd34110fe6a1526a96ffdf9786
Personally, I haven't downloaded this antivirus test file and, as the data is found in the db of Tracker (indexing for Gnome [2]), I thought it could be related to books that quote the word "EICAR" or a hash of that testfile. Tracker documentation [3] states however that Tracker simply reads metadata and, as what was found by the Insights malware scan is $eicar_hex, not sure about the meaning of this output.
This doesn't look like a threat but still, wondering how such hit should be understood in Insights.
Many thanks
Alexandre
[1] https://www.eicar.org/download-anti-malware-testfile/
[2] https://www.linuxlinks.com/tracker/
[3] https://gnome.pages.gitlab.gnome.org/tracker/faq/