RFR: Why Excel Export Files Open as Corrupt: EICAR Signature in Item Content

Erik Haake
Erik Haake
  • Updated
  • Jama Connect® version(s)
    • Cloud/CVC

Summary

This article explains why a default Excel export can appear as a corrupt .xls file when item content includes the EICAR antivirus test string.

Jama successfully generates the export file, but downstream security tools (such as antivirus, data loss prevention, or network inspection systems) can detect the EICAR test signature and interrupt, modify, or quarantine the file during download. When that happens, Excel may report the file as damaged or unreadable.

In this case, the full EICAR signature triggered external security behavior.

Example EICAR test signature:

X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

This is the standard EICAR antivirus test string. It is not a real virus, but many security tools are designed to detect it and may block or modify files that contain it.

Resolution

Identify the Triggering Content

First, locate the item text included in the export and check for the EICAR test signature string. If the content contains the full EICAR pattern, treat it as the likely trigger for downstream security scanning.

Next, confirm that the export process completes successfully in Jama logs. If the report completes server-side without generation errors, this supports the conclusion that corruption occurs after file generation.

Apply the Immediate Fix

Edit the affected item content to remove or alter the EICAR test signature in the exported fields. Even a one-character change breaks the antivirus test signature and usually prevents security tools from flagging the file.

After updating the content, run the same export again and verify that Excel opens the file normally. If it opens correctly, the issue is resolved.

Confirm with Security Team

Ask your security or network team to review antivirus, proxy, and content inspection logs for the export timestamp. They should check for detections or policy actions tied to the EICAR pattern.

If security logs show interception events, document the finding as external tooling behavior rather than a Jama export defect.

Prevent Recurrence

Do not store EICAR test signatures in fields that are commonly included in reports or exports unless testing specifically requires it. If testing is required, keep it in controlled non-production scenarios and coordinate with security teams in advance.

If users must keep antivirus test content in Jama, recommend using export exclusions or a sanitized variant of the text for reportable fields so downstream tools do not alter exported files.

 

Additional Resources

Feedback:
We welcome your input! Please sign in to leave any comments, suggestions, or ideas for improvement below.

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request

Comments

0 comments

Please sign in to leave a comment.