Just a few days back there was an infection with a java exploit (on 25/Aug), and we got the signature for that class file. And today we saw another infection which is undetected by Antivirus
And the difference is just a minor variation in original java code.
For the one on the left hand side below is not detected while the one in right hand side we have signature and AV is detecting it.
Now we get the signature for left hand side, tomorrow they will add some more strings to the source code which cannot be detected.
Do we need to get signature for this class file????
Now I make one exploit pack change few things every time AV industry detects it so that I am always zero day exploit….ha ha ha