How easy to evade detection by Antivirus



Just a few days back there was an infection with a java exploit (on 25/Aug), and we got the signature for that class file. And today we saw another infection which is undetected by Antivirus


And the difference is just a minor variation in original java code.

For the one on the left hand side below is not detected while the one in right hand side we have signature and AV is detecting it.


Now we get the signature for left hand side, tomorrow they will add some more strings to the source code which cannot be detected.

Do we need to get signature for this class file????

Now I make one exploit pack change few things every time AV industry detects it so that I am always zero day exploit….ha ha ha


About wikihead

A Seeker. Information Security Professional, Pursuing Life with Ayurveda.
This entry was posted in Articles, security. Bookmark the permalink.

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s