
An A/V evasion armoring experiment for CVE-2012-4681
A manual antivirus evasion armoring experiment for CVE-2012-4681 inspired by http://security-obscurity.blogspot.com/2012/11/java-exploit-code-obfuscation-and.html.
Base Exploit: http://pastie.org/4594319
| Sample | Notes | 2014 Score (positive detections) | 2016 Score (postive detections) |
|---|
| Original Sample | http://pastie.org/4594319 | 30/55 | 36/56 |
| Technique A | Changed Class/Method names | 28/55 | 36/56 |
| Techniques A and B | Obfuscate strings | 16/55 | 22/56 |
| Techniques A-C | Change Control Flow | 16/55 | 22/56 |
| Techniques A-D | Reflective invocations (on sensitive APIs) | 3/55 | 16/56 |
| Techniques A-E | Simple XOR Packer | 0/55 | 0/56 |