Bitdefender Generic Evasion of Heuristics Using PDF Container
18 May 2009
Summary
BitDefender provides security solutions to satisfy the protection requirements of today's computing environment, delivering effective threat management for over 41 million home and corporate users in more than 100 countries.
The heuristics of Bitdefender can be bypassed by a special formatted PDF "container", this leads to the bypass of malicious PDF files, old or new. This is not a bypass that relies on archive structures but relies on evading certain code paths in the AV engine "through various means". Interestingly this opens the possibility to evade at scan time and run-time.