From Bloodhound to Acrobat JS
April 24th, 2009
Walk with me. Let me rap unto you a little story about how an AV detection might go. So, your AV makes a good detection on a suspect file. Unbelievable already right? Say it does, but it’s using a heuristics engine and not it’s typical signature definitions.
For Symantec these heuristics are Bloodhound and files that are flagged usually get some name such as ‘Bloodhound.exploit.somenumber’.
So, is this it? Leave it and move on to the next thing that will burn up the day? It doesn’t have to be. Let’s dig deeper. Read more…

