Recomposer - Randomly Changes Win32/64 Pe Files For 'safer' Uploading To Malware And Sandbox Sites

✨ DeeZNuTz

✨ Master ✨
Staff member
May 15, 2017
990
759
1,045
1569929814926.png


Ever have that not so safe feeling uploading your malware binaries to VirusTotal or other AV sites because you can look up binaries by hashes? (Example: https://github.com/mubix/vt-notify)
Feel somewhat safer with Recomposer!*

Recomposer will take your binary and randomly do the following:
  • Change the file name
  • Change the section names
  • Change the section flags
  • Injection random number of five different types of nops into each available code cave over 20 bytes in length
By the way, your file will still execute, so upload away!*
Supports win32/64 PE Files!!

Two modes:
  • Manual: Works like a PE Editor, change section names and flags
  • Auto: Randomly changes the binary
Tested by creating 11200 samples from one binary. Results:
  • No hash collisions
  • ssdeep matching percentage to the original file ranged from 94% to 77%
Download Recomposer
 

About us

  • Our community has been around for many years and pride ourselves on offering unbiased, critical discussion among people of all different backgrounds. We are working every day to make sure our community is one of the best.

Quick Navigation

User Menu