
Modifica aleatoriamente archivos PE Win32/64 para una carga 'más segura' a sitios de malware y sandbox.
¿Alguna vez has tenido esa sensación de inseguridad al subir tus binarios de malware a VirusTotal u otros sitios de antivirus porque se pueden buscar binarios por sus hashes? (Ejemplo: https://github.com/mubix/vt-notify)
¡Siéntete un poco más seguro con Recomposer!*
Recomposer tomará tu binario y hará aleatoriamente lo siguiente:
Por cierto, tu archivo seguirá ejecutándose, ¡así que súbelo sin miedo!*
¡Soporta archivos PE win32/64!!
Dos modos:
Probado creando 11200 muestras a partir de un binario. Resultados:
./recomposer.py -f live.sysinternals.com/Tcpview.exe -a
Old file name: live.sysinternals.com/Tcpview.exe
New file name: zYmycO4NO2LYW.exe
[*] Checking if binary is supported
[*] Gathering file info
1 Section: .text | SectionFlags: 0x60000020
2 Section: .rdata | SectionFlags: 0x40000040
3 Section: .data | SectionFlags: 0xc0000040
4 Section: .rsrc | SectionFlags: 0x40000040
[*] Changing Section .text Name
[*] Changing Section .rdata Name
[*] Changing Section .data Flags
[*] Changing Section .data Name
[*] Changing Section .rsrc Name
Updated Binary:
updatedfile/zYmycO4NO2LYW.exe
[*] Checking if binary is supported
[*] Gathering file info
1 Section: .mhz | SectionFlags: 0x60000020
2 Section: .p1k | SectionFlags: 0x40000040
3 Section: .FSr0U | SectionFlags: 0xd0000443
4 Section: .q2X | SectionFlags: 0x40000040
Writing to log_recomposer.txt
Puede que veas esta advertencia:
[!] Warning, .text section hash is not changed!
[!] No caves available for nop injection.
Lo que significa que el hash de la sección .text será el mismo que el del archivo original y será buscable (en la web) una vez que Google indexe los resultados de VT (si subes el archivo, por supuesto). Si esto sucede, codificar el archivo recomponido con upx debería solucionar ese problema (a menos que el archivo ya esté codificado con upx).
Una vez que Recomposer termine, tu archivo estará en el directorio updatedfile. ¡Siéntete libre de subirlo a tu servicio de sandbox de malware favorito!
Un Editor de PE simple:
./recomposer.py -f live.sysinternals.com/Tcpview.exe -m
[*] Checking if binary is supported
[*] Gathering file info
[?] What sections would you like to change:
1 Section: .text | SectionFlags: 0x60000020
2 Section: .rdata | SectionFlags: 0x40000040
3 Section: .data | SectionFlags: 0xc0000040
4 Section: .rsrc | SectionFlags: 0x40000040
Section number:1
[-] You picked the .text section.
[?] Would you like to (A) change the section name or (B) the section flags? b
[-] You picked: b
=========================
[*] Current attributes:
.text | 0x60000020
[-] IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_EXECUTE
[-] IMAGE_SCN_CNT_CODE
=========================
[*] Commands 'zero' out the flags, 'help', 'write', or ('exit', 'quit', 'q', 'done')
[*] Use 'write' to commit your changes or 'clear' to start over.
[?] Enter an attribute to add or type 'help' or 'exit':
[...]
Solo sigue el menú y tus resultados estarán en el directorio updatedfile como change.filename.exe o como el nombre que hayas elegido al usar el flag -o.
Si estás confundido sobre dónde están tus archivos, solo mira log_recomposer.txt para conocer la ubicación y los hashes de los archivos modificados:
filename|filename_hash|changedfile|changedfile_hash
psinfo.exe|ae1554f2c1b1454a91c5610747603824|updatedfile/8dV5.exe|791ff4d4b2010accebc718afda58f83a
psexec.exe|d0df366711c8b296680002840336b6fd|updatedfile/udi6ieIVFi.exe|6fafa108d697a46a271a918436e60cd5
live.sysinternals.com/Tcpview.exe|9aa5a93712c584acdcaa7eef9d25ef4d|updatedfile/zYmycO4NO2LYW.exe|fd984b833443c457668a480a37cf9904
live.sysinternals.com/Tcpview.exe|9aa5a93712c584acdcaa7eef9d25ef4d|updatedfile/change.Tcpview.exe|c43eeec089a3e4f9e6fd0218a27ca4c2
*Recomposer no impide que el malware notifique al propietario del malware de que su binario se está ejecutando fuera de un entorno esperado.**
**P.ej.: Tu entorno.***
***Pero si no te importa, ¡adelante!