Several years ago, the tool "DSplit" was released by class101 which was used to demonstrate how some AV signatures could be bypassed by finding and modifying one byte within the binary. Unfortunately, the original file (and source code?) is no longer available for download by the author. During OSCE's AV bypass module, I recalled learning about the method described in the linked post and using DSplit to bypass signature based AV detection. I wanted to play around with it using the OSCE labs. I proceeded to search for DSplit and came to the same conclusion as the above author, what can be found looks rather janky.