RWX Section Self-Modifying Code
A PE section marked simultaneously readable, writable, and executable (IMAGE_SCN_MEM_READ | IMAGE_SCN_MEM_WRITE | IMAGE_SCN_MEM_EXECUTE, characteristics 0xE0000020). Legitimate software rarely needs all three permissions on the same section. Malware uses RWX sections to decrypt, unpack, or rewrite code in-place at runtime without calling VirtualProtect.
Fingerprint
- Section characteristics contain
0xE0000020or0x60000020. .textwithMEM_WRITEis a strong anomaly.- High entropy (>7.0) in the on-disk section indicates encrypted or compressed content.
Countermeasures
- EDR hooks on
VirtualProtectmay miss in-place decryption if the section is already RWX. - Memory-scanning after the entry point completes can catch decrypted payloads.
Pages Where Observed
- wraith —
.stuband.textboth RWX. ^[sample 0ab9a570/pefile.txt]