typeconceptconfidencehighcreated2026-08-04updated2026-08-04obfuscationevasiondefense-evasion

RWX Section Self-Modifying Code

A PE section marked simultaneously readable, writable, and executable (IMAGE_SCN_MEM_READ | IMAGE_SCN_MEM_WRITE | IMAGE_SCN_MEM_EXECUTE, characteristics 0xE0000020). Legitimate software rarely needs all three permissions on the same section. Malware uses RWX sections to decrypt, unpack, or rewrite code in-place at runtime without calling VirtualProtect.

Fingerprint

  • Section characteristics contain 0xE0000020 or 0x60000020.
  • .text with MEM_WRITE is a strong anomaly.
  • High entropy (>7.0) in the on-disk section indicates encrypted or compressed content.

Countermeasures

  • EDR hooks on VirtualProtect may miss in-place decryption if the section is already RWX.
  • Memory-scanning after the entry point completes can catch decrypted payloads.

Pages Where Observed

  • wraith — .stub and .text both RWX. ^[sample 0ab9a570/pefile.txt]