Parasitic PE Section Append Infection
A file-infection technique in which a parasitic malware appends a new PE section to existing executables, copies its payload shellcode into that section, and patches the victim's entry point to trampoline through the new code. The victim file remains functional (the original entry point is preserved and eventually reached) but now carries and executes attacker code on every launch.
Detection / Fingerprint
- New section appended after
.relocor the last existing section - Section name may be
.zero,.text, or random ASCII NumberOfSectionsincremented by 1SizeOfImageexpanded to cover new sectionAddressOfEntryPointredirected to the new section's RVA- Infection sentinel in
ImageBase(e.g.,0xdead) or other PE header field - Victim file timestamp modified (unless the infector preserves it)
Implementation Patterns Observed
In the Phorpiex TWIZTPEINF variant (d69d4497), the infector:
- Memory-maps the victim PE via
CreateFileMappingA+MapViewOfFile - Validates MZ/PE signatures and machine type (x86 or x64)
- Checks
ImageBase != 0xdeadto avoid re-infection - Appends a section named
.zerowith characteristics0x60000000(RX) - Copies position-independent shellcode into the new section using a self-measured size (
&end_func - &start_func) - Patches
AddressOfEntryPointto the new section's entry - Sets
ImageBase = 0xdeadas infection marker - Flushes view, truncates file, and closes handles
Reproduce on your own VMs
- Write a small x86 PI shellcode that resolves
LoadLibraryAandMessageBoxAvia PEB walking, then calls them. - Compile a test PE (
victim.exe) with MSVC, stripped. - Open
victim.exewithCreateFileMappingA(FILE_MAP_READ|FILE_MAP_WRITE). - Parse the PE headers to find the last section header.
- Compute new section RVA = align(last_section.VirtualAddress + last_section.VirtualSize, SectionAlignment).
- Compute raw offset = align(last_section.PointerToRawData + last_section.SizeOfRawData, FileAlignment).
- Append section header with Name=
.zero, VirtualSize=shellcode_len, VirtualAddress=new_rva, SizeOfRawData=aligned_len, PointerToRawData=new_raw, Characteristics=0x60000000. - Increment
NumberOfSections, updateSizeOfImage. - Patch
AddressOfEntryPoint = new_rva + shellcode_entry_offset. - Copy shellcode to file offset
new_raw. - Verify with
dumpbin /headersandrabin2 -S.
Defensive Countermeasures
- Integrity monitoring on executables (Tripwire, OSSEC, Windows Defender Application Control)
- YARA rule for
.zerosection +ImageBase == 0xdead - Block execution from newly-created
.exefiles on removable drives - Alert on
CreateFileMappingAwithPAGE_EXECUTE_READWRITEagainst.exefiles
Pages where observed
- phorpiex — Phorpiex campaign parasitic infector (
d69d4497)