typetechniquecreated2026-08-27updated2026-08-27pecode-injectionparasitic-infectorevasionmitre-attck

Parasitic PE Section Append Infection

A file-infection technique in which a parasitic malware appends a new PE section to existing executables, copies its payload shellcode into that section, and patches the victim's entry point to trampoline through the new code. The victim file remains functional (the original entry point is preserved and eventually reached) but now carries and executes attacker code on every launch.

Detection / Fingerprint

  • New section appended after .reloc or the last existing section
  • Section name may be .zero, .text, or random ASCII
  • NumberOfSections incremented by 1
  • SizeOfImage expanded to cover new section
  • AddressOfEntryPoint redirected to the new section's RVA
  • Infection sentinel in ImageBase (e.g., 0xdead) or other PE header field
  • Victim file timestamp modified (unless the infector preserves it)

Implementation Patterns Observed

In the Phorpiex TWIZTPEINF variant (d69d4497), the infector:

  1. Memory-maps the victim PE via CreateFileMappingA + MapViewOfFile
  2. Validates MZ/PE signatures and machine type (x86 or x64)
  3. Checks ImageBase != 0xdead to avoid re-infection
  4. Appends a section named .zero with characteristics 0x60000000 (RX)
  5. Copies position-independent shellcode into the new section using a self-measured size (&end_func - &start_func)
  6. Patches AddressOfEntryPoint to the new section's entry
  7. Sets ImageBase = 0xdead as infection marker
  8. Flushes view, truncates file, and closes handles

Reproduce on your own VMs

  1. Write a small x86 PI shellcode that resolves LoadLibraryA and MessageBoxA via PEB walking, then calls them.
  2. Compile a test PE (victim.exe) with MSVC, stripped.
  3. Open victim.exe with CreateFileMappingA(FILE_MAP_READ|FILE_MAP_WRITE).
  4. Parse the PE headers to find the last section header.
  5. Compute new section RVA = align(last_section.VirtualAddress + last_section.VirtualSize, SectionAlignment).
  6. Compute raw offset = align(last_section.PointerToRawData + last_section.SizeOfRawData, FileAlignment).
  7. Append section header with Name=.zero, VirtualSize=shellcode_len, VirtualAddress=new_rva, SizeOfRawData=aligned_len, PointerToRawData=new_raw, Characteristics=0x60000000.
  8. Increment NumberOfSections, update SizeOfImage.
  9. Patch AddressOfEntryPoint = new_rva + shellcode_entry_offset.
  10. Copy shellcode to file offset new_raw.
  11. Verify with dumpbin /headers and rabin2 -S.

Defensive Countermeasures

  • Integrity monitoring on executables (Tripwire, OSSEC, Windows Defender Application Control)
  • YARA rule for .zero section + ImageBase == 0xdead
  • Block execution from newly-created .exe files on removable drives
  • Alert on CreateFileMappingA with PAGE_EXECUTE_READWRITE against .exe files

Pages where observed

  • phorpiex — Phorpiex campaign parasitic infector (d69d4497)