typetechniquecreated2026-08-27updated2026-08-27code-injectionevasionruntime-api-resolutionpe

Shellcode Self-Injection via ntdll.dll Scratchpad

A staging technique observed in parasitic file infectors where the infector copies its payload shellcode into a temporary memory region (here, a newly-created section mapped at 0x60000000 with PAGE_EXECUTE_READWRITE) before writing it into the victim PE. The intermediate copy may serve as an anti-analysis or anti-EDR evasion layer: writes to the victim file are batched and appear to come from a "clean" mapped view, while the actual shellcode construction happens in a scratchpad region.

Detection / Fingerprint

  • CreateFileMappingA with PAGE_EXECUTE_READWRITE (0x40) and a section name like .zero
  • MapViewOfFile followed by memcpy from attacker-controlled buffer
  • Subsequent memcpy into a file-mapped PE view
  • FlushViewOfFile + UnmapViewOfFile + SetEndOfFile sequence on an .exe

Implementation Patterns Observed

In the Phorpiex d69d4497 sample, fcn.00402160 performs:

  1. CreateFileMappingA with access 0x60000000 (RX scratchpad)
  2. Copies shellcode into scratchpad using memcpy
  3. Reads sentinel bytes (0xCCCCCCCC pairs) to locate shellcode boundaries
  4. Copies from scratchpad into victim PE's new section

The sentinel bytes (0xCCCCCCCC) are MSVC debug-fill patterns, suggesting the shellcode was extracted from a debug build or the sentinel is deliberately used as a length marker.

Pages where observed