Shellcode Self-Injection via ntdll.dll Scratchpad
A staging technique observed in parasitic file infectors where the infector copies its payload shellcode into a temporary memory region (here, a newly-created section mapped at 0x60000000 with PAGE_EXECUTE_READWRITE) before writing it into the victim PE. The intermediate copy may serve as an anti-analysis or anti-EDR evasion layer: writes to the victim file are batched and appear to come from a "clean" mapped view, while the actual shellcode construction happens in a scratchpad region.
Detection / Fingerprint
CreateFileMappingAwithPAGE_EXECUTE_READWRITE(0x40) and a section name like.zeroMapViewOfFilefollowed bymemcpyfrom attacker-controlled buffer- Subsequent
memcpyinto a file-mapped PE view FlushViewOfFile+UnmapViewOfFile+SetEndOfFilesequence on an.exe
Implementation Patterns Observed
In the Phorpiex d69d4497 sample, fcn.00402160 performs:
CreateFileMappingAwith access0x60000000(RX scratchpad)- Copies shellcode into scratchpad using
memcpy - Reads sentinel bytes (
0xCCCCCCCCpairs) to locate shellcode boundaries - Copies from scratchpad into victim PE's new section
The sentinel bytes (0xCCCCCCCC) are MSVC debug-fill patterns, suggesting the shellcode was extracted from a debug build or the sentinel is deliberately used as a length marker.
Pages where observed
- phorpiex — Phorpiex campaign parasitic infector (
d69d4497) - parasitic-pe-section-append — the parent infection technique