PE Header Erasure (Anti-Dump)
After loading, the stub zeroes the in-memory PE header or corrupts SizeOfImage so memory dumpers that rely on the header fail, forcing the analyst to reconstruct the header before a dump can be parsed.
Most memory dumpers locate a module by reading its in-memory PE header: the MZ/PE signatures, the optional header, and the section table tell the tool where the image starts, how big it is, and how to lay sections out. PE header erasure attacks that assumption. Once Windows has mapped and relocated the image, the stub overwrites the header — zeroing the MZ/PE magic and the section table, or just corrupting SizeOfImage — so a dumper that scans for headers finds nothing, or computes the wrong image size and produces a truncated, unparseable dump.
How it works
The loader needs the header only until the image is mapped; afterwards it destroys it in place:
// after the loader has mapped + relocated the image at 'base'
IMAGE_DOS_HEADER *dos = (IMAGE_DOS_HEADER *)base;
IMAGE_NT_HEADERS *nt = (IMAGE_NT_HEADERS *)((BYTE *)base + dos->e_lfanew);
// option A: nuke the signatures so scanners can't find the module
RtlZeroMemory(base, nt->OptionalHeader.SizeOfHeaders);
// option B: leave the header but lie about the size
nt->OptionalHeader.SizeOfImage = 0x1000; // dumper grabs one page onlyExecution continues normally because the OS no longer consults the header, but any tool that re-reads it sees garbage.
Detection & bypass
- Static — Irrelevant by definition: erasure happens at runtime. On disk the file still has a header; the trick only manifests in memory.
- Dynamic — In the debugger, inspect the module's base page: a zeroed first page (no
MZ) or aSizeOfImagefar smaller than the mapped region is the signature. Compare the loaded module's real extent (from the memory map / VAD) against the header's claimed size to spot the corruption. Breakpoint onRtlZeroMemory/memsetwrites targeting the image base to catch the erasure happening. - Rebuild — Reconstruct the header from a clean on-disk copy of the same file (the file header is intact on disk), or let pe-sieve rebuild it: pe-sieve scans process memory, recovers section boundaries, and writes a valid header for the dump. Alternatively dump each section by its real memory bounds and assemble a fresh PE in PE-bear, fixing
SizeOfImage, the section table, and the entry point by hand. - Tools — pe-sieve (automatic header reconstruction and dumping), Scylla (image dump with header rebuild), PE-bear (manual header/section repair), and the debugger's memory map to find the true image bounds.