Skip to content

Malware

puzzlemaker

The dropper module is used to install two executables that pretend to be legitimate files belonging to Microsoft Windows OS.

puzzlemaker is a Windows malware family operated by [Unnamed group].

Background

The dropper module drops two executables that masquerade as legitimate Microsoft Windows OS files. The first (%SYSTEM%\WmiPrvMon.exe) is registered as a service and serves as a launcher for the second. That second file (%SYSTEM%\wmimon.dll) acts as a remote shell and represents the attack's main payload.


Source: Malpedia (Fraunhofer FKIE).