SYMBOLCOMMON_NAMEaka. SYNONYMS
win.puzzlemaker (Back to overview)

puzzlemaker

Actor(s): [Unnamed group]

VTCollection    

The dropper module is used to install two executables that pretend to be legitimate files belonging to Microsoft Windows OS. One of these files (%SYSTEM%\WmiPrvMon.exe) is registered as a service and is used as a launcher for the second executable. This second executable (%SYSTEM%\wmimon.dll) has the functionality of a remote shell and can be considered the main payload of the attack.

References
2021-06-08 ⋅ Kaspersky ⋅ Alexey Kulaev, Boris Larin, Costin Raiu
PuzzleMaker attacks with Chrome zero-day exploit chain
Chainshot puzzlemaker
Yara Rules
[TLP:WHITE] win_puzzlemaker_auto (20260917 | Detects win.puzzlemaker.)
rule win_puzzlemaker_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.puzzlemaker."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.puzzlemaker"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { eb1e 488bc3 498784f620300200 4885c0 }
            // n = 4, score = 100
            //   eb1e                 | dec                 esp
            //   488bc3               | mov                 ebp, edx
            //   498784f620300200     | dec                 ebx
            //   4885c0               | mov                 ecx, dword ptr [esi + edi*8 + 0x230c0]

        $sequence_1 = { 4a0fbe8419b8640100 428a8c19c8640100 4c2bd0 418b4148 418b52fc d3ea 03c2 }
            // n = 7, score = 100
            //   4a0fbe8419b8640100     | xorps    xmm0, xmm0
            //   428a8c19c8640100     | dec                 eax
            //   4c2bd0               | lea                 eax, [0x13b18]
            //   418b4148             | dec                 eax
            //   418b52fc             | mov                 dword ptr [ebx], eax
            //   d3ea                 | dec                 eax
            //   03c2                 | mov                 eax, ebx

        $sequence_2 = { 4a0fbe8439b8640100 428a8c39c8640100 482bd0 8b42fc d3e8 eb02 8bc3 }
            // n = 7, score = 100
            //   4a0fbe8439b8640100     | lea    ecx, [0xfffefbf3]
            //   428a8c39c8640100     | dec                 eax
            //   482bd0               | shl                 esi, 2
            //   8b42fc               | movzx               eax, word ptr [ecx + edi*4 + 0x19740]
            //   d3e8                 | dec                 eax
            //   eb02                 | lea                 edx, [ecx + 0x18e30]
            //   8bc3                 | dec                 eax

        $sequence_3 = { 0bc7 e9???????? ff8170040000 83b97004000002 0f8407020000 4c8d350aff0000 }
            // n = 6, score = 100
            //   0bc7                 | dec                 eax
            //   e9????????           |                     
            //   ff8170040000         | lea                 eax, [0x141ae]
            //   83b97004000002       | dec                 eax
            //   0f8407020000         | cmp                 ecx, eax
            //   4c8d350aff0000       | je                  0x9dd

        $sequence_4 = { 8bd0 85c0 7412 488dbd10020000 33c0 b908030000 }
            // n = 6, score = 100
            //   8bd0                 | nop                 word ptr [eax + eax]
            //   85c0                 | xor                 eax, eax
            //   7412                 | dec                 esp
            //   488dbd10020000       | lea                 ecx, [0xd3bb]
            //   33c0                 | dec                 ecx
            //   b908030000           | mov                 edx, ecx

        $sequence_5 = { 48895c2408 57 4883ec20 33db 488d3d3d6d0100 488b0c3b }
            // n = 6, score = 100
            //   48895c2408           | lea                 eax, [0xffffb3c9]
            //   57                   | dec                 ecx
            //   4883ec20             | mov                 edx, dword ptr [edi + 8]
            //   33db                 | movzx               ecx, byte ptr [edx]
            //   488d3d3d6d0100       | and                 ecx, 0xf
            //   488b0c3b             | dec                 esp

        $sequence_6 = { e8???????? 85ff 418d4701 488d3541020200 }
            // n = 4, score = 100
            //   e8????????           |                     
            //   85ff                 | dec                 eax
            //   418d4701             | test                ebx, ebx
            //   488d3541020200       | je                  0x136

        $sequence_7 = { 440f44f8 eb1b 498bcc ff15???????? 488b8d00020000 ba983a0000 ff15???????? }
            // n = 7, score = 100
            //   440f44f8             | dec                 eax
            //   eb1b                 | mov                 eax, ebx
            //   498bcc               | dec                 ecx
            //   ff15????????         |                     
            //   488b8d00020000       | xchg                dword ptr [edi + esi*8 + 0x22758], eax
            //   ba983a0000           | dec                 eax
            //   ff15????????         |                     

        $sequence_8 = { 8bda 4c8d053e0e0100 488bf9 488d153c0e0100 b904000000 e8???????? }
            // n = 6, score = 100
            //   8bda                 | jne                 0x3a3
            //   4c8d053e0e0100       | xor                 ecx, ecx
            //   488bf9               | test                eax, eax
            //   488d153c0e0100       | js                  0x4fe
            //   b904000000           | dec                 esp
            //   e8????????           |                     

        $sequence_9 = { 488d4d07 ff15???????? 498bcc ff15???????? 498bcf }
            // n = 5, score = 100
            //   488d4d07             | xor                 eax, eax
            //   ff15????????         |                     
            //   498bcc               | cmp                 ecx, 2
            //   ff15????????         |                     
            //   498bcf               | xor                 eax, eax

    condition:
        7 of them and filesize < 331776
}
Download all Yara Rules