Fun.exe is a Windows virus identified as part of the W32.Assarm family. It was reported as first appearing in early 2008. According to the provided content, it spreads via email attachments through Outlook Express, periodically sending messages with malicious attachments in response to unopened emails. It is also described as being embedded in PowerPoint documents and disguised with a folder-like icon to trick users into executing it.
On execution, Fun.exe is described as registering itself as a Windows system process and establishing persistence by installing multiple copies of itself across the infected system under different filenames and in different locations. It adds autorun entries so multiple copies execute at startup, and those copies monitor one another and restore deleted instances, making removal from within Windows difficult. The running copy is described as restarting if manually terminated.
Known filenames associated with the malware include Fun.exe, DC.exe, Other.exe, SVIQ.exe, win.exe, WinSit.exe, Windev.exe, and thisisnotmalwarelol.exe. The content notes that some of these names overlap with legitimate Windows filenames, increasing the risk of accidental deletion during manual cleanup. Additional file characteristics mentioned in the content include a creation date of 2008-06-23, original name Olalatheworld.exe, internal name Olalatheworld, and file size 124,928 bytes. No specific threat actor, industry targeting, or victim sector attribution is provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows-based virus in the W32.Assarm family that installs multiple copies of itself under different names, persists via autorun, runs as a system process, self-restores if removed, and spreads by sending email attachments through Outlook Express. The content also says it is usually embedded in PowerPoint documents and disguises itself with a folder-like icon.
2008 Agent.BTZ Asprox Conficker Fun.exe Hupigon Mariposa MonaRonaDona OpenCandy
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.