IOC Report
habe_fun.exe

loading gifFilesProcessesURLsMemdumps1020102Label

Files

File Path
Type
Category
Malicious
Download
habe_fun.exe
PE32 executable (console) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Temp\45D4.tmp\45D5.tmp\45D6.bat
Unicode text, UTF-8 text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\habe_fun.exe
"C:\Users\user\Desktop\habe_fun.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\cmd.exe
"C:\Windows\sysnative\cmd" /c "C:\Users\user\AppData\Local\Temp\45D4.tmp\45D5.tmp\45D6.bat C:\Users\user\Desktop\habe_fun.exe"
C:\Windows\System32\chcp.com
chcp 65001

URLs

Name
IP
Malicious
https://workupload.com/file/9Ha2YGuhADX
unknown
https://discord.gg/cometrs
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
Download
21C33A50000
heap
page read and write
6ACD17F000
stack
page read and write
21C33990000
heap
page read and write
590000
heap
page read and write
21C338B0000
heap
page read and write
400000
unkown
page readonly
59A000
heap
page read and write
6ACD07C000
stack
page read and write
920000
heap
page read and write
417000
unkown
page write copy
470000
heap
page read and write
401000
unkown
page execute read
9B000
stack
page read and write
21C33A58000
heap
page read and write
19D000
stack
page read and write
420000
heap
page read and write
2157000
heap
page read and write
417000
unkown
page read and write
59E000
heap
page read and write
450000
heap
page read and write
21C33CE5000
heap
page read and write
23E0000
heap
page read and write
401000
unkown
page execute read
413000
unkown
page readonly
23F0000
heap
page read and write
400000
unkown
page readonly
21C33A5A000
heap
page read and write
413000
unkown
page readonly
2210000
heap
page read and write
430000
heap
page read and write
21C33CE0000
heap
page read and write
2150000
heap
page read and write
419000
unkown
page readonly
419000
unkown
page readonly
21C339B0000
heap
page read and write
6ACD0FE000
stack
page read and write
2280000
heap
page read and write
There are 27 hidden memdumps, click here to show them.