| download: | /fiddler-classic/FiddlerSetup.5.0.20242.10753-latest.exe |
| Full analysis: | https://app.any.run/tasks/4b6f0c01-3f04-48f4-9543-c382476a79d3 |
| Verdict: | Malicious activity |
| Analysis date: | April 08, 2024, 07:45:28 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 78537045A5E032D4AC93514F027C7A47 |
| SHA1: | 5B6E705B20652C0CF39EE890013B9B8E8AD26B07 |
| SHA256: | 06812518A722AF6F98FBD8C3A5ACE0CAD1C6D53477972618728E64BAFCBC948C |
| SSDEEP: | 98304:3UcCiT73zI3qt/zDuMslI4vT8LPWtl65FOGVHCi5W8DiGfB8l5JZhmkxFpUgwPXN:Y7mjc7++svyh5 |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:07:02 02:09:39+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 26112 |
| InitializedDataSize: | 139776 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x34fc |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.0.20242.10753 |
| ProductVersionNumber: | 5.0.20242.10753 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| Comments: | http://www.telerik.com/fiddler |
| CompanyName: | Progress Software Corporation |
| FileDescription: | Installer for Progress Telerik Fiddler Classic |
| FileVersion: | 5.0.20242.10753 |
| LegalCopyright: | Copyright ©2003 - 2024 Progress Software Corporation. All rights reserved. |
| ProductName: | Progress Telerik Fiddler Classic Setup |
| ProductVersion: | 5.0.20242.10753 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 492 | "C:\Users\admin\AppData\Local\Programs\Fiddler\Fiddler.exe" | C:\Users\admin\AppData\Local\Programs\Fiddler\Fiddler.exe | explorer.exe | ||||||||||||
User: admin Company: Progress Software Corporation Integrity Level: MEDIUM Description: Fiddler Version: 5.0.20242.10753 Modules
| |||||||||||||||
| 920 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 1a4 -InterruptEvent 0 -NGENProcess 198 -Pipe 1a0 -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | ngen.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| 1124 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1260 --field-trial-handle=1100,i,15978449684013051289,11500370336417600787,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1216 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 194 -InterruptEvent 0 -NGENProcess 188 -Pipe 190 -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | ngen.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| 1308 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 214 -InterruptEvent 0 -NGENProcess 1b4 -Pipe 1c8 -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | — | ngen.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| 1316 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3444 --field-trial-handle=1100,i,15978449684013051289,11500370336417600787,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1644 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 108 -InterruptEvent 0 -NGENProcess f8 -Pipe 104 -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | — | ngen.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| 1784 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate http://fiddler2.com/r/?Fiddler2FirstRun | C:\Program Files\Microsoft\Edge\Application\msedge.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1792 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 20c -InterruptEvent 0 -NGENProcess 1fc -Pipe 18c -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | — | ngen.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| 1976 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe" install "C:\Users\admin\AppData\Local\Programs\Fiddler\EnableLoopback.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe | — | FiddlerSetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Common Language Runtime native compiler Exit code: 4294967295 Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| (PID) Process: | (3488) FiddlerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Fiddler2\InstallerSettings |
| Operation: | write | Name: | InstallPath |
Value: C:\Users\admin\AppData\Local\Programs\Fiddler\ | |||
| (PID) Process: | (3488) FiddlerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Fiddler2\InstallerSettings |
| Operation: | write | Name: | PluginPath |
Value: "C:\Users\admin\AppData\Local\Programs\Fiddler\Inspectors\" | |||
| (PID) Process: | (3488) FiddlerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Fiddler2\InstallerSettings |
| Operation: | write | Name: | ScriptPath |
Value: "C:\Users\admin\AppData\Local\Programs\Fiddler\Scripts\" | |||
| (PID) Process: | (3488) FiddlerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Fiddler2\InstallerSettings |
| Operation: | write | Name: | InstalledVersion |
Value: 5.0.20242.10753 | |||
| (PID) Process: | (3488) FiddlerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION |
| Operation: | write | Name: | Fiddler.exe |
Value: 0 | |||
| (PID) Process: | (3488) FiddlerSetup.exe | Key: | HKEY_CLASSES_ROOT\Fiddler.ArchiveZip |
| Operation: | write | Name: | PerceivedType |
Value: compressed | |||
| (PID) Process: | (3488) FiddlerSetup.exe | Key: | HKEY_CLASSES_ROOT\Fiddler.ArchiveZip |
| Operation: | write | Name: | Content Type |
Value: application/vnd.telerik-fiddler.SessionArchive | |||
| (PID) Process: | (3488) FiddlerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Fiddler2 |
| Operation: | write | Name: | UpdatePending |
Value: False | |||
| (PID) Process: | (3488) FiddlerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Fiddler2\UI |
| Operation: | write | Name: | frmViewer_WState |
Value: 2 | |||
| (PID) Process: | (3488) FiddlerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Fiddler2 |
| Operation: | write | Name: | JSEditor |
Value: C:\Users\admin\AppData\Local\Programs\Fiddler\ScriptEditor\FSE2.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2896 | FiddlerSetup.5.0.20242.10753-latest.exe | C:\Users\admin\AppData\Local\Temp\nsp2576.tmp\FiddlerSetup.exe | executable | |
MD5:— | SHA256:— | |||
| 3488 | FiddlerSetup.exe | C:\Users\admin\AppData\Local\Programs\Fiddler\Fiddler.exe | executable | |
MD5:— | SHA256:— | |||
| 3488 | FiddlerSetup.exe | C:\Users\admin\AppData\Local\Programs\Fiddler\Fiddler.exe.config | xml | |
MD5:— | SHA256:— | |||
| 3488 | FiddlerSetup.exe | C:\Users\admin\AppData\Local\Programs\Fiddler\Fiddler.pdb | binary | |
MD5:— | SHA256:— | |||
| 3488 | FiddlerSetup.exe | C:\Users\admin\AppData\Local\Programs\Fiddler\SetupHelper | executable | |
MD5:— | SHA256:— | |||
| 3488 | FiddlerSetup.exe | C:\Users\admin\AppData\Local\Programs\Fiddler\TrustCert.exe | executable | |
MD5:— | SHA256:— | |||
| 3488 | FiddlerSetup.exe | C:\Users\admin\AppData\Local\Programs\Fiddler\TrustCert.pdb | binary | |
MD5:— | SHA256:— | |||
| 3488 | FiddlerSetup.exe | C:\Users\admin\AppData\Local\Programs\Fiddler\Be.Windows.Forms.HexBox.dll | executable | |
MD5:— | SHA256:— | |||
| 3488 | FiddlerSetup.exe | C:\Users\admin\AppData\Local\Programs\Fiddler\Analytics.dll | executable | |
MD5:— | SHA256:— | |||
| 3488 | FiddlerSetup.exe | C:\Users\admin\AppData\Local\Programs\Fiddler\Analytics.pdb | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3352 | msedge.exe | GET | 301 | 50.56.19.112:80 | http://www.telerik.com/download/fiddler/first-run | unknown | — | — | unknown |
3352 | msedge.exe | GET | 301 | 50.56.19.116:80 | http://fiddler2.com/r/?Fiddler2FirstRun | unknown | — | — | unknown |
492 | Fiddler.exe | GET | 200 | 50.56.19.116:80 | http://fiddler2.com/content/GetArticles?clientId=44181964E5BBCFCF7A5045EC6623AA11B56D25E7722D30CF1680719BAAC2EB1E | unknown | — | — | unknown |
492 | Fiddler.exe | GET | 200 | 50.56.19.116:80 | http://fiddler2.com/content/GetBanner?clientId=44181964E5BBCFCF7A5045EC6623AA11B56D25E7722D30CF1680719BAAC2EB1E | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3352 | msedge.exe | 131.253.33.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
1784 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
3352 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3352 | msedge.exe | 50.56.19.116:80 | fiddler2.com | RACKSPACE | US | unknown |
3352 | msedge.exe | 50.56.19.112:80 | www.telerik.com | RACKSPACE | US | unknown |
3352 | msedge.exe | 50.56.19.112:443 | www.telerik.com | RACKSPACE | US | unknown |
Domain | IP | Reputation |
|---|---|---|
fiddler2.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
www.telerik.com |
| unknown |
dtzbdy9anri2p.cloudfront.net |
| whitelisted |
d6vtbcy3ong79.cloudfront.net |
| whitelisted |
cdnjs.cloudflare.com |
| whitelisted |
cdn.cookielaw.org |
| whitelisted |
cdn.insight.sitefinity.com |
| unknown |
d585tldpucybw.cloudfront.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3352 | msedge.exe | Misc activity | ET INFO Observed ZeroSSL SSL/TLS Certificate |
Process | Message |
|---|---|
Fiddler.exe | Object reference not set to an instance of an object.
|