download:

/fiddler-classic/FiddlerSetup.5.0.20242.10753-latest.exe

Full analysis: https://app.any.run/tasks/4b6f0c01-3f04-48f4-9543-c382476a79d3
Verdict: Malicious activity
Analysis date: April 08, 2024, 07:45:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

78537045A5E032D4AC93514F027C7A47

SHA1:

5B6E705B20652C0CF39EE890013B9B8E8AD26B07

SHA256:

06812518A722AF6F98FBD8C3A5ACE0CAD1C6D53477972618728E64BAFCBC948C

SSDEEP:

98304:3UcCiT73zI3qt/zDuMslI4vT8LPWtl65FOGVHCi5W8DiGfB8l5JZhmkxFpUgwPXN:Y7mjc7++svyh5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • FiddlerSetup.5.0.20242.10753-latest.exe (PID: 2896)
      • FiddlerSetup.exe (PID: 3488)
      • mscorsvw.exe (PID: 3332)
      • mscorsvw.exe (PID: 1216)
      • mscorsvw.exe (PID: 3588)
      • mscorsvw.exe (PID: 920)
      • mscorsvw.exe (PID: 2956)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • FiddlerSetup.5.0.20242.10753-latest.exe (PID: 2896)
      • FiddlerSetup.exe (PID: 3488)
      • mscorsvw.exe (PID: 3332)
      • mscorsvw.exe (PID: 1216)
      • mscorsvw.exe (PID: 920)
      • mscorsvw.exe (PID: 2956)
      • mscorsvw.exe (PID: 3588)
    • Process drops legitimate windows executable

      • FiddlerSetup.exe (PID: 3488)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • FiddlerSetup.exe (PID: 3488)
    • Creates a software uninstall entry

      • FiddlerSetup.exe (PID: 3488)
    • The process creates files with name similar to system file names

      • FiddlerSetup.exe (PID: 3488)
    • Changes Internet Explorer settings (feature browser emulation)

      • FiddlerSetup.exe (PID: 3488)
    • Reads the Internet Settings

      • FiddlerSetup.exe (PID: 3488)
      • Fiddler.exe (PID: 492)
    • Reads security settings of Internet Explorer

      • FiddlerSetup.exe (PID: 3488)
      • Fiddler.exe (PID: 492)
    • Starts application with an unusual extension

      • FiddlerSetup.exe (PID: 3488)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • FiddlerSetup.exe (PID: 3488)
    • Uses NETSH.EXE to delete a firewall rule or allowed programs

      • FiddlerSetup.exe (PID: 3488)
    • Reads settings of System Certificates

      • Fiddler.exe (PID: 492)
    • Reads Internet Explorer settings

      • Fiddler.exe (PID: 492)
    • Reads Microsoft Outlook installation path

      • Fiddler.exe (PID: 492)
  • INFO

    • Checks supported languages

      • FiddlerSetup.5.0.20242.10753-latest.exe (PID: 2896)
      • FiddlerSetup.exe (PID: 3488)
      • SetupHelper (PID: 2148)
      • ngen.exe (PID: 3684)
      • ngen.exe (PID: 1976)
      • mscorsvw.exe (PID: 1644)
      • mscorsvw.exe (PID: 2956)
      • mscorsvw.exe (PID: 920)
      • mscorsvw.exe (PID: 2068)
      • mscorsvw.exe (PID: 1216)
      • mscorsvw.exe (PID: 3588)
      • mscorsvw.exe (PID: 2328)
      • mscorsvw.exe (PID: 3332)
      • mscorsvw.exe (PID: 3508)
      • mscorsvw.exe (PID: 1308)
      • mscorsvw.exe (PID: 3164)
      • mscorsvw.exe (PID: 1792)
      • mscorsvw.exe (PID: 2440)
      • Fiddler.exe (PID: 492)
    • Reads the computer name

      • FiddlerSetup.5.0.20242.10753-latest.exe (PID: 2896)
      • FiddlerSetup.exe (PID: 3488)
      • SetupHelper (PID: 2148)
      • ngen.exe (PID: 3684)
      • mscorsvw.exe (PID: 1644)
      • mscorsvw.exe (PID: 1216)
      • mscorsvw.exe (PID: 2956)
      • mscorsvw.exe (PID: 920)
      • mscorsvw.exe (PID: 2068)
      • mscorsvw.exe (PID: 3588)
      • mscorsvw.exe (PID: 2328)
      • mscorsvw.exe (PID: 3332)
      • mscorsvw.exe (PID: 1308)
      • mscorsvw.exe (PID: 2440)
      • mscorsvw.exe (PID: 3164)
      • mscorsvw.exe (PID: 1792)
      • mscorsvw.exe (PID: 3508)
      • Fiddler.exe (PID: 492)
    • Create files in a temporary directory

      • FiddlerSetup.5.0.20242.10753-latest.exe (PID: 2896)
      • FiddlerSetup.exe (PID: 3488)
      • Fiddler.exe (PID: 492)
    • Creates files or folders in the user directory

      • FiddlerSetup.exe (PID: 3488)
      • Fiddler.exe (PID: 492)
    • Reads the machine GUID from the registry

      • mscorsvw.exe (PID: 1644)
      • ngen.exe (PID: 3684)
      • mscorsvw.exe (PID: 2068)
      • mscorsvw.exe (PID: 920)
      • mscorsvw.exe (PID: 2956)
      • mscorsvw.exe (PID: 1216)
      • mscorsvw.exe (PID: 3588)
      • mscorsvw.exe (PID: 2328)
      • mscorsvw.exe (PID: 3332)
      • mscorsvw.exe (PID: 1308)
      • mscorsvw.exe (PID: 2440)
      • mscorsvw.exe (PID: 3164)
      • mscorsvw.exe (PID: 1792)
      • mscorsvw.exe (PID: 3508)
      • Fiddler.exe (PID: 492)
    • Application launched itself

      • msedge.exe (PID: 2260)
      • msedge.exe (PID: 1784)
    • Manual execution by a user

      • msedge.exe (PID: 1784)
      • Fiddler.exe (PID: 492)
    • Reads Microsoft Office registry keys

      • Fiddler.exe (PID: 492)
    • Reads the software policy settings

      • Fiddler.exe (PID: 492)
    • Reads Environment values

      • Fiddler.exe (PID: 492)
    • Checks proxy server information

      • Fiddler.exe (PID: 492)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:07:02 02:09:39+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26112
InitializedDataSize: 139776
UninitializedDataSize: 2048
EntryPoint: 0x34fc
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 5.0.20242.10753
ProductVersionNumber: 5.0.20242.10753
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: http://www.telerik.com/fiddler
CompanyName: Progress Software Corporation
FileDescription: Installer for Progress Telerik Fiddler Classic
FileVersion: 5.0.20242.10753
LegalCopyright: Copyright ©2003 - 2024 Progress Software Corporation. All rights reserved.
ProductName: Progress Telerik Fiddler Classic Setup
ProductVersion: 5.0.20242.10753
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
89
Monitored processes
44
Malicious processes
4
Suspicious processes
5

Behavior graph

Click at the process to see the details
start fiddlersetup.5.0.20242.10753-latest.exe fiddlersetup.exe netsh.exe no specs netsh.exe no specs ngen.exe no specs ngen.exe no specs setuphelper no specs mscorsvw.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs mscorsvw.exe mscorsvw.exe mscorsvw.exe no specs mscorsvw.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs mscorsvw.exe mscorsvw.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs mscorsvw.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs fiddler.exe msedge.exe no specs msedge.exe no specs fiddlersetup.5.0.20242.10753-latest.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
492"C:\Users\admin\AppData\Local\Programs\Fiddler\Fiddler.exe" C:\Users\admin\AppData\Local\Programs\Fiddler\Fiddler.exe
explorer.exe
User:
admin
Company:
Progress Software Corporation
Integrity Level:
MEDIUM
Description:
Fiddler
Version:
5.0.20242.10753
Modules
Images
c:\users\admin\appdata\local\programs\fiddler\fiddler.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
920C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 1a4 -InterruptEvent 0 -NGENProcess 198 -Pipe 1a0 -Comment "NGen Worker Process"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
ngen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
.NET Runtime Optimization Service
Exit code:
0
Version:
4.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\vcruntime140_clr0400.dll
c:\windows\system32\ucrtbase_clr0400.dll
1124"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1260 --field-trial-handle=1100,i,15978449684013051289,11500370336417600787,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1216C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 194 -InterruptEvent 0 -NGENProcess 188 -Pipe 190 -Comment "NGen Worker Process"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
ngen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
.NET Runtime Optimization Service
Exit code:
0
Version:
4.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\vcruntime140_clr0400.dll
c:\windows\system32\ucrtbase_clr0400.dll
1308C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 214 -InterruptEvent 0 -NGENProcess 1b4 -Pipe 1c8 -Comment "NGen Worker Process"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exengen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
.NET Runtime Optimization Service
Exit code:
0
Version:
4.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\vcruntime140_clr0400.dll
c:\windows\system32\ucrtbase_clr0400.dll
1316"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3444 --field-trial-handle=1100,i,15978449684013051289,11500370336417600787,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1644C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 108 -InterruptEvent 0 -NGENProcess f8 -Pipe 104 -Comment "NGen Worker Process"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exengen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
.NET Runtime Optimization Service
Exit code:
0
Version:
4.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\vcruntime140_clr0400.dll
c:\windows\system32\ucrtbase_clr0400.dll
1784"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate http://fiddler2.com/r/?Fiddler2FirstRunC:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1792C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 20c -InterruptEvent 0 -NGENProcess 1fc -Pipe 18c -Comment "NGen Worker Process"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exengen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
.NET Runtime Optimization Service
Exit code:
0
Version:
4.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\vcruntime140_clr0400.dll
c:\windows\system32\ucrtbase_clr0400.dll
1976"C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe" install "C:\Users\admin\AppData\Local\Programs\Fiddler\EnableLoopback.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exeFiddlerSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
4294967295
Version:
4.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\ngen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\vcruntime140_clr0400.dll
c:\windows\system32\ucrtbase_clr0400.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
Total events
30 571
Read events
30 291
Write events
266
Delete events
14

Modification events

(PID) Process:(3488) FiddlerSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Fiddler2\InstallerSettings
Operation:writeName:InstallPath
Value:
C:\Users\admin\AppData\Local\Programs\Fiddler\
(PID) Process:(3488) FiddlerSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Fiddler2\InstallerSettings
Operation:writeName:PluginPath
Value:
"C:\Users\admin\AppData\Local\Programs\Fiddler\Inspectors\"
(PID) Process:(3488) FiddlerSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Fiddler2\InstallerSettings
Operation:writeName:ScriptPath
Value:
"C:\Users\admin\AppData\Local\Programs\Fiddler\Scripts\"
(PID) Process:(3488) FiddlerSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Fiddler2\InstallerSettings
Operation:writeName:InstalledVersion
Value:
5.0.20242.10753
(PID) Process:(3488) FiddlerSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
Operation:writeName:Fiddler.exe
Value:
0
(PID) Process:(3488) FiddlerSetup.exeKey:HKEY_CLASSES_ROOT\Fiddler.ArchiveZip
Operation:writeName:PerceivedType
Value:
compressed
(PID) Process:(3488) FiddlerSetup.exeKey:HKEY_CLASSES_ROOT\Fiddler.ArchiveZip
Operation:writeName:Content Type
Value:
application/vnd.telerik-fiddler.SessionArchive
(PID) Process:(3488) FiddlerSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Fiddler2
Operation:writeName:UpdatePending
Value:
False
(PID) Process:(3488) FiddlerSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Fiddler2\UI
Operation:writeName:frmViewer_WState
Value:
2
(PID) Process:(3488) FiddlerSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Fiddler2
Operation:writeName:JSEditor
Value:
C:\Users\admin\AppData\Local\Programs\Fiddler\ScriptEditor\FSE2.exe
Executable files
59
Suspicious files
75
Text files
75
Unknown types
27

Dropped files

PID
Process
Filename
Type
2896FiddlerSetup.5.0.20242.10753-latest.exeC:\Users\admin\AppData\Local\Temp\nsp2576.tmp\FiddlerSetup.exeexecutable
MD5:
SHA256:
3488FiddlerSetup.exeC:\Users\admin\AppData\Local\Programs\Fiddler\Fiddler.exeexecutable
MD5:
SHA256:
3488FiddlerSetup.exeC:\Users\admin\AppData\Local\Programs\Fiddler\Fiddler.exe.configxml
MD5:
SHA256:
3488FiddlerSetup.exeC:\Users\admin\AppData\Local\Programs\Fiddler\Fiddler.pdbbinary
MD5:
SHA256:
3488FiddlerSetup.exeC:\Users\admin\AppData\Local\Programs\Fiddler\SetupHelperexecutable
MD5:
SHA256:
3488FiddlerSetup.exeC:\Users\admin\AppData\Local\Programs\Fiddler\TrustCert.exeexecutable
MD5:
SHA256:
3488FiddlerSetup.exeC:\Users\admin\AppData\Local\Programs\Fiddler\TrustCert.pdbbinary
MD5:
SHA256:
3488FiddlerSetup.exeC:\Users\admin\AppData\Local\Programs\Fiddler\Be.Windows.Forms.HexBox.dllexecutable
MD5:
SHA256:
3488FiddlerSetup.exeC:\Users\admin\AppData\Local\Programs\Fiddler\Analytics.dllexecutable
MD5:
SHA256:
3488FiddlerSetup.exeC:\Users\admin\AppData\Local\Programs\Fiddler\Analytics.pdbbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
61
DNS requests
62
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3352
msedge.exe
GET
301
50.56.19.112:80
http://www.telerik.com/download/fiddler/first-run
unknown
unknown
3352
msedge.exe
GET
301
50.56.19.116:80
http://fiddler2.com/r/?Fiddler2FirstRun
unknown
unknown
492
Fiddler.exe
GET
200
50.56.19.116:80
http://fiddler2.com/content/GetArticles?clientId=44181964E5BBCFCF7A5045EC6623AA11B56D25E7722D30CF1680719BAAC2EB1E
unknown
unknown
492
Fiddler.exe
GET
200
50.56.19.116:80
http://fiddler2.com/content/GetBanner?clientId=44181964E5BBCFCF7A5045EC6623AA11B56D25E7722D30CF1680719BAAC2EB1E
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3352
msedge.exe
131.253.33.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
1784
msedge.exe
239.255.255.250:1900
unknown
3352
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3352
msedge.exe
50.56.19.116:80
fiddler2.com
RACKSPACE
US
unknown
3352
msedge.exe
50.56.19.112:80
www.telerik.com
RACKSPACE
US
unknown
3352
msedge.exe
50.56.19.112:443
www.telerik.com
RACKSPACE
US
unknown

DNS requests

Domain
IP
Reputation
fiddler2.com
  • 50.56.19.116
whitelisted
edge.microsoft.com
  • 131.253.33.239
  • 13.107.22.239
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.telerik.com
  • 50.56.19.112
unknown
dtzbdy9anri2p.cloudfront.net
  • 3.160.156.198
  • 3.160.156.184
  • 3.160.156.22
  • 3.160.156.47
whitelisted
d6vtbcy3ong79.cloudfront.net
  • 13.225.84.205
  • 13.225.84.94
  • 13.225.84.34
  • 13.225.84.196
whitelisted
cdnjs.cloudflare.com
  • 104.17.25.14
  • 104.17.24.14
whitelisted
cdn.cookielaw.org
  • 104.19.178.52
  • 104.19.177.52
whitelisted
cdn.insight.sitefinity.com
  • 152.199.21.175
unknown
d585tldpucybw.cloudfront.net
  • 18.66.107.78
  • 18.66.107.115
  • 18.66.107.176
  • 18.66.107.59
whitelisted

Threats

PID
Process
Class
Message
3352
msedge.exe
Misc activity
ET INFO Observed ZeroSSL SSL/TLS Certificate
Process
Message
Fiddler.exe
Object reference not set to an instance of an object.