File name:

FiddlerSetup.5.0.20245.10105-latest.exe

Full analysis: https://app.any.run/tasks/c10a3cf6-f2b3-4257-a272-75edc0288bf3
Verdict: Malicious activity
Analysis date: November 08, 2024, 19:48:59
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

C1980B018489DF28BE8809EB32519001

SHA1:

E860439703D7B6665AF4507B20BBEF2BBB7B73F4

SHA256:

588024037B1E5929B1F2A741FFF52A207BCAB17F0650EC7CB0CD3CB78051998D

SSDEEP:

98304:XWH7Ul7d3LAXiwKUMflextp+k6+IA2oSfIVhlnjxRo0Qzp4f42W7/MjenFuihE55:tQO9ALRx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts application with an unusual extension

      • FiddlerSetup.exe (PID: 5372)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • FiddlerSetup.exe (PID: 5372)
    • Reads security settings of Internet Explorer

      • FiddlerSetup.exe (PID: 5372)
    • Process drops legitimate windows executable

      • FiddlerSetup.exe (PID: 5372)
      • mscorsvw.exe (PID: 6956)
      • mscorsvw.exe (PID: 2484)
      • mscorsvw.exe (PID: 6888)
      • mscorsvw.exe (PID: 4340)
      • mscorsvw.exe (PID: 2888)
      • mscorsvw.exe (PID: 7472)
      • mscorsvw.exe (PID: 7480)
      • mscorsvw.exe (PID: 7464)
      • mscorsvw.exe (PID: 8052)
      • mscorsvw.exe (PID: 8008)
      • mscorsvw.exe (PID: 8152)
      • mscorsvw.exe (PID: 8468)
      • mscorsvw.exe (PID: 7480)
      • mscorsvw.exe (PID: 7936)
      • mscorsvw.exe (PID: 9120)
      • mscorsvw.exe (PID: 8880)
      • mscorsvw.exe (PID: 8900)
      • mscorsvw.exe (PID: 7952)
    • The process creates files with name similar to system file names

      • FiddlerSetup.exe (PID: 5372)
    • Uses NETSH.EXE to delete a firewall rule or allowed programs

      • FiddlerSetup.exe (PID: 5372)
    • Executable content was dropped or overwritten

      • FiddlerSetup.5.0.20245.10105-latest.exe (PID: 6664)
      • mscorsvw.exe (PID: 6956)
      • mscorsvw.exe (PID: 6888)
      • mscorsvw.exe (PID: 4340)
      • mscorsvw.exe (PID: 2888)
      • mscorsvw.exe (PID: 2484)
      • mscorsvw.exe (PID: 6168)
      • FiddlerSetup.exe (PID: 5372)
      • mscorsvw.exe (PID: 7952)
      • mscorsvw.exe (PID: 7472)
      • mscorsvw.exe (PID: 8900)
      • mscorsvw.exe (PID: 8008)
      • mscorsvw.exe (PID: 7480)
      • mscorsvw.exe (PID: 7464)
      • mscorsvw.exe (PID: 8152)
      • mscorsvw.exe (PID: 8468)
      • mscorsvw.exe (PID: 8052)
      • mscorsvw.exe (PID: 9120)
      • mscorsvw.exe (PID: 8880)
      • mscorsvw.exe (PID: 7480)
      • mscorsvw.exe (PID: 7936)
    • Creates a software uninstall entry

      • FiddlerSetup.exe (PID: 5372)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • FiddlerSetup.exe (PID: 5372)
  • INFO

    • Checks supported languages

      • SetupHelper (PID: 6668)
      • FiddlerSetup.5.0.20245.10105-latest.exe (PID: 6664)
      • FiddlerSetup.exe (PID: 5372)
      • mscorsvw.exe (PID: 6956)
      • ngen.exe (PID: 6612)
      • mscorsvw.exe (PID: 6168)
      • mscorsvw.exe (PID: 5644)
      • ngen.exe (PID: 6684)
      • mscorsvw.exe (PID: 2484)
      • mscorsvw.exe (PID: 4340)
      • mscorsvw.exe (PID: 6888)
    • Reads the computer name

      • ngen.exe (PID: 6612)
      • FiddlerSetup.exe (PID: 5372)
      • SetupHelper (PID: 6668)
      • mscorsvw.exe (PID: 6168)
      • mscorsvw.exe (PID: 6956)
      • mscorsvw.exe (PID: 6888)
      • mscorsvw.exe (PID: 2484)
      • ngen.exe (PID: 6684)
      • mscorsvw.exe (PID: 4340)
      • mscorsvw.exe (PID: 5644)
    • Create files in a temporary directory

      • FiddlerSetup.exe (PID: 5372)
      • FiddlerSetup.5.0.20245.10105-latest.exe (PID: 6664)
    • Process checks computer location settings

      • FiddlerSetup.exe (PID: 5372)
    • Creates files or folders in the user directory

      • FiddlerSetup.exe (PID: 5372)
    • The process uses the downloaded file

      • FiddlerSetup.exe (PID: 5372)
    • Reads the machine GUID from the registry

      • mscorsvw.exe (PID: 2484)
      • mscorsvw.exe (PID: 6956)
      • mscorsvw.exe (PID: 6888)
    • Application launched itself

      • msedge.exe (PID: 824)
      • msedge.exe (PID: 2736)
      • msedge.exe (PID: 8204)
      • msedge.exe (PID: 3932)
    • Manual execution by a user

      • msedge.exe (PID: 2736)
      • Fiddler.exe (PID: 1084)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:30 16:55:15+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26112
InitializedDataSize: 139776
UninitializedDataSize: 2048
EntryPoint: 0x351c
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 5.0.20245.10105
ProductVersionNumber: 5.0.20245.10105
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: http://www.telerik.com/fiddler
CompanyName: Progress Software Corporation
FileDescription: Installer for Progress Telerik Fiddler Classic
FileVersion: 5.0.20245.10105
LegalCopyright: Copyright ©2003 - 2024 Progress Software Corporation. All rights reserved.
ProductName: Progress Telerik Fiddler Classic Setup
ProductVersion: 5.0.20245.10105
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
263
Monitored processes
120
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start fiddlersetup.5.0.20245.10105-latest.exe fiddlersetup.exe netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs ngen.exe no specs conhost.exe no specs ngen.exe no specs setuphelper no specs conhost.exe no specs conhost.exe no specs mscorsvw.exe no specs mscorsvw.exe mscorsvw.exe mscorsvw.exe mscorsvw.exe mscorsvw.exe mscorsvw.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs mscorsvw.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs mscorsvw.exe no specs mscorsvw.exe mscorsvw.exe mscorsvw.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs mscorsvw.exe mscorsvw.exe msedge.exe no specs mscorsvw.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs mscorsvw.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs mscorsvw.exe no specs mscorsvw.exe mscorsvw.exe mscorsvw.exe mscorsvw.exe mscorsvw.exe mscorsvw.exe mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs mscorsvw.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs sppextcomobj.exe no specs slui.exe no specs fiddler.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs fiddlersetup.5.0.20245.10105-latest.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
512C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe -StartupEvent 27c -InterruptEvent 0 -NGENProcess 298 -Pipe 2d4 -Comment "NGen Worker Process"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exengen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
.NET Runtime Optimization Service
Exit code:
0
Version:
4.8.9093.0 built by: NET481REL1LAST_C
Modules
Images
c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
624"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --renderer-sub-type=extension --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3684 --field-trial-handle=2340,i,968522068895347795,11647037299634893735,262144 --variations-seed-version /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
824"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument http://fiddler2.com/r/?Fiddler2FirstRunC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeFiddlerSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
1
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
948\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenetsh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1008"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2312 --field-trial-handle=2152,i,7426578866429814812,12824125115641054613,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1068\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSetupHelper
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1084"C:\Users\admin\AppData\Local\Programs\Fiddler\Fiddler.exe" C:\Users\admin\AppData\Local\Programs\Fiddler\Fiddler.exeexplorer.exe
User:
admin
Company:
Progress Software Corporation
Integrity Level:
MEDIUM
Description:
Fiddler
Version:
5.0.20245.10105
1440"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5124 --field-trial-handle=2340,i,968522068895347795,11647037299634893735,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1700"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2500 --field-trial-handle=2400,i,8109827364558555164,3400505470676432687,262144 --variations-seed-version /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2312"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --no-appcompat-clear --mojo-platform-channel-handle=6816 --field-trial-handle=2400,i,8109827364558555164,3400505470676432687,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
17 231
Read events
17 116
Write events
113
Delete events
2

Modification events

(PID) Process:(5372) FiddlerSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fiddler2\InstallerSettings
Operation:writeName:InstallPath
Value:
C:\Users\admin\AppData\Local\Programs\Fiddler\
(PID) Process:(5372) FiddlerSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fiddler2\InstallerSettings
Operation:writeName:PluginPath
Value:
"C:\Users\admin\AppData\Local\Programs\Fiddler\Inspectors\"
(PID) Process:(5372) FiddlerSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fiddler2\InstallerSettings
Operation:writeName:ScriptPath
Value:
"C:\Users\admin\AppData\Local\Programs\Fiddler\Scripts\"
(PID) Process:(5372) FiddlerSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fiddler2\InstallerSettings
Operation:writeName:InstalledVersion
Value:
5.0.20245.10105
(PID) Process:(5372) FiddlerSetup.exeKey:HKEY_CLASSES_ROOT\Fiddler.ArchiveZip
Operation:writeName:PerceivedType
Value:
compressed
(PID) Process:(5372) FiddlerSetup.exeKey:HKEY_CLASSES_ROOT\Fiddler.ArchiveZip
Operation:writeName:Content Type
Value:
application/vnd.telerik-fiddler.SessionArchive
(PID) Process:(5372) FiddlerSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fiddler2
Operation:writeName:UpdatePending
Value:
False
(PID) Process:(5372) FiddlerSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fiddler2\UI
Operation:writeName:frmViewer_WState
Value:
2
(PID) Process:(5372) FiddlerSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fiddler2
Operation:writeName:JSEditor
Value:
C:\Users\admin\AppData\Local\Programs\Fiddler\ScriptEditor\FSE2.exe
(PID) Process:(5372) FiddlerSetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Fiddler2\MenuExt\&Sandbox
Operation:writeName:Command
Value:
iexplore.exe
Executable files
90
Suspicious files
391
Text files
137
Unknown types
11

Dropped files

PID
Process
Filename
Type
6664FiddlerSetup.5.0.20245.10105-latest.exeC:\Users\admin\AppData\Local\Temp\nsoC3C7.tmp\FiddlerSetup.exeexecutable
MD5:C2A0EB6F104EACEC3F39581451EE208F
SHA256:1F926CC353301E547E76C6D2EFF23FCBE85495BA0292174CC6344FAC26457AF8
5372FiddlerSetup.exeC:\Users\admin\AppData\Local\Programs\Fiddler\Fiddler.exe.configxml
MD5:C2EDC7B631ABCE6DB98B978995561E57
SHA256:E59AFC2818AD61C1338197A112C936A811C5341614F4AD9AD33D35C8356C0B14
5372FiddlerSetup.exeC:\Users\admin\AppData\Local\Programs\Fiddler\Analytics.dllexecutable
MD5:1C2BD080B0E972A3EE1579895EA17B42
SHA256:166E1A6CF86B254525A03D1510FE76DA574F977C012064DF39DD6F4AF72A4B29
5372FiddlerSetup.exeC:\Users\admin\AppData\Local\Programs\Fiddler\Fiddler.exeexecutable
MD5:87BC17F56E744E74408E6AE8BB28B724
SHA256:FFB24FC36ADE87988F9908E848D0333CE7FFB2B4E4D0FFB43F6556246069D057
5372FiddlerSetup.exeC:\Users\admin\AppData\Local\Programs\Fiddler\GA.Analytics.Monitor.pdbpdb
MD5:DF9591879A5AF2A8458FB9148E197313
SHA256:6C19EC08FFB13998ACE51E1B531128AF12CD47CCADFF5E346176C6992C00A843
5372FiddlerSetup.exeC:\Users\admin\AppData\Local\Programs\Fiddler\Newtonsoft.Json.dllexecutable
MD5:195FFB7167DB3219B217C4FD439EEDD6
SHA256:E1E27AF7B07EEEDF5CE71A9255F0422816A6FC5849A483C6714E1B472044FA9D
5372FiddlerSetup.exeC:\Users\admin\AppData\Local\Programs\Fiddler\Be.Windows.Forms.HexBox.dllexecutable
MD5:E6F7B8C5EC4D1543EAA7F5D148C6327C
SHA256:BBFD21490A4BE96E1A44A92E39406E87978AEA1FC58B603702E4E21A143DD89E
5372FiddlerSetup.exeC:\Users\admin\AppData\Local\Programs\Fiddler\SetupHelperexecutable
MD5:B1827FCA38A5D49FB706A4A7EEE4A778
SHA256:77523D1504AB2C0A4CDE6FCC2C8223CA1172841E2FD9D59D18E5FC132E808AE2
5372FiddlerSetup.exeC:\Users\admin\AppData\Local\Programs\Fiddler\Fiddler.pdbpdb
MD5:5C43B7F1CFF2F8F74D0C75721DD34797
SHA256:9C50823F84CE09AF60ED760C95CE73DA559505DBF411EF7797F4CE65FC0BF1BB
5372FiddlerSetup.exeC:\Users\admin\AppData\Local\Programs\Fiddler\Analytics.pdbbinary
MD5:F84FB6CD84B5D07E3DE4D78D38F388FF
SHA256:03CA5A20D36BBC0AEA28AA3184D65B322CECC3080D55A975CDF0F5D31199829D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
138
DNS requests
170
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6944
svchost.exe
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1552
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8956
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
6944
svchost.exe
GET
200
23.32.185.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
8956
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
8068
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5488
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:138
whitelisted
6944
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6944
svchost.exe
2.16.241.12:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6944
svchost.exe
23.32.185.131:80
www.microsoft.com
AKAMAI-AS
BR
whitelisted
1700
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2736
msedge.exe
239.255.255.250:1900
whitelisted
1700
msedge.exe
50.56.19.116:80
fiddler2.com
RACKSPACE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.119.249.228
  • 4.231.128.59
  • 40.127.240.158
whitelisted
google.com
  • 142.250.185.206
whitelisted
crl.microsoft.com
  • 2.16.241.12
  • 2.16.241.19
whitelisted
www.microsoft.com
  • 23.32.185.131
  • 184.30.21.171
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
fiddler2.com
  • 50.56.19.116
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
business.bing.com
  • 13.107.6.158
whitelisted
edge-mobile-static.azureedge.net
  • 13.107.246.45
whitelisted
bzib.nelreports.net
  • 104.124.11.19
  • 104.124.11.32
whitelisted

Threats

PID
Process
Class
Message
1700
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
1700
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
1700
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Global content delivery network (unpkg .com)
1700
msedge.exe
Misc activity
ET INFO Observed ZeroSSL SSL/TLS Certificate
No debug info