| File name: | FiddlerSetup.exe |
| Full analysis: | https://app.any.run/tasks/f3ea36ef-7b9a-4b90-93c6-5f32e15fe4b8 |
| Verdict: | Malicious activity |
| Analysis date: | November 02, 2023, 04:12:12 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 7FD1119B5F29E4094228DABF57E65A9D |
| SHA1: | 1A4E248BFE07F8C65CE68B4F29013442BE6EF7C7 |
| SHA256: | 5C92F0738C290EAC319D4AC3006B5725F1D2163FBFE68DBB2047E07920F4D5E8 |
| SSDEEP: | 196608:Q962sDwuahkk8ZaQd9NCMbw4fO0ADH6Op:Q5uAkk8ZBCuXfjADH6s |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:04:03 22:18:47+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 24064 |
| InitializedDataSize: | 118272 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x30d9 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.0.20211.51073 |
| ProductVersionNumber: | 5.0.20211.51073 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| Comments: | http://www.telerik.com/fiddler |
| CompanyName: | Progress Software Corporation |
| FileDescription: | Installer for Progress Telerik Fiddler Classic |
| FileVersion: | 5.0.20211.51073 |
| LegalCopyright: | Copyright ©2003 - 2021 Progress Software Corporation. All rights reserved. |
| ProductName: | Progress Telerik Fiddler Classic Setup |
| ProductVersion: | 5.0.20211.51073 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 396 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe" install "C:\Users\admin\AppData\Local\Programs\Fiddler\EnableLoopback.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe | — | FiddlerSetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Common Language Runtime native compiler Exit code: 4294967295 Version: 4.0.30319.34209 built by: FX452RTMGDR Modules
| |||||||||||||||
| 960 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=2424 --field-trial-handle=1372,i,8524054245843905276,7663138148674240708,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 976 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://fiddler2.com/r/?Fiddler2FirstRun | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | FiddlerSetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1464 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=16 --mojo-platform-channel-handle=3712 --field-trial-handle=1372,i,8524054245843905276,7663138148674240708,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1560 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1312 --field-trial-handle=1372,i,8524054245843905276,7663138148674240708,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1836 | "C:\Windows\system32\netsh.exe" advfirewall firewall add rule name="FiddlerProxy" program="C:\Users\admin\AppData\Local\Programs\Fiddler\Fiddler.exe" action=allow profile=any dir=in edge=deferuser protocol=tcp description="Permit inbound connections to Fiddler" | C:\Windows\System32\netsh.exe | — | FiddlerSetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -StartupEvent 180 -InterruptEvent 0 -NGENProcess 108 -Pipe 184 -Comment "NGen Worker Process" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe | — | ngen.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: .NET Runtime Optimization Service Exit code: 0 Version: 4.0.30319.34209 built by: FX452RTMGDR Modules
| |||||||||||||||
| 1928 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=2372 --field-trial-handle=1372,i,8524054245843905276,7663138148674240708,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2084 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4200 --field-trial-handle=1372,i,8524054245843905276,7663138148674240708,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2088 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=2424 --field-trial-handle=1372,i,8524054245843905276,7663138148674240708,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (3268) FiddlerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyHttp1.1 |
Value: 1 | |||
| (PID) Process: | (3268) FiddlerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | EnableHttp1_1 |
Value: 1 | |||
| (PID) Process: | (3268) FiddlerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3268) FiddlerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3268) FiddlerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3268) FiddlerSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2424) ngen.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGENService\Roots |
| Operation: | write | Name: | WorkPending |
Value: 0 | |||
| (PID) Process: | (1836) netsh.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1836) netsh.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\napipsec.dll,-1 |
Value: IPsec Relying Party | |||
| (PID) Process: | (3360) netsh.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3268 | FiddlerSetup.exe | C:\Users\admin\AppData\Local\Programs\Fiddler\Fiddler.pdb | binary | |
MD5:E9151C8E4FA69548C22B9809FE842520 | SHA256:CD57AA1D617AC27CA33DE362042B2FECA6B87265A7156CFC16CCF49211EADCC4 | |||
| 3268 | FiddlerSetup.exe | C:\Users\admin\AppData\Local\Programs\Fiddler\Fiddler.exe | executable | |
MD5:38DF8B767C52FB45371D86F20CEE8969 | SHA256:682604BA362EF71944442684EF6A3F17D99E551C6E6865C65DF99423C1CEBACB | |||
| 3268 | FiddlerSetup.exe | C:\Users\admin\AppData\Local\Programs\Fiddler\Fiddler.exe.config | xml | |
MD5:38A7379A4B36FC661C69A3E299373A05 | SHA256:70107440ED3E5CE934B947A85669A963ED0370D1D34C27E8F3BD2A8F5F670342 | |||
| 3268 | FiddlerSetup.exe | C:\Users\admin\AppData\Local\Programs\Fiddler\SetupHelper | executable | |
MD5:45A29924B29CD5881DA857104C5554FE | SHA256:B31D4C6A86BAD9EAFFAA543476261AAA95705FFFAAF367A6AB67133C6AF5FCFE | |||
| 3268 | FiddlerSetup.exe | C:\Users\admin\AppData\Local\Programs\Fiddler\TrustCert.exe | executable | |
MD5:D8834E9B32FBA784D96151481D9698F8 | SHA256:4130FA595C107211549C8BE551754822AAE811A2857CE39863E41EB5E3662BBF | |||
| 3268 | FiddlerSetup.exe | C:\Users\admin\AppData\Local\Programs\Fiddler\Be.Windows.Forms.HexBox.dll | executable | |
MD5:E6F7B8C5EC4D1543EAA7F5D148C6327C | SHA256:BBFD21490A4BE96E1A44A92E39406E87978AEA1FC58B603702E4E21A143DD89E | |||
| 3268 | FiddlerSetup.exe | C:\Users\admin\AppData\Local\Programs\Fiddler\Analytics.pdb | binary | |
MD5:F84FB6CD84B5D07E3DE4D78D38F388FF | SHA256:03CA5A20D36BBC0AEA28AA3184D65B322CECC3080D55A975CDF0F5D31199829D | |||
| 3268 | FiddlerSetup.exe | C:\Users\admin\AppData\Local\Programs\Fiddler\GA.Analytics.Monitor.dll | executable | |
MD5:6F9E5C4B5662C7F8D1159EDCBA6E7429 | SHA256:E3261A13953F4BEDEC65957B58074C71D2E1B9926529D48C77CFB1E70EC68790 | |||
| 2416 | FiddlerSetup.exe | C:\Users\admin\AppData\Local\Temp\nsb70BE.tmp\FiddlerSetup.exe | executable | |
MD5:612DA4BB7C48904D6D1473F053384A14 | SHA256:8DA8F52E9EEA560A935A0EF28B580B2FEB7DA5C23BE35D787BEC32584A6CFEB9 | |||
| 3268 | FiddlerSetup.exe | C:\Users\admin\AppData\Local\Programs\Fiddler\TrustCert.pdb | binary | |
MD5:76383C0B8ADBE7CFEFC47259217B854F | SHA256:B56AABBFE106338C664BA98AF3C3C94A8D51C3998ADF72E338004BFECFA7E286 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3652 | msedge.exe | GET | — | 50.56.19.116:80 | http://fiddler2.com/r/?Fiddler2FirstRun | unknown | — | — | unknown |
3652 | msedge.exe | GET | 301 | 50.56.19.112:80 | http://www.telerik.com/download/fiddler/first-run | unknown | — | — | unknown |
3652 | msedge.exe | GET | 301 | 50.56.19.116:80 | http://fiddler2.com/r/?Fiddler2FirstRun | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3652 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2460 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3652 | msedge.exe | 20.103.180.120:443 | nav-edge.smartscreen.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
3652 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3652 | msedge.exe | 50.56.19.116:80 | fiddler2.com | RACKSPACE | US | unknown |
3652 | msedge.exe | 51.104.176.40:443 | data-edge.smartscreen.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
Domain | IP | Reputation |
|---|---|---|
config.edge.skype.com |
| whitelisted |
nav-edge.smartscreen.microsoft.com |
| whitelisted |
fiddler2.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
data-edge.smartscreen.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com |
| whitelisted |
www.telerik.com |
| unknown |
dtzbdy9anri2p.cloudfront.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3652 | msedge.exe | Misc activity | ET INFO Observed ZeroSSL SSL/TLS Certificate |