| File name: | fiddler.exe |
| Full analysis: | https://app.any.run/tasks/233b2afc-5b91-4fe6-a471-3ff37e591e80 |
| Verdict: | Malicious activity |
| Threats: | NanoCore is a Remote Access Trojan or RAT. This malware is highly customizable with plugins which allow attackers to tailor its functionality to their needs. Nanocore is created with the .NET framework and it’s available for purchase for just $25 from its “official” website. |
| Analysis date: | August 25, 2024, 13:34:42 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| MD5: | 71776EEAC76AC1591144338385374C5D |
| SHA1: | 2273F36D078D132C44A16A1564E9D9FF01334D51 |
| SHA256: | 6D233149CF42F476907C45A4E63329D00AF0C78D9DAFE6F9CC5A38784206DB02 |
| SSDEEP: | 12288:5p+ThJ8q/0E+Lrs64xnYxjkUdB2PVVV1YBK:wb8q/0E+LA6YnYlk7UK |
| .dll | | | Win32 Dynamic Link Library (generic) (38.3) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (26.2) |
| .exe | | | Win16/32 Executable Delphi generic (12) |
| .exe | | | Generic Win/DOS Executable (11.6) |
| .exe | | | DOS Executable Generic (11.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:07:13 16:01:05+00:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 243712 |
| InitializedDataSize: | 23552 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x3d69e |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.0.20192.25091 |
| ProductVersionNumber: | 5.0.20192.25091 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| Comments: | http://www.telerik.com/fiddler |
| CompanyName: | Telerik |
| FileDescription: | Installer for Progress Telerik Fiddler Web Debugger |
| FileVersion: | 5.0.20192.25091 |
| LegalCopyright: | Copyright ©2003 - 2019 Telerik EAD. All rights reserved. |
| ProductName: | Progress Telerik Fiddler Setup |
| ProductVersion: | 5.0.20192.25091 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 5624 | "C:\Users\admin\AppData\Roaming\b1b2dqljdx3\a1punf5t2of.exe" | C:\Users\admin\AppData\Roaming\b1b2dqljdx3\a1punf5t2of.exe | fiddler.exe | ||||||||||||
User: admin Company: Telerik Integrity Level: HIGH Description: Installer for Progress Telerik Fiddler Web Debugger Exit code: 0 Version: 5.0.20192.25091 Modules
| |||||||||||||||
| 6488 | "C:\Users\admin\AppData\Roaming\b1b2dqljdx3\a1punf5t2of.exe" | C:\Users\admin\AppData\Roaming\b1b2dqljdx3\a1punf5t2of.exe | a1punf5t2of.exe | ||||||||||||
User: admin Company: Telerik Integrity Level: HIGH Description: Installer for Progress Telerik Fiddler Web Debugger Version: 5.0.20192.25091 | |||||||||||||||
| 6652 | "C:\Users\admin\Desktop\fiddler.exe" | C:\Users\admin\Desktop\fiddler.exe | — | explorer.exe | |||||||||||
User: admin Company: Telerik Integrity Level: MEDIUM Description: Installer for Progress Telerik Fiddler Web Debugger Exit code: 3221226540 Version: 5.0.20192.25091 Modules
| |||||||||||||||
| 6700 | "C:\Users\admin\Desktop\fiddler.exe" | C:\Users\admin\Desktop\fiddler.exe | explorer.exe | ||||||||||||
User: admin Company: Telerik Integrity Level: HIGH Description: Installer for Progress Telerik Fiddler Web Debugger Exit code: 0 Version: 5.0.20192.25091 Modules
| |||||||||||||||
| (PID) Process: | (6700) fiddler.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | b1b2dqljdx3 |
Value: C:\Users\admin\AppData\Roaming\b1b2dqljdx3\a1punf5t2of.exe | |||
| (PID) Process: | (6700) fiddler.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (6700) fiddler.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (6700) fiddler.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (6700) fiddler.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6700 | fiddler.exe | C:\Users\admin\AppData\Roaming\b1b2dqljdx3\a1punf5t2of.exe | binary | |
MD5:2774A179C941459EB399558F6C48803E | SHA256:1B34F0F8EC5228FB7AA3B7BFB7BAC3684E50E9FF01183FC70C2E86658557BFDF | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6356 | SIHClient.exe | GET | 200 | 23.52.120.96:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6356 | SIHClient.exe | GET | 200 | 23.52.120.96:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
3276 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3304 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
568 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
2120 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3304 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2120 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3260 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6356 | SIHClient.exe | 40.127.169.103:443 | slscr.update.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
6356 | SIHClient.exe | 23.52.120.96:80 | www.microsoft.com | AKAMAI-AS | DE | unknown |
6356 | SIHClient.exe | 52.165.164.15:443 | fe3cr.delivery.mp.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
nexusrules.officeapps.live.com |
| whitelisted |