This is a migrated thread and some comments may be shown as answers.

Fiddler refuses to decode when CRC mismatching?

2 Answers 83 Views
Fiddler Classic
This is a migrated thread and some comments may be shown as answers.
Chun
Top achievements
Rank 1
Chun asked on 19 Jan 2017, 04:52 AM

Hi:

I downloaded a few .pcap files from http://malware-traffic-analysis.net.

I noticed that Fiddler would complain about CRC mismatch when decoding some gzip streams, and hence it won't display the decoded stream.

I am not quite sure whether the CRC is really wrong, however, looks like IE would decode regardless (since I have no trouble to replay it).

I attached one here. Session 1, session 3 are complained by Fiddler. (I am using the latest version 4.6.3.50306)

Password "infected"

 

 

 

2 Answers, 1 is accepted

Sort by
0
Chun
Top achievements
Rank 1
answered on 19 Jan 2017, 04:57 AM

My attachment seems to be discarded somehow.

You can download it from 

http://malware-traffic-analysis.net/2017/01/18/2017-01-18-EK-campaigns-switch-back-to-Cerber-pcaps.zip

unzip it(password "infected"), and look at session 1, 3 from capture 

2017-01-18-pseudoDarkleech-Rig-V-sends-Cerber-ransomware.pcap  

 

0
Chun
Top achievements
Rank 1
answered on 19 Jan 2017, 04:58 AM

Attachment seems to be discarded:

It can be downloaded from link

hxxp://malware-traffic-analysis.net/2017/01/18/2017-01-18-EK-campaigns-switch-back-to-Cerber-pcaps.zip

unzip it  with password "infected"

2017-01-18-pseudoDarkleech-Rig-V-sends-Cerber-ransomware.pcap  

 

Tags
Fiddler Classic
Asked by
Chun
Top achievements
Rank 1
Answers by
Chun
Top achievements
Rank 1
Share this question
or