URL:

http://crystalfiles.ru

Full analysis: https://app.any.run/tasks/7b5f63d7-8b91-4076-9645-869cb3247594
Verdict: No threats detected
Analysis date: July 21, 2020, 12:50:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
Indicators:
MD5:

B803EE5A01C3EE59AA77637EE2DAE30B

SHA1:

C337EDEC582761A5C6C2EC8B12B5C643D5FE5210

SHA256:

742F16CB6375302DF9ACB9EB3B025A2CBC934BCF935AF7D1BE183E0710C735A9

SSDEEP:

3:N1KdX4Myn:CWMy

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • CrystalUS.exe (PID: 3068)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Creates files in the user directory

      • opera.exe (PID: 2152)
    • Manual execution by user

      • CrystalUS.exe (PID: 3068)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start opera.exe winrar.exe no specs crystalus.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2152"C:\Program Files\Opera\opera.exe" "http://crystalfiles.ru"C:\Program Files\Opera\opera.exe
explorer.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Internet Browser
Exit code:
0
Version:
1748
Modules
Images
c:\program files\opera\opera.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
2204"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Opera\Opera\temporary_downloads\f7b04a35029e69b590010db12c2a5e46.zip"C:\Program Files\WinRAR\WinRAR.exeopera.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3068"C:\Users\admin\Desktop\CrystalUS.exe" C:\Users\admin\Desktop\CrystalUS.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
CrystalUniversalSorter
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\crystalus.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 085
Read events
946
Write events
139
Delete events
0

Modification events

(PID) Process:(2152) opera.exeKey:HKEY_CURRENT_USER\Software\Opera Software
Operation:writeName:Last CommandLine v2
Value:
C:\Program Files\Opera\opera.exe "http://crystalfiles.ru"
(PID) Process:(2152) opera.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2152) opera.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2152) opera.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2204) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2204) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2204) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2204) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Opera\Opera\temporary_downloads\f7b04a35029e69b590010db12c2a5e46.zip
(PID) Process:(2204) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2204) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
Executable files
0
Suspicious files
31
Text files
25
Unknown types
6

Dropped files

PID
Process
Filename
Type
2152opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\sessions\oprB6A.tmp
MD5:
SHA256:
2152opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\oprB7B.tmp
MD5:
SHA256:
2152opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\oprBCA.tmp
MD5:
SHA256:
2152opera.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\MJSYFMNO34QJPJL7X3NJ.temp
MD5:
SHA256:
2152opera.exeC:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00002.tmp
MD5:
SHA256:
2152opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\sessions\opr446F.tmp
MD5:
SHA256:
2152opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\sessions\opr5038.tmp
MD5:
SHA256:
2152opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.datbinary
MD5:
SHA256:
2152opera.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\16ec093b8f51508f.customDestinations-ms~RF241722.TMPbinary
MD5:
SHA256:
2152opera.exeC:\Users\admin\AppData\Local\Opera\Opera\cache\g_0000\opr00003.tmpimage
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
12
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2152
opera.exe
GET
195.2.93.198:80
http://crystalfiles.ru/uploads/icons/d1dfcaf8147fd27371d33c3aa91f95a7.png
RU
malicious
2152
opera.exe
GET
195.2.93.198:80
http://crystalfiles.ru/uploads/icons/8c3e8be6862f4e9bad636cee962b5fca.png
RU
malicious
2152
opera.exe
GET
195.2.93.198:80
http://crystalfiles.ru/uploads/icons/07a7feffaa87c15d2a37acc0fda40752.png
RU
malicious
2152
opera.exe
GET
195.2.93.198:80
http://crystalfiles.ru/uploads/icons/6300b66776e070305c3c3d1a47288cb8.png
RU
malicious
2152
opera.exe
GET
195.2.93.198:80
http://crystalfiles.ru/uploads/icons/e95b30dd8270317ad3b0d1d17cc46ea9.png
RU
malicious
2152
opera.exe
GET
195.2.93.198:80
http://crystalfiles.ru/uploads/icons/a88f2146bac334c2c686d6ba52b03060.png
RU
malicious
2152
opera.exe
GET
195.2.93.198:80
http://crystalfiles.ru/uploads/icons/dbaf2ccc45c7ce33bb49a22d9d7047ac.png
RU
malicious
2152
opera.exe
GET
195.2.93.198:80
http://crystalfiles.ru/css/style.css
RU
malicious
2152
opera.exe
POST
200
195.2.93.198:80
http://crystalfiles.ru/
RU
html
1.55 Kb
malicious
2152
opera.exe
GET
200
195.2.93.198:80
http://crystalfiles.ru/
RU
html
790 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2152
opera.exe
195.2.93.198:80
crystalfiles.ru
Zenon N.S.P.
RU
unknown
2152
opera.exe
82.145.216.15:80
sitecheck2.opera.com
Opera Software AS
suspicious
2152
opera.exe
185.26.182.94:443
certs.opera.com
Opera Software AS
whitelisted
2152
opera.exe
93.184.220.29:80
crl4.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted

DNS requests

Domain
IP
Reputation
crystalfiles.ru
  • 195.2.93.198
malicious
certs.opera.com
  • 185.26.182.94
whitelisted
sitecheck2.opera.com
  • 82.145.216.15
whitelisted
crl4.digicert.com
  • 93.184.220.29
whitelisted

Threats

No threats detected
No debug info