File name:

CrystalLauncherN.exe

Full analysis: https://app.any.run/tasks/43dcf81b-b67c-4694-a186-8fb31f9d5b43
Verdict: Malicious activity
Analysis date: December 04, 2023, 12:10:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

71CE62AD6A1DA34BCC3A0BCA71F1E2DF

SHA1:

C5080FCB7B9CA8A8A267E217A4DF2170EAFC2BB2

SHA256:

7F13BB7A4B4FDAB3EE99AA40599314FB2AB48F17C02736E06894C2578B3C0A36

SSDEEP:

12288:qXlhhEayVkv/JBdBS4msNUCe65frHMnz2R9aty+v54BgCN:qXlhhUQ/bdo4mz1U8z22y+vLCN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • CrystalLauncherN.exe (PID: 2980)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • CrystalLauncherN.exe (PID: 2980)
      • launcher.exe (PID: 1696)
      • launcher.exe (PID: 3784)
    • Reads the Internet Settings

      • CrystalLauncherN.exe (PID: 2980)
      • launcher.exe (PID: 3784)
      • launcher.exe (PID: 1696)
  • INFO

    • Reads the machine GUID from the registry

      • CrystalLauncherN.exe (PID: 2980)
      • launcher.exe (PID: 3784)
      • launcher.exe (PID: 1696)
    • Checks supported languages

      • CrystalLauncherN.exe (PID: 2980)
      • wmpnscfg.exe (PID: 4032)
      • launcher.exe (PID: 3784)
      • wmpnscfg.exe (PID: 1296)
      • launcher.exe (PID: 1696)
    • Reads the computer name

      • CrystalLauncherN.exe (PID: 2980)
      • wmpnscfg.exe (PID: 4032)
      • launcher.exe (PID: 3784)
      • launcher.exe (PID: 1696)
      • wmpnscfg.exe (PID: 1296)
    • Checks proxy server information

      • CrystalLauncherN.exe (PID: 2980)
      • launcher.exe (PID: 3784)
      • launcher.exe (PID: 1696)
    • Reads Environment values

      • CrystalLauncherN.exe (PID: 2980)
      • launcher.exe (PID: 3784)
      • launcher.exe (PID: 1696)
    • Create files in a temporary directory

      • CrystalLauncherN.exe (PID: 2980)
    • Creates files or folders in the user directory

      • CrystalLauncherN.exe (PID: 2980)
      • launcher.exe (PID: 3784)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 4032)
      • launcher.exe (PID: 3784)
      • launcher.exe (PID: 1696)
      • wmpnscfg.exe (PID: 1296)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2042:05:27 01:26:27+02:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 848384
InitializedDataSize: 768000
UninitializedDataSize: -
EntryPoint: 0xd1086
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.0
ProductVersionNumber: 2.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Crystal Launcher
CompanyName: https://crystal-launcher.net
FileDescription: Crystal Launcher
FileVersion: 2.0.0.0
InternalName: CrystalLauncherInstaller.exe
LegalCopyright: Copyright © Crystal Launcher 2021
LegalTrademarks: -
OriginalFileName: CrystalLauncherInstaller.NX.exe
ProductName: CrystalLauncherInstaller.NX
ProductVersion: 2.0.0.0
AssemblyVersion: 2.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start crystallaunchern.exe wmpnscfg.exe no specs launcher.exe launcher.exe PhotoViewer.dll no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1296"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1696"C:\Users\admin\AppData\Roaming\Crystal-Launcher\launcher.exe" /nosetupC:\Users\admin\AppData\Roaming\Crystal-Launcher\launcher.exe
explorer.exe
User:
admin
Company:
https://crystal-launcher.net
Integrity Level:
MEDIUM
Description:
Crystal Launcher
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\crystal-launcher\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2980"C:\Users\admin\AppData\Local\Temp\CrystalLauncherN.exe" C:\Users\admin\AppData\Local\Temp\CrystalLauncherN.exe
explorer.exe
User:
admin
Company:
https://crystal-launcher.net
Integrity Level:
MEDIUM
Description:
Crystal Launcher
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\crystallaunchern.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3756C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3784"C:\Users\admin\AppData\Roaming\Crystal-Launcher\launcher.exe" /nosetupC:\Users\admin\AppData\Roaming\Crystal-Launcher\launcher.exe
explorer.exe
User:
admin
Company:
https://crystal-launcher.net
Integrity Level:
MEDIUM
Description:
Crystal Launcher
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\crystal-launcher\launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
4032"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
13 155
Read events
13 112
Write events
43
Delete events
0

Modification events

(PID) Process:(2980) CrystalLauncherN.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2980) CrystalLauncherN.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005A010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2980) CrystalLauncherN.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3784) launcher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3784) launcher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3784) launcher.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1696) launcher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1696) launcher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1696) launcher.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3756) dllhost.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
Executable files
1
Suspicious files
7
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
2980CrystalLauncherN.exeC:\Users\admin\AppData\Local\CrystalLauncherInstallerNX\launchlog.txttext
MD5:9D699162290500BA4D0B548765AF234A
SHA256:5A658011E123BA6364297EBDB9C59FE5CA117547D9F457A19426C015C4A94D4C
2980CrystalLauncherN.exeC:\Users\admin\AppData\Local\Temp\Tar66AE.tmpbinary
MD5:9C0C641C06238516F27941AA1166D427
SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F
2980CrystalLauncherN.exeC:\Users\admin\AppData\Roaming\.crystalinsttext
MD5:75403FF6425A6D21F15BBBE4112BAA88
SHA256:FCB0FDCD38C9A4FED38476AA28AE014942FF0EB2630CA5B84D975E628AF81E5D
2980CrystalLauncherN.exeC:\Users\admin\AppData\Local\Temp\Cab66AD.tmpcompressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
2980CrystalLauncherN.exeC:\Users\admin\AppData\Local\CrystalLauncherInstallerNX\language.flagtext
MD5:9CFEFED8FB9497BAA5CD519D7D2BB5D7
SHA256:DBD3A49D0D906B4ED9216B73330D2FB080EF2F758C12F3885068222E5E17151C
2980CrystalLauncherN.exeC:\Users\admin\AppData\Local\CrystalLauncherInstallerNX\crystalRuntimeBranchtext
MD5:C00F0C4675B91FB8B918E4079A0B1BAC
SHA256:FE6D3468CF5C74D8EC2A95B40F2E05338C37A4202F8FAD692D2B64A9CF9B468A
2980CrystalLauncherN.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
2980CrystalLauncherN.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:6BCDE659F8DA85D63FBE190F9621169A
SHA256:B950BE4E3440A2BE2DC11A317804075E471EDE51F395C0A7366C2827D37344AD
2980CrystalLauncherN.exeC:\Users\admin\AppData\Local\CrystalLauncherInstallerNX\crystalRuntimetext
MD5:2E3287AAF04853614DF94851955CFBE4
SHA256:A865BFC17913DACDDFAED4BFBAABB9A690061153A50CD418DBB0822C7150E960
2980CrystalLauncherN.exeC:\Users\admin\AppData\Roaming\Crystal-Launcher\launcher.exeexecutable
MD5:71CE62AD6A1DA34BCC3A0BCA71F1E2DF
SHA256:7F13BB7A4B4FDAB3EE99AA40599314FB2AB48F17C02736E06894C2578B3C0A36
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
10
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2980
CrystalLauncherN.exe
GET
200
95.101.54.195:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?4f2ce9858a120c5d
unknown
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2980
CrystalLauncherN.exe
188.114.96.3:443
launcher.crystal-launcher.net
CLOUDFLARENET
NL
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted
2980
CrystalLauncherN.exe
95.101.54.195:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3784
launcher.exe
188.114.96.3:443
launcher.crystal-launcher.net
CLOUDFLARENET
NL
unknown
1696
launcher.exe
188.114.96.3:443
launcher.crystal-launcher.net
CLOUDFLARENET
NL
unknown

DNS requests

Domain
IP
Reputation
launcher.crystal-launcher.net
  • 188.114.96.3
  • 188.114.97.3
unknown
ctldl.windowsupdate.com
  • 95.101.54.195
  • 95.101.54.203
  • 95.101.54.121
whitelisted

Threats

No threats detected
Process
Message
CrystalLauncherN.exe
[12/4/2023 12:10:54 PM][Void Log(System.String, System.String):0] [INFO] Starting task ResolveAssembilesTask...
CrystalLauncherN.exe
[12/4/2023 12:10:54 PM][Void Log(System.String, System.String):0] [INFO] Task ResolveAssembilesTask finished with ActionResult OK
CrystalLauncherN.exe
[12/4/2023 12:10:54 PM][Void Log(System.String, System.String):0] [INFO] Starting task SetupEnvTask...
CrystalLauncherN.exe
[12/4/2023 12:10:54 PM][Void Log(System.String, System.String):0] [INFO] Setting up newer TLS version...
CrystalLauncherN.exe
[12/4/2023 12:10:54 PM][Void Log(System.String, System.String):0] [INFO] Starting task RuntimeModelTask...
CrystalLauncherN.exe
[12/4/2023 12:10:54 PM][System.String GetArgument(System.String):0] HasArgument /params? = false
CrystalLauncherN.exe
[12/4/2023 12:10:54 PM][Boolean HasArgument(System.String):0] HasArgument /dryRun? = false
CrystalLauncherN.exe
[12/4/2023 12:10:54 PM][Boolean HasArgument(System.String):0] HasArgument /nosetup? = false
CrystalLauncherN.exe
[12/4/2023 12:10:54 PM][Void Log(System.String, System.String):0] [INFO] Task SetupEnvTask finished with ActionResult OK
CrystalLauncherN.exe
[12/4/2023 12:10:54 PM][Void Log(System.String, System.String):0] [INFO] Cleaning up attributes...