| File name: | CrystalLauncherN.exe |
| Full analysis: | https://app.any.run/tasks/43dcf81b-b67c-4694-a186-8fb31f9d5b43 |
| Verdict: | Malicious activity |
| Analysis date: | December 04, 2023, 12:10:46 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| MD5: | 71CE62AD6A1DA34BCC3A0BCA71F1E2DF |
| SHA1: | C5080FCB7B9CA8A8A267E217A4DF2170EAFC2BB2 |
| SHA256: | 7F13BB7A4B4FDAB3EE99AA40599314FB2AB48F17C02736E06894C2578B3C0A36 |
| SSDEEP: | 12288:qXlhhEayVkv/JBdBS4msNUCe65frHMnz2R9aty+v54BgCN:qXlhhUQ/bdo4mz1U8z22y+vLCN |
| .exe | | | Generic CIL Executable (.NET, Mono, etc.) (63.1) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (23.8) |
| .dll | | | Win32 Dynamic Link Library (generic) (5.6) |
| .exe | | | Win32 Executable (generic) (3.8) |
| .exe | | | Generic Win/DOS Executable (1.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2042:05:27 01:26:27+02:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32 |
| LinkerVersion: | 48 |
| CodeSize: | 848384 |
| InitializedDataSize: | 768000 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xd1086 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.0.0.0 |
| ProductVersionNumber: | 2.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | Crystal Launcher |
| CompanyName: | https://crystal-launcher.net |
| FileDescription: | Crystal Launcher |
| FileVersion: | 2.0.0.0 |
| InternalName: | CrystalLauncherInstaller.exe |
| LegalCopyright: | Copyright © Crystal Launcher 2021 |
| LegalTrademarks: | - |
| OriginalFileName: | CrystalLauncherInstaller.NX.exe |
| ProductName: | CrystalLauncherInstaller.NX |
| ProductVersion: | 2.0.0.0 |
| AssemblyVersion: | 2.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1296 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1696 | "C:\Users\admin\AppData\Roaming\Crystal-Launcher\launcher.exe" /nosetup | C:\Users\admin\AppData\Roaming\Crystal-Launcher\launcher.exe | explorer.exe | ||||||||||||
User: admin Company: https://crystal-launcher.net Integrity Level: MEDIUM Description: Crystal Launcher Exit code: 0 Version: 2.0.0.0 Modules
| |||||||||||||||
| 2980 | "C:\Users\admin\AppData\Local\Temp\CrystalLauncherN.exe" | C:\Users\admin\AppData\Local\Temp\CrystalLauncherN.exe | explorer.exe | ||||||||||||
User: admin Company: https://crystal-launcher.net Integrity Level: MEDIUM Description: Crystal Launcher Exit code: 0 Version: 2.0.0.0 Modules
| |||||||||||||||
| 3756 | C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3784 | "C:\Users\admin\AppData\Roaming\Crystal-Launcher\launcher.exe" /nosetup | C:\Users\admin\AppData\Roaming\Crystal-Launcher\launcher.exe | explorer.exe | ||||||||||||
User: admin Company: https://crystal-launcher.net Integrity Level: MEDIUM Description: Crystal Launcher Exit code: 0 Version: 2.0.0.0 Modules
| |||||||||||||||
| 4032 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2980) CrystalLauncherN.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2980) CrystalLauncherN.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005A010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2980) CrystalLauncherN.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3784) launcher.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3784) launcher.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3784) launcher.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1696) launcher.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (1696) launcher.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1696) launcher.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3756) dllhost.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: Explorer.EXE | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2980 | CrystalLauncherN.exe | C:\Users\admin\AppData\Local\CrystalLauncherInstallerNX\launchlog.txt | text | |
MD5:9D699162290500BA4D0B548765AF234A | SHA256:5A658011E123BA6364297EBDB9C59FE5CA117547D9F457A19426C015C4A94D4C | |||
| 2980 | CrystalLauncherN.exe | C:\Users\admin\AppData\Local\Temp\Tar66AE.tmp | binary | |
MD5:9C0C641C06238516F27941AA1166D427 | SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F | |||
| 2980 | CrystalLauncherN.exe | C:\Users\admin\AppData\Roaming\.crystalinst | text | |
MD5:75403FF6425A6D21F15BBBE4112BAA88 | SHA256:FCB0FDCD38C9A4FED38476AA28AE014942FF0EB2630CA5B84D975E628AF81E5D | |||
| 2980 | CrystalLauncherN.exe | C:\Users\admin\AppData\Local\Temp\Cab66AD.tmp | compressed | |
MD5:AC05D27423A85ADC1622C714F2CB6184 | SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D | |||
| 2980 | CrystalLauncherN.exe | C:\Users\admin\AppData\Local\CrystalLauncherInstallerNX\language.flag | text | |
MD5:9CFEFED8FB9497BAA5CD519D7D2BB5D7 | SHA256:DBD3A49D0D906B4ED9216B73330D2FB080EF2F758C12F3885068222E5E17151C | |||
| 2980 | CrystalLauncherN.exe | C:\Users\admin\AppData\Local\CrystalLauncherInstallerNX\crystalRuntimeBranch | text | |
MD5:C00F0C4675B91FB8B918E4079A0B1BAC | SHA256:FE6D3468CF5C74D8EC2A95B40F2E05338C37A4202F8FAD692D2B64A9CF9B468A | |||
| 2980 | CrystalLauncherN.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 | compressed | |
MD5:AC05D27423A85ADC1622C714F2CB6184 | SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D | |||
| 2980 | CrystalLauncherN.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 | binary | |
MD5:6BCDE659F8DA85D63FBE190F9621169A | SHA256:B950BE4E3440A2BE2DC11A317804075E471EDE51F395C0A7366C2827D37344AD | |||
| 2980 | CrystalLauncherN.exe | C:\Users\admin\AppData\Local\CrystalLauncherInstallerNX\crystalRuntime | text | |
MD5:2E3287AAF04853614DF94851955CFBE4 | SHA256:A865BFC17913DACDDFAED4BFBAABB9A690061153A50CD418DBB0822C7150E960 | |||
| 2980 | CrystalLauncherN.exe | C:\Users\admin\AppData\Roaming\Crystal-Launcher\launcher.exe | executable | |
MD5:71CE62AD6A1DA34BCC3A0BCA71F1E2DF | SHA256:7F13BB7A4B4FDAB3EE99AA40599314FB2AB48F17C02736E06894C2578B3C0A36 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2980 | CrystalLauncherN.exe | GET | 200 | 95.101.54.195:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?4f2ce9858a120c5d | unknown | compressed | 65.2 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2980 | CrystalLauncherN.exe | 188.114.96.3:443 | launcher.crystal-launcher.net | CLOUDFLARENET | NL | unknown |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2980 | CrystalLauncherN.exe | 95.101.54.195:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3784 | launcher.exe | 188.114.96.3:443 | launcher.crystal-launcher.net | CLOUDFLARENET | NL | unknown |
1696 | launcher.exe | 188.114.96.3:443 | launcher.crystal-launcher.net | CLOUDFLARENET | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
launcher.crystal-launcher.net |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
Process | Message |
|---|---|
CrystalLauncherN.exe | [12/4/2023 12:10:54 PM][Void Log(System.String, System.String):0] [INFO] Starting task ResolveAssembilesTask...
|
CrystalLauncherN.exe | [12/4/2023 12:10:54 PM][Void Log(System.String, System.String):0] [INFO] Task ResolveAssembilesTask finished with ActionResult OK
|
CrystalLauncherN.exe | [12/4/2023 12:10:54 PM][Void Log(System.String, System.String):0] [INFO] Starting task SetupEnvTask...
|
CrystalLauncherN.exe | [12/4/2023 12:10:54 PM][Void Log(System.String, System.String):0] [INFO] Setting up newer TLS version...
|
CrystalLauncherN.exe | [12/4/2023 12:10:54 PM][Void Log(System.String, System.String):0] [INFO] Starting task RuntimeModelTask...
|
CrystalLauncherN.exe | [12/4/2023 12:10:54 PM][System.String GetArgument(System.String):0] HasArgument /params? = false
|
CrystalLauncherN.exe | [12/4/2023 12:10:54 PM][Boolean HasArgument(System.String):0] HasArgument /dryRun? = false
|
CrystalLauncherN.exe | [12/4/2023 12:10:54 PM][Boolean HasArgument(System.String):0] HasArgument /nosetup? = false
|
CrystalLauncherN.exe | [12/4/2023 12:10:54 PM][Void Log(System.String, System.String):0] [INFO] Task SetupEnvTask finished with ActionResult OK
|
CrystalLauncherN.exe | [12/4/2023 12:10:54 PM][Void Log(System.String, System.String):0] [INFO] Cleaning up attributes...
|