File name:

CrystalLauncherN.exe

Full analysis: https://app.any.run/tasks/804e2ba9-015b-4654-b3c9-c8a61e2ddf5e
Verdict: Malicious activity
Analysis date: June 21, 2025, 20:45:37
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-doc
antivm
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

71CE62AD6A1DA34BCC3A0BCA71F1E2DF

SHA1:

C5080FCB7B9CA8A8A267E217A4DF2170EAFC2BB2

SHA256:

7F13BB7A4B4FDAB3EE99AA40599314FB2AB48F17C02736E06894C2578B3C0A36

SSDEEP:

12288:qXlhhEayVkv/JBdBS4msNUCe65frHMnz2R9aty+v54BgCN:qXlhhUQ/bdo4mz1U8z22y+vLCN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • CrystalLauncherN.exe (PID: 3780)
      • java.exe (PID: 3148)
      • javaw.exe (PID: 768)
      • expand.exe (PID: 536)
    • There is functionality for taking screenshot (YARA)

      • CrystalLauncherN.exe (PID: 3780)
      • java.exe (PID: 3148)
    • The process creates files with name similar to system file names

      • CrystalLauncherN.exe (PID: 3780)
    • The process drops C-runtime libraries

      • CrystalLauncherN.exe (PID: 3780)
      • expand.exe (PID: 536)
      • javaw.exe (PID: 768)
    • Reads security settings of Internet Explorer

      • CrystalLauncherN.exe (PID: 3780)
    • Process drops legitimate windows executable

      • CrystalLauncherN.exe (PID: 3780)
      • expand.exe (PID: 536)
      • javaw.exe (PID: 768)
    • There is functionality for VM detection antiVM strings (YARA)

      • java.exe (PID: 3148)
      • javaw.exe (PID: 768)
    • There is functionality for VM detection VMWare (YARA)

      • javaw.exe (PID: 768)
      • java.exe (PID: 3148)
    • Unpacks CAB file

      • expand.exe (PID: 536)
  • INFO

    • Checks supported languages

      • CrystalLauncherN.exe (PID: 3780)
      • javaw.exe (PID: 768)
      • java.exe (PID: 3148)
      • expand.exe (PID: 536)
    • Reads the computer name

      • CrystalLauncherN.exe (PID: 3780)
      • javaw.exe (PID: 768)
      • java.exe (PID: 3148)
    • Checks proxy server information

      • CrystalLauncherN.exe (PID: 3780)
      • slui.exe (PID: 6704)
    • Reads the software policy settings

      • CrystalLauncherN.exe (PID: 3780)
      • slui.exe (PID: 6704)
      • javaw.exe (PID: 768)
    • Reads the machine GUID from the registry

      • CrystalLauncherN.exe (PID: 3780)
      • javaw.exe (PID: 768)
      • java.exe (PID: 3148)
      • expand.exe (PID: 536)
    • Reads Environment values

      • CrystalLauncherN.exe (PID: 3780)
    • Disables trace logs

      • CrystalLauncherN.exe (PID: 3780)
    • The sample compiled with english language support

      • CrystalLauncherN.exe (PID: 3780)
      • javaw.exe (PID: 768)
      • expand.exe (PID: 536)
    • Process checks computer location settings

      • javaw.exe (PID: 768)
      • java.exe (PID: 3148)
    • Reads CPU info

      • javaw.exe (PID: 768)
      • java.exe (PID: 3148)
    • Creates files or folders in the user directory

      • CrystalLauncherN.exe (PID: 3780)
      • javaw.exe (PID: 768)
      • java.exe (PID: 3148)
      • expand.exe (PID: 536)
    • Create files in a temporary directory

      • javaw.exe (PID: 768)
      • java.exe (PID: 3148)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2042:05:26 23:26:27+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 848384
InitializedDataSize: 768000
UninitializedDataSize: -
EntryPoint: 0xd1086
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.0
ProductVersionNumber: 2.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Crystal Launcher
CompanyName: https://crystal-launcher.net
FileDescription: Crystal Launcher
FileVersion: 2.0.0.0
InternalName: CrystalLauncherInstaller.exe
LegalCopyright: Copyright © Crystal Launcher 2021
LegalTrademarks: -
OriginalFileName: CrystalLauncherInstaller.NX.exe
ProductName: CrystalLauncherInstaller.NX
ProductVersion: 2.0.0.0
AssemblyVersion: 2.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
7
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start crystallaunchern.exe slui.exe javaw.exe java.exe conhost.exe no specs expand.exe conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
536C:\WINDOWS\system32\expand.exe C:\Users\admin\AppData\Roaming\Crystal-Launcher\Downloads\webrt.cab -F:* C:\Users\admin\AppData\Roaming\Crystal-Launcher\webrtC:\Windows\System32\expand.exe
javaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
LZ Expansion Utility
Exit code:
0
Version:
5.00 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\expand.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
768"C:\Users\admin\AppData\Roaming\Crystal-Launcher\runtime\64\jdk-17.0.1+12\bin\javaw.exe" -Dfile.encoding="UTF-8" -Dcrystal.windowsEngine="true" -Djava.net.preferIPv4Stack=true -Xmx256M -Xms128M -Dcrystal.wrapper.graphicscard=4D6963726F736F667420426173696320446973706C61792041646170746572 -Dcrystal.wrapper.version=34 -Dcrystal.runtimedir=jdk-17.0.1+12 -cp "C:\Users\admin\AppData\Roaming\Crystal-Launcher\launcher.jar" ovh.leszczu8023.crystalwrapper.MainC:\Users\admin\AppData\Roaming\Crystal-Launcher\runtime\64\jdk-17.0.1+12\bin\javaw.exe
CrystalLauncherN.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
OpenJDK Platform binary
Version:
17.0.1.0
Modules
Images
c:\users\admin\appdata\roaming\crystal-launcher\runtime\64\jdk-17.0.1+12\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\roaming\crystal-launcher\runtime\64\jdk-17.0.1+12\bin\jli.dll
c:\users\admin\appdata\roaming\crystal-launcher\runtime\64\jdk-17.0.1+12\bin\vcruntime140.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
2128\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeexpand.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3148C:\Users\admin\AppData\Roaming\Crystal-Launcher\runtime\64\jdk-17.0.1+12\bin\java -cp C:\Users\admin\AppData\Roaming\Crystal-Launcher\launcher.jar ovh.crystallauncher.crystalwrapper.SubProcessMainC:\Users\admin\AppData\Roaming\Crystal-Launcher\runtime\64\jdk-17.0.1+12\bin\java.exe
javaw.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
OpenJDK Platform binary
Exit code:
1
Version:
17.0.1.0
Modules
Images
c:\users\admin\appdata\roaming\crystal-launcher\runtime\64\jdk-17.0.1+12\bin\java.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\roaming\crystal-launcher\runtime\64\jdk-17.0.1+12\bin\jli.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\users\admin\appdata\roaming\crystal-launcher\runtime\64\jdk-17.0.1+12\bin\vcruntime140.dll
3780"C:\Users\admin\AppData\Local\Temp\CrystalLauncherN.exe" C:\Users\admin\AppData\Local\Temp\CrystalLauncherN.exe
explorer.exe
User:
admin
Company:
https://crystal-launcher.net
Integrity Level:
MEDIUM
Description:
Crystal Launcher
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\crystallaunchern.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6180\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exejava.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6704C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
8 742
Read events
8 725
Write events
17
Delete events
0

Modification events

(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
432
Suspicious files
398
Text files
644
Unknown types
0

Dropped files

PID
Process
Filename
Type
3780CrystalLauncherN.exeC:\Users\admin\AppData\Roaming\Crystal-Launcher\Downloads\jre_17.0.1-x64.zip
MD5:
SHA256:
3780CrystalLauncherN.exeC:\Users\admin\AppData\Local\CrystalLauncherInstallerNX\libChecksumstext
MD5:745AEEDF75582605D2AD5A2BA5AFE2D4
SHA256:69D7834399C58D1B9971C6465137F77445A697C131C487CE1683CCEFF5E056AA
3780CrystalLauncherN.exeC:\Users\admin\AppData\Roaming\Crystal-Launcher\runtime\64\jdk-17.0.1+12\release.tmptext
MD5:467156137A12676C32197B7041B78757
SHA256:6C964E482B5EC5A0A24DD0FE9B1A54323AF220FAEE866B8AC56C1E5A42475A70
3780CrystalLauncherN.exeC:\Users\admin\AppData\Local\CrystalLauncherInstallerNX\crystalRuntimeBranchtext
MD5:C00F0C4675B91FB8B918E4079A0B1BAC
SHA256:FE6D3468CF5C74D8EC2A95B40F2E05338C37A4202F8FAD692D2B64A9CF9B468A
3780CrystalLauncherN.exeC:\Users\admin\AppData\Roaming\.crystalinsttext
MD5:75403FF6425A6D21F15BBBE4112BAA88
SHA256:FCB0FDCD38C9A4FED38476AA28AE014942FF0EB2630CA5B84D975E628AF81E5D
3780CrystalLauncherN.exeC:\Users\admin\AppData\Local\CrystalLauncherInstallerNX\launchlog.txttext
MD5:BD4AC26785A07BD69323493FAF8FD847
SHA256:CE2D35CCA6512D96EA4E642DDD6E3814F17B8FA20D2D678ABA72063DB33FF3F8
3780CrystalLauncherN.exeC:\Users\admin\Desktop\Crystal Launcher.lnkbinary
MD5:91F88BC37EFBCC2E85C7D49191736A34
SHA256:69E9AA97C3FF2FF372F65DE4B4420C8A702277816B1D9B5996EE4A0C726A6732
3780CrystalLauncherN.exeC:\Users\admin\AppData\Roaming\Crystal-Launcher\runtime\64\jdk-17.0.1+12\releasetext
MD5:467156137A12676C32197B7041B78757
SHA256:6C964E482B5EC5A0A24DD0FE9B1A54323AF220FAEE866B8AC56C1E5A42475A70
3780CrystalLauncherN.exeC:\Users\admin\AppData\Roaming\Crystal-Launcher\runtime\64\jdk-17.0.1+12\bin\api-ms-win-core-datetime-l1-1-0.dll.tmpexecutable
MD5:FCDBA7576097D85ACAA30125E12102C3
SHA256:EC3CF75F8B3451474A7F77CD5D9FA4D70DC2FB58E1BFB31698FC8997D50E96CB
3780CrystalLauncherN.exeC:\Users\admin\AppData\Local\CrystalLauncherInstallerNX\language.flagtext
MD5:288404204E3D452229308317344A285D
SHA256:3485639FAF1591F3C16F295198E9389DB5B33C949587EC48663597D4E00299D5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
109
DNS requests
27
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3768
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1268
svchost.exe
GET
200
184.25.50.10:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4836
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4836
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
23.209.209.135:80
http://x1.c.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5476
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3780
CrystalLauncherN.exe
188.114.96.3:443
launcher.crystal-launcher.net
CLOUDFLARENET
NL
unknown
4
System
192.168.100.255:138
whitelisted
2336
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
3768
svchost.exe
20.190.159.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3768
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
3780
CrystalLauncherN.exe
92.123.38.9:443
aka.ms
AKAMAI-AS
AT
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 142.250.184.206
whitelisted
launcher.crystal-launcher.net
  • 188.114.96.3
  • 188.114.97.3
unknown
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.159.0
  • 20.190.159.64
  • 20.190.159.128
  • 20.190.159.23
  • 40.126.31.67
  • 40.126.31.2
  • 20.190.159.130
  • 40.126.31.128
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
aka.ms
  • 92.123.38.9
whitelisted
download.visualstudio.microsoft.com
  • 104.123.50.170
whitelisted
crl.microsoft.com
  • 184.25.50.10
  • 184.25.50.8
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 95.101.149.131
whitelisted

Threats

No threats detected
Process
Message
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][Void Log(System.String, System.String):0] [INFO] Starting task ResolveAssembilesTask...
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][Void Log(System.String, System.String):0] [INFO] Task ResolveAssembilesTask finished with ActionResult OK
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][Boolean HasArgument(System.String):0] HasArgument /nosetup? = false
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][Void Log(System.String, System.String):0] [INFO] Setting up newer TLS version...
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][Boolean HasArgument(System.String):0] HasArgument /dryRun? = false
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][Void Log(System.String, System.String):0] [INFO] Cleaning up attributes...
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][Void Log(System.String, System.String):0] [INFO] Starting task SetupEnvTask...
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][System.String GetArgument(System.String):0] HasArgument /params? = false
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][Void Log(System.String, System.String):0] [INFO] Starting task RuntimeModelTask...
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][Void Log(System.String, System.String):0] [INFO] Task SetupEnvTask finished with ActionResult OK