File name:

CrystalLauncherN.exe

Full analysis: https://app.any.run/tasks/804e2ba9-015b-4654-b3c9-c8a61e2ddf5e
Verdict: Malicious activity
Analysis date: June 21, 2025, 20:45:37
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-doc
antivm
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

71CE62AD6A1DA34BCC3A0BCA71F1E2DF

SHA1:

C5080FCB7B9CA8A8A267E217A4DF2170EAFC2BB2

SHA256:

7F13BB7A4B4FDAB3EE99AA40599314FB2AB48F17C02736E06894C2578B3C0A36

SSDEEP:

12288:qXlhhEayVkv/JBdBS4msNUCe65frHMnz2R9aty+v54BgCN:qXlhhUQ/bdo4mz1U8z22y+vLCN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • CrystalLauncherN.exe (PID: 3780)
    • Executable content was dropped or overwritten

      • CrystalLauncherN.exe (PID: 3780)
      • java.exe (PID: 3148)
      • javaw.exe (PID: 768)
      • expand.exe (PID: 536)
    • There is functionality for taking screenshot (YARA)

      • CrystalLauncherN.exe (PID: 3780)
      • java.exe (PID: 3148)
    • Process drops legitimate windows executable

      • CrystalLauncherN.exe (PID: 3780)
      • javaw.exe (PID: 768)
      • expand.exe (PID: 536)
    • The process creates files with name similar to system file names

      • CrystalLauncherN.exe (PID: 3780)
    • The process drops C-runtime libraries

      • CrystalLauncherN.exe (PID: 3780)
      • expand.exe (PID: 536)
      • javaw.exe (PID: 768)
    • There is functionality for VM detection VMWare (YARA)

      • java.exe (PID: 3148)
      • javaw.exe (PID: 768)
    • Unpacks CAB file

      • expand.exe (PID: 536)
    • There is functionality for VM detection antiVM strings (YARA)

      • javaw.exe (PID: 768)
      • java.exe (PID: 3148)
  • INFO

    • Checks supported languages

      • CrystalLauncherN.exe (PID: 3780)
      • java.exe (PID: 3148)
      • javaw.exe (PID: 768)
      • expand.exe (PID: 536)
    • Reads the computer name

      • CrystalLauncherN.exe (PID: 3780)
      • javaw.exe (PID: 768)
      • java.exe (PID: 3148)
    • Reads the machine GUID from the registry

      • CrystalLauncherN.exe (PID: 3780)
      • javaw.exe (PID: 768)
      • java.exe (PID: 3148)
      • expand.exe (PID: 536)
    • Checks proxy server information

      • CrystalLauncherN.exe (PID: 3780)
      • slui.exe (PID: 6704)
    • Reads Environment values

      • CrystalLauncherN.exe (PID: 3780)
    • Reads the software policy settings

      • CrystalLauncherN.exe (PID: 3780)
      • javaw.exe (PID: 768)
      • slui.exe (PID: 6704)
    • Creates files or folders in the user directory

      • CrystalLauncherN.exe (PID: 3780)
      • javaw.exe (PID: 768)
      • java.exe (PID: 3148)
      • expand.exe (PID: 536)
    • Disables trace logs

      • CrystalLauncherN.exe (PID: 3780)
    • The sample compiled with english language support

      • CrystalLauncherN.exe (PID: 3780)
      • javaw.exe (PID: 768)
      • expand.exe (PID: 536)
    • Process checks computer location settings

      • java.exe (PID: 3148)
      • javaw.exe (PID: 768)
    • Create files in a temporary directory

      • java.exe (PID: 3148)
      • javaw.exe (PID: 768)
    • Reads CPU info

      • java.exe (PID: 3148)
      • javaw.exe (PID: 768)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2042:05:26 23:26:27+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 848384
InitializedDataSize: 768000
UninitializedDataSize: -
EntryPoint: 0xd1086
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.0
ProductVersionNumber: 2.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Crystal Launcher
CompanyName: https://crystal-launcher.net
FileDescription: Crystal Launcher
FileVersion: 2.0.0.0
InternalName: CrystalLauncherInstaller.exe
LegalCopyright: Copyright © Crystal Launcher 2021
LegalTrademarks: -
OriginalFileName: CrystalLauncherInstaller.NX.exe
ProductName: CrystalLauncherInstaller.NX
ProductVersion: 2.0.0.0
AssemblyVersion: 2.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
7
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start crystallaunchern.exe slui.exe javaw.exe java.exe conhost.exe no specs expand.exe conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
536C:\WINDOWS\system32\expand.exe C:\Users\admin\AppData\Roaming\Crystal-Launcher\Downloads\webrt.cab -F:* C:\Users\admin\AppData\Roaming\Crystal-Launcher\webrtC:\Windows\System32\expand.exe
javaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
LZ Expansion Utility
Exit code:
0
Version:
5.00 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\expand.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
768"C:\Users\admin\AppData\Roaming\Crystal-Launcher\runtime\64\jdk-17.0.1+12\bin\javaw.exe" -Dfile.encoding="UTF-8" -Dcrystal.windowsEngine="true" -Djava.net.preferIPv4Stack=true -Xmx256M -Xms128M -Dcrystal.wrapper.graphicscard=4D6963726F736F667420426173696320446973706C61792041646170746572 -Dcrystal.wrapper.version=34 -Dcrystal.runtimedir=jdk-17.0.1+12 -cp "C:\Users\admin\AppData\Roaming\Crystal-Launcher\launcher.jar" ovh.leszczu8023.crystalwrapper.MainC:\Users\admin\AppData\Roaming\Crystal-Launcher\runtime\64\jdk-17.0.1+12\bin\javaw.exe
CrystalLauncherN.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
OpenJDK Platform binary
Version:
17.0.1.0
Modules
Images
c:\users\admin\appdata\roaming\crystal-launcher\runtime\64\jdk-17.0.1+12\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\roaming\crystal-launcher\runtime\64\jdk-17.0.1+12\bin\jli.dll
c:\users\admin\appdata\roaming\crystal-launcher\runtime\64\jdk-17.0.1+12\bin\vcruntime140.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
2128\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeexpand.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3148C:\Users\admin\AppData\Roaming\Crystal-Launcher\runtime\64\jdk-17.0.1+12\bin\java -cp C:\Users\admin\AppData\Roaming\Crystal-Launcher\launcher.jar ovh.crystallauncher.crystalwrapper.SubProcessMainC:\Users\admin\AppData\Roaming\Crystal-Launcher\runtime\64\jdk-17.0.1+12\bin\java.exe
javaw.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
OpenJDK Platform binary
Exit code:
1
Version:
17.0.1.0
Modules
Images
c:\users\admin\appdata\roaming\crystal-launcher\runtime\64\jdk-17.0.1+12\bin\java.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\roaming\crystal-launcher\runtime\64\jdk-17.0.1+12\bin\jli.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\users\admin\appdata\roaming\crystal-launcher\runtime\64\jdk-17.0.1+12\bin\vcruntime140.dll
3780"C:\Users\admin\AppData\Local\Temp\CrystalLauncherN.exe" C:\Users\admin\AppData\Local\Temp\CrystalLauncherN.exe
explorer.exe
User:
admin
Company:
https://crystal-launcher.net
Integrity Level:
MEDIUM
Description:
Crystal Launcher
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\crystallaunchern.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6180\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exejava.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6704C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
8 742
Read events
8 725
Write events
17
Delete events
0

Modification events

(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(3780) CrystalLauncherN.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CrystalLauncherN_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
432
Suspicious files
398
Text files
644
Unknown types
0

Dropped files

PID
Process
Filename
Type
3780CrystalLauncherN.exeC:\Users\admin\AppData\Roaming\Crystal-Launcher\Downloads\jre_17.0.1-x64.zip
MD5:
SHA256:
3780CrystalLauncherN.exeC:\Users\admin\AppData\Local\CrystalLauncherInstallerNX\language.flagtext
MD5:288404204E3D452229308317344A285D
SHA256:3485639FAF1591F3C16F295198E9389DB5B33C949587EC48663597D4E00299D5
3780CrystalLauncherN.exeC:\Users\admin\AppData\Local\CrystalLauncherInstallerNX\crystalRuntimetext
MD5:2E3287AAF04853614DF94851955CFBE4
SHA256:A865BFC17913DACDDFAED4BFBAABB9A690061153A50CD418DBB0822C7150E960
3780CrystalLauncherN.exeC:\Users\admin\AppData\Local\CrystalLauncherInstallerNX\launchlog.txttext
MD5:BD4AC26785A07BD69323493FAF8FD847
SHA256:CE2D35CCA6512D96EA4E642DDD6E3814F17B8FA20D2D678ABA72063DB33FF3F8
3780CrystalLauncherN.exeC:\Users\admin\AppData\Roaming\Crystal-Launcher\runtime\64\jdk-17.0.1+12\bin\api-ms-win-core-console-l1-1-0.dll.tmpexecutable
MD5:41029141EBDB1F1885471CDFC9C0F029
SHA256:9172D46FE807CAE7A1845BFC3A0EB5B5DB9E244693590B4EC251C8D4668DF86F
3780CrystalLauncherN.exeC:\Users\admin\AppData\Roaming\Crystal-Launcher\launcher.exeexecutable
MD5:71CE62AD6A1DA34BCC3A0BCA71F1E2DF
SHA256:7F13BB7A4B4FDAB3EE99AA40599314FB2AB48F17C02736E06894C2578B3C0A36
3780CrystalLauncherN.exeC:\Users\admin\AppData\Local\CrystalLauncherInstallerNX\crystalRuntimeBranchtext
MD5:C00F0C4675B91FB8B918E4079A0B1BAC
SHA256:FE6D3468CF5C74D8EC2A95B40F2E05338C37A4202F8FAD692D2B64A9CF9B468A
3780CrystalLauncherN.exeC:\Users\admin\Desktop\Crystal Launcher.lnkbinary
MD5:91F88BC37EFBCC2E85C7D49191736A34
SHA256:69E9AA97C3FF2FF372F65DE4B4420C8A702277816B1D9B5996EE4A0C726A6732
3780CrystalLauncherN.exeC:\Users\admin\AppData\Roaming\Crystal-Launcher\runtime\64\jdk-17.0.1+12\bin\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:FCDBA7576097D85ACAA30125E12102C3
SHA256:EC3CF75F8B3451474A7F77CD5D9FA4D70DC2FB58E1BFB31698FC8997D50E96CB
3780CrystalLauncherN.exeC:\Users\admin\AppData\Roaming\.crystalinsttext
MD5:75403FF6425A6D21F15BBBE4112BAA88
SHA256:FCB0FDCD38C9A4FED38476AA28AE014942FF0EB2630CA5B84D975E628AF81E5D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
109
DNS requests
27
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3768
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1268
svchost.exe
GET
200
184.25.50.10:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4836
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4836
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
23.209.209.135:80
http://x1.c.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5476
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3780
CrystalLauncherN.exe
188.114.96.3:443
launcher.crystal-launcher.net
CLOUDFLARENET
NL
unknown
4
System
192.168.100.255:138
whitelisted
2336
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
3768
svchost.exe
20.190.159.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3768
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
3780
CrystalLauncherN.exe
92.123.38.9:443
aka.ms
AKAMAI-AS
AT
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 142.250.184.206
whitelisted
launcher.crystal-launcher.net
  • 188.114.96.3
  • 188.114.97.3
unknown
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.159.0
  • 20.190.159.64
  • 20.190.159.128
  • 20.190.159.23
  • 40.126.31.67
  • 40.126.31.2
  • 20.190.159.130
  • 40.126.31.128
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
aka.ms
  • 92.123.38.9
whitelisted
download.visualstudio.microsoft.com
  • 104.123.50.170
whitelisted
crl.microsoft.com
  • 184.25.50.10
  • 184.25.50.8
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 95.101.149.131
whitelisted

Threats

No threats detected
Process
Message
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][Void Log(System.String, System.String):0] [INFO] Starting task ResolveAssembilesTask...
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][Void Log(System.String, System.String):0] [INFO] Task ResolveAssembilesTask finished with ActionResult OK
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][Boolean HasArgument(System.String):0] HasArgument /nosetup? = false
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][Void Log(System.String, System.String):0] [INFO] Setting up newer TLS version...
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][Boolean HasArgument(System.String):0] HasArgument /dryRun? = false
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][Void Log(System.String, System.String):0] [INFO] Cleaning up attributes...
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][Void Log(System.String, System.String):0] [INFO] Starting task SetupEnvTask...
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][System.String GetArgument(System.String):0] HasArgument /params? = false
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][Void Log(System.String, System.String):0] [INFO] Starting task RuntimeModelTask...
CrystalLauncherN.exe
[6/21/2025 8:45:42 PM][Void Log(System.String, System.String):0] [INFO] Task SetupEnvTask finished with ActionResult OK