File name:

NightCrowsGLauncher_Installer.exe

Full analysis: https://app.any.run/tasks/cbcc3cf0-604f-4d3d-8654-51b4aaf00fa5
Verdict: Malicious activity
Analysis date: March 13, 2024, 18:51:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

51A8557ED14ABD6B024B3EAF5DA37C24

SHA1:

F004EEC85D25EEEE6DD90DEC2EF8535C2079C3D5

SHA256:

FBEA13DB26D6CCE8DA802C3DE7281BBF402242B92926075EED77E7870CBC29F3

SSDEEP:

98304:tcg1SAaK+hbh/32FuuAuuNHttToclKuuAuu0CttYnBMJfqWFKI1rwmNOMBc3ntq/:YEWFz1E0tD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • NightCrowsGLauncher_Installer.exe (PID: 2844)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • NightCrowsGLauncher_Installer.exe (PID: 2844)
    • The process creates files with name similar to system file names

      • NightCrowsGLauncher_Installer.exe (PID: 2844)
    • Process drops legitimate windows executable

      • NightCrowsGLauncher_Installer.exe (PID: 2844)
    • Executable content was dropped or overwritten

      • NightCrowsGLauncher_Installer.exe (PID: 2844)
    • Creates a software uninstall entry

      • NightCrowsGLauncher_Installer.exe (PID: 2844)
  • INFO

    • Create files in a temporary directory

      • NightCrowsGLauncher_Installer.exe (PID: 2844)
    • Checks supported languages

      • NightCrowsGLauncher_Installer.exe (PID: 2844)
    • Reads the computer name

      • NightCrowsGLauncher_Installer.exe (PID: 2844)
    • Creates files in the program directory

      • NightCrowsGLauncher_Installer.exe (PID: 2844)
    • Manual execution by a user

      • chrome.exe (PID: 2120)
    • Application launched itself

      • chrome.exe (PID: 2120)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:07:02 02:09:39+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26112
InitializedDataSize: 139776
UninitializedDataSize: 2048
EntryPoint: 0x34fc
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Russian
CharacterSet: Windows, Cyrillic
Comments: NIGHT CROWS Launcher 설치 파일 (2024-03-06 오후 2:40:36)
CompanyName: Wemade
FileDescription: NIGHT CROWS Launcher 설치 파일
FileVersion: 1.0.0
LegalCopyright: 저작권(C) 2023 Wemade
ProductName: NIGHT CROWS Launcher
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
15
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start nightcrowsglauncher_installer.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs nightcrowsglauncher_installer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1348"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1152 --field-trial-handle=1112,i,17325244842475518510,5703886700862475622,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1404"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=3472 --field-trial-handle=1112,i,17325244842475518510,5703886700862475622,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1728"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=3524 --field-trial-handle=1112,i,17325244842475518510,5703886700862475622,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1784"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=3404 --field-trial-handle=1112,i,17325244842475518510,5703886700862475622,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1824"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=1376 --field-trial-handle=1112,i,17325244842475518510,5703886700862475622,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1860"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2172 --field-trial-handle=1112,i,17325244842475518510,5703886700862475622,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2120"C:\Program Files\Google\Chrome\Application\chrome.exe" "--disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints"C:\Program Files\Google\Chrome\Application\chrome.exe
explorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2384"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=1020 --field-trial-handle=1112,i,17325244842475518510,5703886700862475622,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2688"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1608 --field-trial-handle=1112,i,17325244842475518510,5703886700862475622,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2832"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2216 --field-trial-handle=1112,i,17325244842475518510,5703886700862475622,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
5 054
Read events
5 015
Write events
39
Delete events
0

Modification events

(PID) Process:(2844) NightCrowsGLauncher_Installer.exeKey:HKEY_CURRENT_USER\Software\WEMADE\NCG\Launcher
Operation:writeName:FILE
Value:
NightCrowsGLauncher.exe
(PID) Process:(2844) NightCrowsGLauncher_Installer.exeKey:HKEY_CURRENT_USER\Software\WEMADE\NCG\Launcher
Operation:writeName:PATH
Value:
C:\Wemade\NightCrowsG\launcher
(PID) Process:(2844) NightCrowsGLauncher_Installer.exeKey:HKEY_CURRENT_USER\Software\WEMADE\NCG\Launcher
Operation:writeName:LANG
Value:
0
(PID) Process:(2844) NightCrowsGLauncher_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\wemade-nc-gl
Operation:writeName:URL Protocol
Value:
(PID) Process:(2844) NightCrowsGLauncher_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NightCrowsGLauncher
Operation:writeName:DisplayName
Value:
NightCrowsG
(PID) Process:(2844) NightCrowsGLauncher_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NightCrowsGLauncher
Operation:writeName:UninstallString
Value:
C:\Wemade\NightCrowsG\NightCrowsG_Uninstall.exe
(PID) Process:(2844) NightCrowsGLauncher_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NightCrowsGLauncher
Operation:writeName:DisplayIcon
Value:
C:\Wemade\NightCrowsG\launcher\NightCrowsGLauncher.exe
(PID) Process:(2844) NightCrowsGLauncher_Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NightCrowsGLauncher
Operation:writeName:Publisher
Value:
Wemade
(PID) Process:(2120) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2120) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
Executable files
21
Suspicious files
12
Text files
26
Unknown types
11

Dropped files

PID
Process
Filename
Type
2844NightCrowsGLauncher_Installer.exeC:\Users\admin\AppData\Local\Temp\nshF88A.tmp\UserInfo.dllexecutable
MD5:D458B8251443536E4A334147E0170E95
SHA256:4913D4CCCF84CD0534069107CFF3E8E2F427160CAD841547DB9019310AC86CC7
2844NightCrowsGLauncher_Installer.exeC:\Users\admin\AppData\Local\Temp\nshF88A.tmp\modern-header.bmpimage
MD5:9CCE1E3A5995C8DCB19CC622D9CDDCFE
SHA256:789EE33321DCFC0D39714843F4B491E99FF0682416B4D78E826A40FC04B08B12
2844NightCrowsGLauncher_Installer.exeC:\Users\admin\AppData\Local\Temp\nshF88A.tmp\System.dllexecutable
MD5:4ADD245D4BA34B04F213409BFE504C07
SHA256:9111099EFE9D5C9B391DC132B2FAF0A3851A760D4106D5368E30AC744EB42706
2844NightCrowsGLauncher_Installer.exeC:\Users\admin\AppData\Local\Temp\nshF88A.tmp\LockedList.dllexecutable
MD5:2EE096682CC84F5FD44FB5291C00596C
SHA256:671570118024C9132F12999E198CEBC87B3BF1846695553BF478C5A42EFEC226
2844NightCrowsGLauncher_Installer.exeC:\Wemade\NightCrowsG\launcher\Newtonsoft.Json.dllexecutable
MD5:195FFB7167DB3219B217C4FD439EEDD6
SHA256:E1E27AF7B07EEEDF5CE71A9255F0422816A6FC5849A483C6714E1B472044FA9D
2844NightCrowsGLauncher_Installer.exeC:\Users\admin\AppData\Local\Temp\nshF88A.tmp\LangDLL.dllexecutable
MD5:50016010FB0D8DB2BC4CD258CEB43BE5
SHA256:32230128C18574C1E860DFE4B17FE0334F685740E27BC182E0D525A8948C9C2E
2844NightCrowsGLauncher_Installer.exeC:\Wemade\NightCrowsG\launcher\Sentry.dllexecutable
MD5:DD1170182D8403F12ED53AD1868EC597
SHA256:3E90E54A88841DA0B70E92B3339D6ED683170BFC0EACA882F29A8C3E999663F8
2844NightCrowsGLauncher_Installer.exeC:\Wemade\NightCrowsG\launcher\LauncherBase.dllexecutable
MD5:397EBB16FC45D0AF8078F53A49404C78
SHA256:5375A2F41D6A0AF7B520A7EDAEF2BBC9CB18B832D11DFE139A53DA4414356CDA
2844NightCrowsGLauncher_Installer.exeC:\Wemade\NightCrowsG\launcher\NightCrowsGLauncher.exe.configxml
MD5:3F282627AA7BDAB3EE95E036B4162F8C
SHA256:A8131EFF07314DC8E16A39154BF1737673DF5DE7C5B3DA1FA61064426C7F8626
2844NightCrowsGLauncher_Installer.exeC:\Wemade\NightCrowsG\launcher\NightCrowsGLauncher.exeexecutable
MD5:2A576EE2CB83ECD10E61B5147F832DDF
SHA256:8460382BC464123D79158060A168FA25CCE0E09D5F58748B38A081B21451E749
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
28
DNS requests
16
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2120
chrome.exe
239.255.255.250:1900
unknown
1824
chrome.exe
142.250.184.195:443
clientservices.googleapis.com
GOOGLE
US
unknown
1824
chrome.exe
142.251.168.84:443
accounts.google.com
GOOGLE
US
unknown
1824
chrome.exe
142.250.186.132:443
www.google.com
GOOGLE
US
unknown
1824
chrome.exe
142.250.185.195:443
www.gstatic.com
GOOGLE
US
unknown
1824
chrome.exe
142.250.184.206:443
apis.google.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
clientservices.googleapis.com
  • 142.250.184.195
unknown
accounts.google.com
  • 142.251.168.84
unknown
www.google.com
  • 142.250.186.132
unknown
www.gstatic.com
  • 142.250.185.195
unknown
apis.google.com
  • 142.250.184.206
unknown
update.googleapis.com
  • 142.250.185.227
unknown
encrypted-tbn0.gstatic.com
  • 142.250.185.78
unknown
lh5.googleusercontent.com
  • 172.217.16.129
unknown

Threats

No threats detected
No debug info