cameyo.exe

Cameyo

The executable cameyo.exe has been detected as malware by 5 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from files.downloadnow.com and multiple other hosts. While running, it connects to the Internet address ns517362.ip-158-69-27.net on port 443.
Publisher:
Cameyo

Product:
Cameyo

Description:
Cameyo client

Version:
0.0.0.0

MD5:
6a305109a853c9f5374208b84bf2445f

SHA-1:
d1d34ab090bfab69d3dcec6c277c32942f4d90e1

SHA-256:
eabb3689f8c1707b95d3e36f50b0b51f9ae845d81f0682e347db257362f4df1f

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
11/15/2024 5:56:35 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.Siggen6.20129
9.0.1.0189

G Data
Win32.Trojan.Agent.S697WU
14.7.24

NANO AntiVirus
Trojan.Win32.ArchSMS.djrvft
0.30.0.65070

Vba32 AntiVirus
TrojanDropper.Injector
3.12.26.3

Zillya! Antivirus
Dropper.Injector.Win32.62981
2.0.0.2062

File size:
15.1 MB (15,801,141 bytes)

Product version:
0.0.0.0

Copyright:
Copyright © Cameyo

Original file name:
CameyoMenu.exe

File type:
Executable application (Win64 EXE)

Language:
Turkish (Turkey)

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
393216:5tcuGz/i91ezBwwBdDADhv7ZJff1e12jOO7e:nneBbBREfA1KOOS

Entry point:
E8, 97, 86, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, 10, BF, 51, 00, 75, 02, F3, C3, E9, 19, 87, 00, 00, 8B, FF, 55, 8B, EC, 83, EC, 20, 56, 33, F6, 39, 75, 0C, 75, 1D, E8, 21, 71, 00, 00, 56, 56, 56, 56, 56, C7, 00, 16, 00, 00, 00, E8, 82, 0A, 00, 00, 83, C4, 14, 83, C8, FF, EB, 27, FF, 75, 14, 8D, 45, E0, FF, 75, 10, C7, 45, E4, FF, FF, FF, 7F, FF, 75, 0C, C7, 45, EC, 42, 00, 00, 00, 50, 89, 75, E8, 89, 75, E0, FF, 55, 08, 83, C4, 10, 5E, C9, C3, 8B, FF, 55, 8B, EC, FF, 75, 0C, 6A, 00, FF, 75, 08, 68, 19, B8...
 
[+]

The file cameyo.exe has been seen being distributed by the following 4 URLs.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP SSL):
Connects to ns517362.ip-158-69-27.net  (158.69.27.194:443)

Remove cameyo.exe - Powered by Reason Core Security