camstudio.exe

CamStudio

The application camstudio.exe has been detected as a potentially unwanted program by 5 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from cdn.wellbundlehouse.com and multiple other hosts.
Publisher:
CamStudio

Product:
CamStudio

Version:
2.0.11.38106

MD5:
d8e4c707fd7099189aff14f76ba70c00

SHA-1:
006ad750a0928021a82011832fbddb42b1637615

SHA-256:
decfee986f3d5a7f5c58ed6d04efd627436d516de26c397e43ce247340061442

Scanner detections:
5 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/30/2024 3:19:51 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.InstallCore
2015.07.29

Comodo Security
Application.Win32.InstallCore.AEK
22702

Malwarebytes
v2015.07.31.12

Panda Antivirus
Trj/Chgt.O
15.07.31.12

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
3.12.26.4

File size:
951.1 KB (973,964 bytes)

Product version:
2.0.11.38106

Copyright:
CamStudio

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\camstudio.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:hkr9uyOVPAP/z1I+UcucMeHJ6Cv5m6ZKYqII8MBTlP0QjcpMXVJoT:h0Cw/hI+U3De5KOI8Gpf8

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9272

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file camstudio.exe has been seen being distributed by the following 2 URLs.

http://cdn.wellbundlehouse.com/c?x=XL7vkr5/ivN567rnnprFYF79R0gPmsHC4hk9UhUDOC0=&c=Y6dGQiBhJs9Bok/UeJH2jamxnpfAOln3hljMvR4SznBLfjuwgc2DIaN4h0R5bK9fcMx9ueB2IfJPaGdDUTBRh/qgkx/wjUaAFwt8SZeMMvXhXsfE5FivnDk A4khQyP0l/Vw 4kb/f0VTczZjqVrpVoNNzxrTyLddMUDGLID828=&downloadAs=camstudio.exe&fallback_url=https://s3.amazonaws.com/.../CamStudioSetup.exe

Remove camstudio.exe - Powered by Reason Core Security