camstudio.exe

Path Quality (Alpha Criteria Ltd.)

The application camstudio.exe by Path Quality (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.conceptspresentmeta.com and multiple other hosts.
Publisher:
CamStudio  (signed by Path Quality (Alpha Criteria Ltd.))

Product:
CamStudio

Version:
2.0.5.a0.1_60682

MD5:
d0ca8ed45dfe2d14616afc92dc2bfa27

SHA-1:
10d9629d40bbcf5f0d9abf5b400fbfa5f11df192

SHA-256:
b21cbcd4a3a56d2795aef1c2bc1d158fc3f72229dee68519adbfbb68921d2469

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/1/2024 8:28:42 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC (M)
16.7.10.13

File size:
990 KB (1,013,792 bytes)

Product version:
2.0.5.a0.1_60682

Copyright:
CamStudio

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\camstudio.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/31/2015 3:09:15 AM

Valid to:
8/3/2016 6:53:56 AM

Subject:
CN=Path Quality (Alpha Criteria Ltd.), O=Path Quality (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121865442A968BACB1F4EC1956476A3AE8D

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:d1QPcnADHUAApXfhY/91+Q/C7vMFvaBEi5wsItQ:d6ZepXfDQN17sqQ

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9258

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file camstudio.exe has been seen being distributed by the following 42 URLs.

http://www.conceptspresentmeta.com/c?x=3WsJKhrgP0uZcyiZu8mkUoJGjUMgEb4LyfC4hlaO3xE=&e=0&c=UoxMoRUVYCYgcRZLaqvnnJ N8yQz08SQiVS49JNi6Uujg0y77Vf6NFjgpckZL3OzJpizK1D7LFA/XwKUzUA dsh8C33x3Vo7U0irPrdJ/8AFl6ItHH3IPKWAf4DSiVomz 79/rOz92zBbJQgGby3j5baBApQoo/QhZQ1Oo7yzow=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=whgoxNL/wKuw7izgPKOyWt5CfF//EJ g093cQGIvMEQ=&e=0&c=Q60GIW6Ng ldvx1/1tGNT02MVMgqT2WuyOitK3XsqIX3DLKHjHOGWHlNIvesIXi9juyMs3yb1Hy/g2lo4c8G01jnG CAJycjQqllysUe8Yy1 0aPNXgS3ODSz1gLcQmMd/5QXlT/HCTyTZA s5nPpi2nuKwmoWHt7A34Pz/fRuc=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=sa0UUyZrdxjrJkOMxC8UY1jal hvGz/n1tsWZ11lctg=&e=0&c=bKZImQzTuTJ4siH4tKVin683VuxneXH13nIzS2T10Z04jK6elGObHuj1nZUqkF/eKlZOTyzodmpqdCU3HEfaOMIv1fsduj3zG/j/OsvLNLf4TecLPP/1BkOygs6Ru62L6e1eB3uz6bZxrubF YJicHDqJfbIEMgbEzA8RHvTaXI=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=AfuVhitiu095oB FrSN5DEgRze1SF9D6QEpx5DJ1w68=&e=0&c=Pnp2eV1Z8ZTq4CnunaN2EcN3jVUnC8bxBHcZZKCiSUmKmyNi6m1URpUR9VtltcKW28RpDzJccEVm9o6jilb9q1Mh7K8ayAfnCp/Yta bxihtO41lcu/6lvhdIskUgnLapRHgjAapMJ91eY1e6vaMIW/PAugVyL gGkCadnEcFkw=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=Zk8sPJZ/xodH9pboVQ1opMnmJ9JyD1Ed5OgpitFggts=&e=0&c=i9mbtsrv7k9jHTu6QBxka 4rVn9XIDN8SNUWJE8/f8eEpPfk6EIy0u4/cwFaAYnJotWTIkqAy9PadPd8lZ03A1uS0GSjtVQ 5HkLu4xhAIIS1vqVPCgmu6SCpBL0w5H6cIjxiNc6VYWefjeEVEmihVgq/Wex/20ka5iH9esKwRQ=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=MAYaY3W0sOSQcQ6O6IsLla5T0T116O W6e5CTtpq9JU=&e=0&c=wHK/KGrtPFKDOHkHbP0SRq31Ptr0a/CPvuN9gbjGWKaRskbqvRdYxrA4foq2476tegUlwrUyKsxdhX6atPaPrIpXCXFFct8ish5xom1gt7u0WA5avw7gcLk6mXbnOM4ru7dmxIZ9cjUI0pF Rt6seEP1QPxmcSeoGs4/4Zt78CI=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=KPyhkCt6obF6/1/jaWEHPkywsAzDW5o1Zq28FNHUuqg=&e=0&c=z8NjFu9n6RcfrASLViI23aAqOVWyiU4QXsUDJePN w9 WsL k1pAb8UUDrXwzNaVGRMO9xxBYvrzNriZ42pPCT3j7723Hu1JZPMt9A5ctuO8lVyEVcLaxpGIxfSg2uIIQ04KPNdQOpyWzkZ6g/sjfkHd6cYEf651lJPgK8CImCk=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=Rvfb85kRfoawx2f2OXGuVFtzBwmz1xHw9sjpt fZ52A=&e=0&c=kYaiyACrBBs8ENbpJBuLLYYYz4IFnT7vAQd5KvKS9L3Y7P4AuktwTJP7m2s9qprthsaYvGL1yHGzYA1X21X/cNUEQ4F0 LfienloP/jiy4eC5G5ciNZg6xAvaAzhw6bwCaLk0dljvFZL616YepMzYWz69LZeeW5Y25ijYa63FFY=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=oGPWBppYZ6vGuC/feKkzYRa8OVfr4Wuvr6tI2hqV22s=&e=0&c=ZaAj7zhnk UOx/JANXTXz9i9 H8CZESIn6OsOLLw0ZWzon80/3poL06eev2uBhUz rUstsQ3R6j0rwDCzWKeEEXi0WSD9PDguK2ib3KoVXR2YRdpEGK/xs 5hKJrvIz Iw7L/qBePr3cWLE8Ekvr5spz7Es6Yyhh2LCUVY5K8HI=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=12keX3PX3IhK sC1/LjrZBhk2iRlC94EPECj9BK5GVA=&e=0&c=Sq/v6lZsTFempOuGgjxrOAQD9hOKpb0iEb48I3okXbk /lwGxr/Va9QPZqZO9/B0dltiaTE6oed2HkP4M0ynCfpPfhTRkOZFHNBoomxrg3nEmYFFH5WiGdBjbGDJWzhtN2fwRYjMfgCYrgBot5r3oxKNZu0AGzhQY3WPT8b2J7g=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=s2wxX2ZSr4Vp61Yp3DvmZESyTQogDOX0 DgkFB3FVjY=&e=0&c=0U/FAxCsh3hmeSi/n6B/2xmRQ3RMfBxeT9CCP1HjI1z1GPK1pMqXmDdD2ozUm1UCe 2fjRzTw5uNIQGefghBCjfnNo6u TlXNn3K3Jr7Z6kUqgJuDb5XgnVNS76a/5pSUQpDKnwBAs8SNCf2uZ4OKBZi78r4UUWMLLr32s2cHtQ=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=sfeWJsSCCwCfCvAPF6wn1NrUs2w1wushNFPXBRelY/Y=&c=0GsBfvlO96H5QXgkgnFH livxlh5UYzx83WGyQ6YoLU78St5 l/SXDc1F3ggmgcn8TBMDzSETJiwDEH9vOUfNgAZWAvrXHqdOlHAXhCmB88iLw8UPtwO8kA8uBYMA8KBDGy0IyM2Kpu8/KEvXmVVc93w1GpJ3kvfbVhABmGO34I=&e=0&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=czMeLfvr4UARXHetVkRD3Drdj1Wp/dWRDjQFBMXS8iU=&e=0&c=mkFmXCsP0n4KCLSlQhF2g89LuiWhIeszWIgs0mdrjBkUL6lTwYlQx0l AhWgMmw8FIpaAs3sI0agNZ7Lj H1qck12NPgi6Wv9Uhl7 YUmPqE64OYXV9jsXKvJ9WNbgx9bVQXW5b3g3EMHAGVEvu9KOJ2mN0NqFevW3sSGz5wekM=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=avpW0YZo0jJCVZIGEGamS7yqCRkOCahKb6z0x4deEQA=&e=0&c=qj/RZscKhWLPhn9UbxEHABYN StUyrsnr91z1wtKjORCtciEnBNAk2MPgtue7srUxxbHRYd17CbyDrCCvmTXXDrZC6sLqg0XNj0r4EE1oM39ad/jyNAMLZBk c84YSfkIDRZk6RFnj/C9ovB/tGu5mXIhonOC1UyURijfj3zHmM=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=CoR6kK8bihW33xT1McKJ1NojD0 yIci4a/5Q1Yhl0RE=&e=0&c=5nb94DfjobJwyRApXukS5s9FC/De9e9IqI7SWRNizLZsjabywBxRnIrfRw40pgG8DUL4NIxqqe0Fi3qBAX60JnLU6iV4pPsMdh 8vwdAgKTZuhYcul6GYBRgOXho88TZHqs0dp2xuHr MTOA7Xxy7V1fC0Lx0wPUxGiKDbzNleI=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=QJZ zTNXoTNGuwCUD1xSsFQjm5AcauaocHI5pz2CD4s=&e=0&c=wCP bXw5YkJ7DFB1TPgKwRDletM8pmqCA9yMRrya80wVZQuDl8th531Db1aIiOiPGOYrQoetm6ONc50Gl fQQHoOou3dfN1FPfx0tOdobhxjjjquAzMiz2rSBeV/R3XHJmsvwEekOye9/HqppfLgl540uky2mZEczkXEWdkmlHQ=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

Latest 30 of 42 download URLs

Remove camstudio.exe - Powered by Reason Core Security