camstudio.exe

SpeedyInstall (Alpha Criteria Ltd.)

The application camstudio.exe by SpeedyInstall (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.giftcapitalbyte.com and multiple other hosts.
Publisher:
CamStudio  (signed by SpeedyInstall (Alpha Criteria Ltd.))

Product:
CamStudio

Version:
2.0.5.a0.1_63242

MD5:
99b5f1fc1f47021c0572ba0e15fdef26

SHA-1:
13d27fb32a4894d43185745db6b640c5aaa8a44a

SHA-256:
8568c3639b7276341faf08d2e210cebf84ac82620a1988b17a9e1403a00ed8c7

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/28/2024 6:40:02 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC (M)
16.8.1.15

File size:
990.4 KB (1,014,184 bytes)

Product version:
2.0.5.a0.1_63242

Copyright:
CamStudio

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\camstudio.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/6/2016 5:35:52 PM

Valid to:
8/20/2016 4:45:01 PM

Subject:
CN=SpeedyInstall (Alpha Criteria Ltd.), O=SpeedyInstall (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121A6DC69485443ADA37B28455486E38F93

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:JbR0DaELULPyWKs2GEoFHzjhSsCbylglmsHZ/w5+WBaNWl7ul:JNjLPyWKslEoFHx6HdwFYNWO

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9321

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file camstudio.exe has been seen being distributed by the following 43 URLs.

http://www.giftcapitalbyte.com/mg Y66LVPvL42DsBQaVuny3sQv6skacMxWrnOLs2M0QI18deMbqk2XR7E3CcutDwzSTxfPuYwu B_7Mp_cyUDkdkeCnaxDpGIPdBPfWaiCqr7yV7LxgphPGGYTWO8upx6ROnK6hHOM krlOr7VBkJ 41K2dPooV7FlhiQtSR3l1FNpNj_fdtu1z8cWM4PcbQnTbBH9Cv-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/GqhYHbxsO76QfiTtJkZDjIoUcR2 xqjysDshVbvwaz5MHmQRla9TfQlEiMCELJ4AMYfDSMstfeTdPRHKZhTqLBz3O0UfsdoK2kBTIt9UhkSrE8RURn5tP1LJL1SIt_oe_uCrMp2lEAgzXjYYslVXQtkAY8rIuU2obRT0AWy7oeEBxFU9N_LWj4OROn5SzIAyxqJ8LOV2-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/pYwmhmX4x3gXNc_Q7WdfqgGyVttcoyxhnxfx4Ext0Ek4ji3JQ xFmO0BFtmh_5OqDFgl7hn170we1lWuHtfMgauvzBm6loARV0Yl9v_QMjLFDcxqkyabRIey8DFwDsP2uHMVWggHys9djxt0BXB_Lco5hIxBnV45HTxV96qAT6IKjZr8ccnAcERAb1QQRRzCZpwzpF0P-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/xb9YWjIJCNcWYZGvA9rJQg1cOnRafxzJF6nsIpTpGZdbh3wbyrY79J2Gu6f7dakjpHFQTJvetyaqEjNA3gzDfzpkRV6l2LeWK4nsuiYdw34NgeR4DgnhPyjpg7N9hRQ5bDZzXRNIEslclnZUedWiehpMtT1ke_d2F2o5p 6ugxD3sf1XFbwZX5CdYC3g6MQBudPFzpg2-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/txdUPBtEYhh3SuC9xzKAUX1a1TGEy perzXKZQuKYyX0SY PWidycEP_Na8DVHzLevn8kuES1YG0FG_KndipKRxTl0ZsqPYn5Bq3ikwOACPGZJQp8kzXrN_mUQk k3Yne O3kQuUKAK5iPyYWas62ypAW l9 fq4IkjOBH4eu zUj_jTpVBTl7u0HZC9xnj0WRRZ2rUA-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/FUzxxqtaA6dJewkEWkPhQx TmXTY1I8OGs0iIRBSsK6Ub796C8ijg53f1rvDPbXtuuNko7G0x_KODYy 65kUXjMhRKvoPSTpuHfxTosxvnxDrEwDN9oLnFzkS0MGWW EhUtThryZayE18HuOj4IdoikcL7OquUDHN4sQlxdjKts6oxaQ1f 4JExmHrk5gkhHoCIDczkN-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/GoegSzp9Go3O2pApGYvq9gqXM6gdWL44ppDBqtnD3K6JDs2n66bA3ZSiFtLh efqxcAxueDy8f7kRGlb G0XX2s27qZtQqmtJHq82NapCzFNhsUOjRcUTtWmkwcJemWNtafzt2gYituXJiwtWYj6PJk99qf3Epjs6ysiAM6MPdSSIVpl1DHet6sJbWllK0aYiVObWHXf-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/l7mNxtUmMGI1CjDE9A7W5N7wOX6oIEWOYTRpQ_wWSdIg_v0yXcdQ8H8Qg2yjjImlECAuPQkjRFkcs8c4DX9e35m4DvHBEzwe52hYSYZRCXXsF8_GQucb4lwbKb814pIzIPFOc42z03fxes6ua6j9dF5pN6yyCp DByb3XtOfdBpQiHm00SipBGqdbxVXQ77iJNInspFC-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/Snn7P_A_GXTGN2aujqadD4_nFdzanLOUUjDoqzEnDjNjB5BvxfQCER68 uTAXoC4Ckt4KKxqFTJ907Dn_37MBL4Oa0WpJHtwxjAfwbkmc7CSYPOxgp7I7QYTV2E9t8Qb7D1smiUKM8pvQid8SgN_c3FhPnIz2J8dkpOREXjLtOqufBpX73VFIiSYmaPbsOzi8N694g0L-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/XqSC4oagiRDC YE7qdYogTOgU43vDaWEGfJZ7UldJRMdDaTMCTORhO_iI5 huhVkg_Alzii5fw9VGTTDa5q3ObMTh2Fh 5VG5Ezv2dhyeWzdOQ3MIRWZ33J4y14WKi7IijCaW1E75Gb1tZs8Vt9RmIZYFAjrruQmykZdgPWSQUX1O9hyZDYhnn2JCqcPWiWyOkm2JQun-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/_WNF2CEDrIlkJHPVtkcmftaASY7jg6rFIVil_WcHu4J10KjzdM8HmnGXNHSXW1tjjJRU_4ULceWVhrysFqoCKMGQI2 P_pwbx4CFevJ3koDk6sp4ciA5 bsm6ZQSFB9X9FwXd9d6ck6rVmsyWMDhiXUzDVq fiqMKdZMFZvbtFUJ9Byv1HlEpiTUYBBuirVsA4SNkxdB-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/jXC66C7zTrdiWb1Q2_3NQDvhqGYhPLLf OVZF3G9mR5oB9KlijsBIzy4hFH0twoZ0YQQowIBkhN5lur8KZSI9QsM4bDlDRiyJJXEglhIIBXw8LESWHfUPSCmfrWyokaWVfTT6bKnJ0UNksVKl7MAJqBpzUiZ633dPPBiVCkEvnyHwyVFQzvdhueZBBSFf2CpcNGT8NCV-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/c_w5y8ztTSTOQUrOOWXGf2Va kEk4hwfD VJ 7rP2771_tyfG7djmad3rG1 tM5ngWk4YPfsIu5hwExIBaWwgDRaNc8JePHDL94dkdWWqrgNObgPt9FMCCYIT UuOpE8SGgqT1X4icCJ9biRj7IzfyrM8Tpyk3Tdjj_oNb_spOPRrzJHIrKMeQW1tykUr_X7HhRCH2XH-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/rR4QI0z_a9SHMmm0mPF1jpJduabLvkyct7lmfE1kvhcQlZhCfUwJA QSSPo8q8eQo WyKmIj9iX5ZhYOVuJvTzFSuffzA9mH5Q51sPa5mkxMFgzrmpYw2FsN7zS0IWb7hkc9Q5 cqUy2fRp8r0o9D1Eus1BbjSCywMgrSBGs 1de34NjZT41MNTqBQRzCEHbaooM4k64-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/aj2KYieiidxMeeloaQoY5AqNQIQ6NvThmMygrLCHj6_SARoUA2PtlTjpSdsNovLAdB5tLtie_H3UWrSNhSbZCLYdf_NxxWwsvET0ilcTQ76Z4ha9Jo26DhhA6KwZaIcJhPxuLo7amXbdo6RfhWDqtb10sqzoL9PuIUjL1kEDy4Wf0lnAtm6Vp Lw5Bvu JcMYgRhQv6I-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/H7qys_9CTFAB39y3emQwNC3O77uLOxns0C1BZ70t 4ACNChcatEkC8nopYTSLXoKpTXsecEj_YLbrQZTc1TovxjMV0cMF6g8_SNB6Fym0tn2KKk SxEZxwa_aGlRluCrGxuBetiLldnI6dl1iMCZfMRZOIzBUpYrLLJahFBlDzX_fUDd3 J57IiH6D33s8hgdNYgaxUy-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/H_MBL9daa4Rm5yjrCnuypCRz mmgvbzyEcDNwFyIsSLsKiKnZ0swGrmCWedtGxRFfnwgev4oQb9OOUiAJwwZzb7WuuKCTKhzSlQMNEe_JRQmd8WgldHjdB7Fw3K0t1hojvbK6FlFn4LsLJVhGnEE_a4sX7VHkckQSHhdhXY0HI vs0JczE8m7w5W2ecjpUKXqziYt6LK-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/KIpViAKs_cEDmMxiJhK_1TcBoMAeaf8RHNUJHSNxU JS95cz7pId3xeSjr1keqo BRBqmSRDelg_RWIhXF6eNOomfM_zqP1AuCHYszERsL1XXkfZ5L4rGT6_wuT1VTpLeYXjkhr1AgZOvzkzo2vtFS yp1OgOjDXdWpoGt01KXL0wsASACrWRnyVxpgJIk4HGt9X1BoM-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/z2wdKK5Qc kwz7AVC8HYzL_VKVl3O9FhEmgPX5MfMZRget85QxCwALbJbwDFblnPp7Z9Syc0s13B_KjFYYm28BRc_AN0S7Ax0nCzCo cLhyASvvG4tyGKnbxyMsPbBrKNObo6gBh7EoCYd_mnagG_sNHzmXGUSD cEzVkaNaWdavosrm8DKTv_2wn9PbevKY_VPImUM0-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/GwCfyp8gmL0eB3wedxVg9c1HQ m_JnuYoQRnKCviAoNZLVt FNN3q7wrGSx3Lbm1NwKOJKXX6GDr2xVs9sKeV8xNbL1XbCa3A2p5JXqCV3Yla3rZ5MVZKEFhNofjhgTAq6uKHlSt8FkBvRMnlAKySfPzoI6xtqB YOJk_9j4oWi8OtyBYFc79KhZ_hTtZ5TbZO6lDHRf-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/1Ebpnw2jqa_iAhWdkfNgsEIPNjfewpyaQ3txjuhSRPn_SSRCHZfAAoU3x50fwuBapyUyRP4UH8F9DvJ7b47T21NGuLrXi3qzr4eVctthhgEtF0sPSwxV1b9 zIPD6A2M2ICgqwPYKQ3GuoXvkK4HR NgrT3w0wLXWWSmGsqqjxGP2yf7sbm891iAPmzZdksyGoXybngb-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/xHb8fuUSb6XjwLrM5cqqotPmcWJwLPxYyOmSaO3GgBlSxFkwVEUdAy2t 68RurLfRNEFy14NCuGVppokdWyh4lvxNgLBZ4mqh73Ul5wVy6KUamnt2h_hvfCsAskOWhTcwGjKkbEVmAZmqIXxcYek1X6g5tJ1rAc2RVMdURBErgEZPL12tCNJZ5dhgMew1Z2eiv2cE1Vv-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/18NT4oU_kKlXUMJ3fsqiGTRScUREfZd026_LVkya0yApQEf8cMnJ5GyzSNTzRsF38ifQDVq9rU_bvHjL1wNYhTGTVnJ659kv6A_fEpUVtV3BMHauok4Sei59zIxIv9KH6FKoWLhf4O8b uYlpBaTamN OXMPDlyKaIgfTqjPUmMpHSr4i24CnbF2H WHuC ZbwrH6 oT-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/Z2CWZLEVH4ROl _P0Rm2QbPGtSYp3jWJnVBmKd9kP4BQDkoQqBnfH1_eNyVu4P3d3OehsAzf4ZOEJ7BVwdqv4zC2HDb0YS5dNQw7YetMK0iOw5fVadN3CxNfov4NybS11Fu_kR8FQVc1BQog9GA8HoIu4CsbZurX NL_msQyyRzqLeIPcEJEssIBVVY9mMX7gR6Q7f9v-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/IsS_AK46jNRPnXFVX6u1PIobPaP_St1bfxuPEf9Z1dDTJ_adBbnj94ZGOebgJSMSZTdejuQ0LXMR99XmIsA87CSqKsuqvxl4xm93arzHPEsze3 mR0e E0Q5igzha0wV PrQULbtj3Znk0wHku7o8BU2TNkal9IWN80Hp BjRMbC1azkPdUJ7bsflRJCbznpBPSRpCFk-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/LVwDvco3gL44vqnT0uq0OEMiX0mbC8QdZ2cQq0LHdQ u oVrgfPMUJo2NhLqpVDjS7BTXtsWSxbNosFNBF2HZlIvfWPhh0Hqd5iwFThI8OkMbnLSDzk58zaGSNRdmfeqdz7pQ0sUyrS9VKzwrwEw9o7vKocPVLl017Ln027dt0N9P5Natao_n7ZyykwP3uOEU8co9eV-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/5fPimhtkjItPJEdUBY0T79O0eDLR6f_RAAKv ppLTpk0GXh6kR5sJ68rc8st_gXgIbqQZk6ToFdJx bE6vy0LJPnvfkCKWNoQA9avwXDrLi1HMEy4jRycIbNr 9L_gOKPFSHNkC5iywCNVsplTa8whWwh8tN SOICmaIT8y2 FCO4C7TBoCXMO5NHsAtYbt4_8wKD7Ve-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/1H629zHgO41_zM_lnnZghRH1wWVKd6lTtVEsPdpVe9rkYTUzaeXTZ8rUZXROHQJnfFZBt37IXB1_vqhlZZtKgPE1hnluqleKkLwm_aXx2uK_Dw6LcxFgW8O8p2aQQIdgJDKi8HKNTbxm0zaU8FV wonlm_0sE8TESat1dEiFSpIFQemXpt0_SAEStrd79WeZJz3k3oor-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/_ tyiNrHtIqdpmOcXcTgyHXIVb6IGm5kpqquf7YgAPYfQCSHUfXAPoG8S5rbWPI2SkRliUYR00SOKYlaeK9qaUOoFrDuelyZRGS2MJD_Ul8l7WRoU5Ykt2RlrAStWlDKVpoSHq6WNI rEN45k5jTA4hAncF7YiFunGbDkm1GMNn9oAxE9w79G7w3IsYpl26w7COJbjkm-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/5ORBfKlyYOBDjWMI 5pl9LeB4GGnZLof41OINDLpamcps7rLkaD844j1ZuM78g74ZHRvWkL9chiaS0eQ7VrN2esEOC7xPs56Q56ju53YWHz3ZA6T51r D1KNQ43rEz33cOyHRwB5tlxsHx _ QqDVyMB7hNuLXVr6Ct4LwphTsnIUlaM4DxGeSjp64TR1Kzmsfq0cn8E-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

Latest 30 of 43 download URLs

Remove camstudio.exe - Powered by Reason Core Security