camstudio.exe

Path Quality (Alpha Criteria Ltd.)

The application camstudio.exe by Path Quality (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.giftcapitalbyte.com and multiple other hosts.
Publisher:
CamStudio  (signed by Path Quality (Alpha Criteria Ltd.))

Product:
CamStudio

Version:
2.0.5.a0.1_61161

MD5:
7b34dc0037f9d94c309345b2d9b24914

SHA-1:
2bf806272f83384670882dd40e7a38e04fc2445e

SHA-256:
e66f58f9571669930fb673f5402890dba8f892e7472eff056142d2ede12d45ad

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/1/2024 8:40:54 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC (M)
16.7.17.10

File size:
988.6 KB (1,012,368 bytes)

Product version:
2.0.5.a0.1_61161

Copyright:
CamStudio

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\camstudio.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/31/2015 1:09:15 PM

Valid to:
8/3/2016 4:53:56 PM

Subject:
CN=Path Quality (Alpha Criteria Ltd.), O=Path Quality (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121865442A968BACB1F4EC1956476A3AE8D

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:iTfX+OUopkvQikg+G0uJpX8rv6Wa3BmVTf/XvQyMBTlP0QjcpMXVJoa:iD1pkvqkKCWaYzGpfL

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9327

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file camstudio.exe has been seen being distributed by the following 19 URLs.

http://www.giftcapitalbyte.com/c?x=q6HxazGLtkHrbRKt7PKezDjfxShKdxa2QF2D79x1Tg4=&e=0&c=65lHfjHz8yDPjxPeH6UPheguJCvFLxaMVb G7EIAV83z6ihIL2FV6MygenNL/KVxu0q2VX735pG vS0BSOl6ETSbTchh5 EA2ib/r6Lsev EnBkSnmyO7pMxHCG1wXiMhdJsNkHuOfQmlWzoWubDsFYYSIXc7MS/gJYPbigx9hI=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=GNbOWe9w/4txIBFFlNwGt8vqk8AsknxeITGDYTdBR o=&e=0&c=Ze6yaPbeL70NlIfdaz96UCg9jyZm402Bd/SGIxj9ucrKHEc/g3MZHNCcw6cY0IoPZyAFgwTOxYwxaIIeEkURU3Uup2Usm0FsDQO/ThewXsgONwUHLnaDQ2TvT8wjqBYwPIjcPIbjL6QkAL5XWhvu Q2F5zXjOXkX5g37P/5Rapo=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=e y6OnBPOcZKA6osMcq4EvO6G1WWpCTN/bSouNw00JU=&e=0&c=LKqc2NaOoGwRVEbPWRbhE0ha r 7alpoPk VMwVZEOdoYjaxmleqRvl8hcZbFFvq 2qRYEtjjwKzAWLbZzTaNP NoTpaR6yIyhAHI2nWdniD//DZAosBc2NYLbsDsD/uV/Q61tS2siM4iJvuGTTE30bClqV/W3uAjXGVwCS1CYI=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=FyZQyUbrtMot6/v2un4GZzk boU3p0k0kK5LkY1Rmm0=&e=0&c=Fvx9687utyFN9KNPBd8x9hBKxzwjWhUbYzfEVeRqmGWsI/x5Bb/IeE0Ru4OPVtFOKqYIACLFs05FnHeLW/UvC8nnZl1MGymdDvG0/dxDNkmXBaLL029IgK5iQG2Gwvzg5d7gd99MxBOWiesE5Uj5oZOxbcN82qKXMmzYL9NHUpU=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=KJUmK nBQ9fwNda4tZKIW8pbo9A P7zdjtYI9lHXHZs=&e=0&c=onzgllW3mgPcXZri1XYeZmWBadYe5 n5JtgcL JVWiM8eGey2H0h7VGKb2fI3Esjf0feRK2ANvBC2kSZPPHVtbvuxY Rs1i8mFTnbUvs9Ku/vWY9CREp 33xd1pu5mW8oqhBQt1QSmxzRhTpV6WtB8pc2F9EIXHd0Geu3XFFCkI=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=yKBiNJQcK0AfQm17uk48Y7oP4QlS51ZMg 1ZOkUA8XE=&e=0&c=S45inOcrndC4VmOeUavGcsO5OkaDwJZhB55UJQ65TKdWmELUcN2Eh9/ZHhlV2P33WoRIPz8SPa7tMmFfEJZFqevhj8t10HzhWmyCmkWtNy2lORSkyqvDVmq43FFImNCu0JH7GCN2D4H0l8JjwyuW7SKf45ck8lfsSUu77/BmeZ4=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=50c2wlQeONaIAHXgDsdV4F8QBcFATQNgzh2 8vvlI5E=&e=0&c=0SrzBeLMM2A M3kup 7Z2siGkUl/sVo59Tp9iCFshwjA4T1IodCzjnpGjajgmDlLylCb2wSHs IWU8ZSnD7SwI8o6ahs7xlCmhQWJ0fVNlPagKrD DYWY7DybDyDYtcJvwVmnn2UCMhjrvu98 cco5wxDnjDMX6ys1GfrS6myaY=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=TAj3s /uS6l1yX0iglHQBy4SOFh7BFmDHjP6TEHqDXs=&e=0&c=GW7w8CK2ko7WTc9/hi9EjJqvGDpqeFyKhL2gT0HOyIF6cumd2EMjHAuynw7fl5zz9pYhekqOH9TBf Kkd SNSbGRQ LIPy5omkP5PDMB879ZwspjA1V Hnt4dlGY tHgNo7vb7y63Qwu1jWUoPVaAowdxaWBfynNQjhsmUXW5as=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=DKpKyC6cFSA79ZEd4wwwnqgjMvBpKCdiLVbwiS15rHg=&e=0&c=U8sa6ZnEPgSfgoWEs8r05E2/4gH5YTF6QrkKTJCJ8ZM7bsOZQj4AAulbHBSVGMEZeAnWcwHD4efTPZJIZyDwOhAxsfdAcgAtsldiqByf0uTJ1V8j1EnTjf0Eb92eK8WgeUqOBQ3vEFwZ AcHjJTQ0mzR k892Z5gqMTlBGN/8nY=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=Ote9jwleTvMjhucwlSUlcmhHpmGlt 6kIxO5Wzf4Pns=&e=0&c=MH0U2HCFGjYtHU8efGwzheCao0QDPnyi2zekc8 ebrXn2t2qGi8GO2O7CIOcx2M00qbwXGtRgTpeiG63J5L u0uUZ5/ANxdq1wehuSZHBV1vu hzNPwYeyBtVUdby9AM7vB3HKgHzCs8HOXmsIe3R8027gQguk/o5H kQqZzRTs=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

Remove camstudio.exe - Powered by Reason Core Security