camstudio.exe

Path Quality (Alpha Criteria Ltd.)

The application camstudio.exe by Path Quality (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.conceptspresentmeta.com and multiple other hosts.
Publisher:
CamStudio  (signed by Path Quality (Alpha Criteria Ltd.))

Product:
CamStudio

Version:
2.0.5.a0.1_60682

MD5:
8e3004baec010f59c512489e50a1287d

SHA-1:
57968f877552420e111888e8e7ba54155ecde26b

SHA-256:
8109b8899b3ac274efd83612d7535e0238d40ff943d38c93b936354c1b8cfa4b

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/1/2024 8:33:49 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC (M)
16.7.7.14

File size:
990 KB (1,013,792 bytes)

Product version:
2.0.5.a0.1_60682

Copyright:
CamStudio

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\camstudio.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/31/2015 6:09:15 AM

Valid to:
8/3/2016 9:53:56 AM

Subject:
CN=Path Quality (Alpha Criteria Ltd.), O=Path Quality (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121865442A968BACB1F4EC1956476A3AE8D

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:A1QPcnADHUAApXfhY/91+Q/C7vMFvaBEi5wsItQ:A6ZepXfDQN17sqQ

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9258

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file camstudio.exe has been seen being distributed by the following 15 URLs.

http://www.conceptspresentmeta.com/c?x= 0TyhTAMUHYWtMbfW/VoDMr1Mi5RGZF4eYV81j2iHo0=&c=v75nNiqAI5ZfeJotLa jZLA8PMYW6LfEuhSEReeSv0Wwc061AK6lBvbZuAqLKD3ky74vJfcc MCEroQu 7 AK5a78qB5TilGzBLGUYrsf2juS/tYbGTMEpAPNali2KgD5LpasPyIQhj4uNaTd2x3vFrxuVrqMzRvn3CfkeS7rs4=&e=0&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=5rz0528bvdVJrPe92hOCv8B5Wvg8NtLqbmf8rNG2Wwc=&c=oTWk1puDsd4p0to5/EvyS/Tch c QdDVTbe5ceQCMrc1JltHSjfRrD6hYvjkbLgetPw wU8aaERxCNfS4Pi vlQ1vgKIZkF ai5XppwkFGx3V1Kh14AM8QQQXlWb9eiAEN5PL rd5Yiip24W bRPS/fI280MdT82jPypxow2QYM=&e=0&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=f6vUzucsMPP1GRNtLhAURXHtxWjxxfdhZr2IaLCWUY8=&c=O78RHTJavo/VK49EmHD kfi51ubEfXJkeqoKVXnQAzR4V nUjguFAAPx9xe3q0ZfGLNelBRTyQ0wfh5LR 4H2/uJJ3fTwJWEqeuorfA15YzpQXjgbsdh zWVq3C3zGXVbKUf7QTOLcp8IsZmEUorPLTbvMNtKD3XZj7rgXh2k1c=&e=0&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=zwuWfCQwwlgveqFEBfd54PZ5tuPf8JtjAiV/wgklCgc=&c=xzsg7SxJuynxDeycrBpbd6Nr4eeHQkJ8FSCvpjSrd5sEi3asvq/wPxZLw9YF3eqlsHZLnIcyPUu9jcm0mO7qlJTQTomzLHLiUleOH agUqL6BAV8sFpe4KJiyFXAGl6MiWtNLHyhXBbRY5MusG3c8/z7Z5e1Sv7rTJPHeqHf 44=&e=0&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=ezgf5vEs3A7V7YxnLe/xvNTtevpZEWOMOYjHCoE6KgQ=&c=bpBAWsSMhYuTI6PMj5IEv3lpwK8sThvxK81 OCrW31VjiDJOwtiKdB9takI7Y2/FCFQG/bVAJ8VtmYl0KvluBIhhcsagNe4QRT GcRnCfb5mRVjb2VmGNjEK7cDnOqka1b9Sv9dbCrvnmEAigKwxLwp d8Sj3MOLwJjFL2HV0kQ=&e=0&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=/0BFI Cy4UD2PpsofDaDHlLo2shnP9RjJIX4 9 Dzeo=&e=0&c=IwF5wiAS3QhJzzzUc/MSuuPxSg4H9DMTK4bh982C8PtzMNQh/InAHTH5PkKocOuoyZjaEDEWLhdePLb8lpp6/6z/MpWcCpTyyjRS/OMxSgkqJj gO NLoRIh3aycjKrCa7809QblDLs8hvJBpHqX7yK33DO9Gxw4Xg4CIAM1q7M=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=iIti0FFm5DzG3OnBHmmMaqcqNTp2xWZQBWf4DRY6SuY=&c=/XGQwge5N7v/MyGkXr0uqBShHvl36p/mSSsmdJVtoZdyqdnjkSGmYdOrFUbCq/L HIpkqcL/abwNn1 bXQGqd0kyWljdyYWn7FWukPK7RiE3U 3EsdMzZHDYg6WtpExpnPkPgAvk6hGxvqbScaF5no9zOHNMD5KkDWao/56Rtw=&e=0&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

Remove camstudio.exe - Powered by Reason Core Security