camstudio.exe

SpeedyInstall (Alpha Criteria Ltd.)

The application camstudio.exe by SpeedyInstall (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.giftcapitalbyte.com and multiple other hosts.
Publisher:
CamStudio  (signed by SpeedyInstall (Alpha Criteria Ltd.))

Product:
CamStudio

Version:
2.0.5.a0.1_63242

MD5:
b8b6b95454230e72a35d480fbb547b7a

SHA-1:
637cdfb9faddce42575403629583abe51b4c5a4d

SHA-256:
d452476c091653699baa6d875279b5bf6aefd16846097e89fba74c41811b123e

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/1/2024 10:30:27 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC (M)
16.8.1.15

File size:
990.4 KB (1,014,184 bytes)

Product version:
2.0.5.a0.1_63242

Copyright:
CamStudio

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\camstudio.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/6/2016 5:35:52 PM

Valid to:
8/20/2016 5:45:01 PM

Subject:
CN=SpeedyInstall (Alpha Criteria Ltd.), O=SpeedyInstall (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121A6DC69485443ADA37B28455486E38F93

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:mbR0DaELULPyWKs2GEoFHzjhSsCbylglmsHZ/w5+WBaNWl7ul:mNjLPyWKslEoFHx6HdwFYNWO

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file camstudio.exe has been seen being distributed by the following 50 URLs.

http://www.giftcapitalbyte.com/yYM5M7B_C51KQQdbCW xr9R_XRcr9qnp0r9XuLGx7_FCH7FbDb Ulkz8eXqdFJFhzDNjkwLrAkTVOt1emxz1sD3T9e1r9OVkuhsSbN82CJNVhGEWcmHwj 4nSttJc1VIoRMAh6TqGSJPoUCJP5izXEsFXg0binaAbyLvxotu7OHDkTP3IF_o78vYXttC3Nl5RFkj MG9-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/ 3CDmqH6QT5rgCfH92S3DLCPcSakIkuUryIAKFOdEIlnt0whWu0xG2CQ0tsw7lJypJpFTjEC45zSbtsNepmVSAXcJaCdyskVEm6 jxcxeHZ4SVg1koB 6jmGS4kJ5NPiRdPo_ Hnoxs6Tywrsmp3H6XOXzKGMsuogJHNdSUzcCk1dlxredsuHhha887hNc2W1uHfEwcy-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/tGPfpQLlCjyVmidH1fl2UV4f yGp4yqdMaHzFpTN63PkjEcDV68qx2tfwTORyjg96NDGg3FW1vj2ClIrZKtUMFT6j9GRLyJI9FCvfwJQ2pSKlthsrIlikjTRZkht2ce0PCn1lr04acSWlXgFx1nUxNsbaRJTCIU0zsY9UZ2sDDPk0wyVhMCUS1gpgrbo52l5ZDXIUhyl-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/7VCNWSFxr 5inQuUMJcZb4PmDwO0t0Dy RBZ5gpvCOjYQKyy45O0TCfTEI0OEk3vlRb1IDZv6X8pgjHtHITlonwMAICJpHAmbHXGkJuR9CcC47w jrAEcoXfdp9j_eyP8JVLK76LMMxM2ReBxaanl4c8kC1q0N0xN29wqX_j7eWPztB0o9YJQnqstcbefrIkWheRdsZy-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/HiyhIjRQynV17kI0pz0zlp_B9QQOkejzJmvT3DZBC405TttomdqFM yHS36E2z3MR_Jwa8Y2KG4q47ZBrn8bGKBvzi7KfSsmAs9LLaPkGKwGQEAfSz1Trkr9wyqoLM5mB5rAs_YeucvTha61C9dKyCt2X9HZdcWckWHtzFF35W4En2iwW8UjU1GSGFUiLsVtWSxiJHSt-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/XH8o4ojymgOi263ggMEEuWGhIaUmvh322zopSXCdSQzJJ7vrjI DSgW49DjiLJq6ueoNJ5_e8DgnCSMr8FV hHb26Wc9TyveQywS5c5ASZGzFb3MHOCr0doU67yK2hH phzDxQX6ZboEELA4vNiq22F6W9Qgah7BCmxT6mWc9k1xO7s_jYqvx9pBw6kreacu6DiPwodm-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/F0cc0TsWmtlvpibypKcqdHduVFa_cOR2tXAJORZTNGIq3dz0ulyKIXU7FN4odSJpSQLevoLMLo_NwHrkpnDwwa_mk3HOCey4y4k16oWGo9Tk_ILkAlwTmFTh6IBXYTLmaIW9 xs90gYl zRS7T5dTQjsDjIy65tUvdUmx6UNVXrX8IfCHD0GN1vNnnd8U7WVfc_xWlqN-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/RIlgwiB8p1oqaQcLckUpVaqE6kI4s1K4_ Fj11jSkqP72BN1S6cd2vpN7rMtI9evEtAwiyKnEYe2N5Ku4 9lOwNVZOa_FmhL86Z9zehT5YuwEWFTYK4LZe0yovPcY29GQia4zTyX7dUUq3VFyT4ADAPpz7SDgcXGg05rTi04o8yj9ae_H5VYz8hEV0cWfSx3rYf8T6f1-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/SEQ1t75eT9PlDLUyylj4a0Nzken QCaLv0ohbdMNlhYj4bdL7AIQ2oR1LGPZEzcdP8dq3OIB26d JU5jDskmwQnjN_6zuBpJfxH54QLsro7Sz60_AsgyPwAuKvWH6hhJ2oFdSkSq236 _vlk8kfY5v20_6qlFfRvHj6ikK_1jQoA 0qD87x7JCjOERrqkUazgdkT5l9E-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/KY2GePaxj4XHVxXlbazZFY5JgJE71jzMqwU2pjv86h2CMM_VBfZUacyZf9SZKjcuGgu41hb8SQ3u5p6kWXCsPBHDxFYliMp3KkVz5gROTeIjCZucqdoU7YXNQn8bJS3C9RnHc6ygHoDeq3zGB5qBYY3n715cPHblThGcHxv wi94gaiANcbX18HrJh5_mheb8cF_9_7B-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/7TT02OT34UvTMI1CblLVpX7a8bHocOftDYZpeegLCHzGrz04MHOKtg9i0y8pB0ukIiZ5_Z6xpv4_sCFDK7fN2BsTvinS1bPEvbXb4rD7mhBxu4ZMqpDooEH56j30NWR_VFn_mSyQG1A2NexenG97odeukkhlSb7MoMr2zsIuyCeuqlQZAtbWC8HcVRMZ5rBnkcHqRFSb-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/oTgnyOiaevvEf3eMql9js74FnF78dBT_1BIsbtcJ 9gBY5eQfaGErGX90VnaihPgx9 Y_tY6LWkO0zv2vrHnkBX LflDGj0SUOQLk4kiHT1lfzOZCmitxpZtXDWka5Pg4rLtJk4jBTyRfKRIB4Lk0t_i9UIEpgPeLeYGNf9sR6t7CUCyJ3vO7TxisJknXAttobeS21Fs-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/ck8GyA_5SpqXO1cLlp cXcpXCnHBBT9A37GTGbiAYiN1FUZOU8VvoPFj97E quelwxjD6ABgs0DEd17gLZ32UbMPxgMYfLovNLxDwXcSLvNhJaR_sp5lk8GtgzSSyO1LPKJJp5f0fdqtIrIZlGQqkAoJWh9JsX6iIa87p5YcCWTuI_jRzViHPmHq7KmwmUFrY9PV8_7h-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/UsGcIt6fAV_IOoeQHFLDSZyMYm2dE8WQLtb0nbPTfXUBy9 BxN S6TItYU4AkBwlI_MsrdxBE3Ny0ifS9XH3YxncFy1gjN96aP_5KghW85jBpdz9EGKHmRuLhko60kc_5ZZ2yx3frUI oDjgDEtats9lpPwFFv2_96 8a244RoT_kBEB5fm8uf5ENzqJdyO2igQhPLkf-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/XmHwKucbr63GcMIA4rR1ZBvv_479Vb5zAFBLUkACD3xVIAms6BIVAPLOqTLASJGIhuZfbhZE3gRbv2LwNGiNLazfpfxsDsxyH79Zm3SEMwM0I3G_NhdCNuQKpWJYNrnqGx0YVgH6CZ7nWnLHwiwKzktCekR2kn_GHV1QtTAUorgAEUNpLIIGfpF jc3VseGaa74w3Hw9-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/LTvutLOMkLjBSD94ZYwzT1TuXZMOMvgEF17JrdnmsHREpjN1ZFTg8oB7iKKqLF 3z8nTts6Dw4wG16VC3vkoZbHiLaoe7of35H4oFgIn7WwNkvlH_IgIX1q8bSMMRI6wHwZZfo3NtY2WDGShm_AYcg3hf6awAC9DiPevhh4DirTLgqBAwQmKgbIaw609X8eWz0tn7CI0-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/Ja6HHQ50_OaJvIDS5P7kJVGMb2utojTM8tB_MtmjgwOB5WHyVhAUQjEUghK40fofj FpsCCGXpy2YJu7GigShC5xQPRGhc CURBpJyRoYB4C6EnGd_v_JvzLv9VF7AKwjJNj9I5U96QL3vuBdO0Hx4vTwup6VAMUq115GuutEgmhkx9BHyMLb9Tm3DLtdfl7J93fTAOu-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/AV_WXCV5E5o7pjnjDj6P_HBb7D5GocFMr6ag8kiYGayeqFZkuZmA8dkRSSwJDzj7Q_grQF0FXP6UTNZbxhxJv6hRfCX6SAstMARvSqhoOu2uZ6mrc5ymQv8idhOHJsArRZG6lbb kkH3CA3cdSM4a6FPSFmBqtnijhG3EPcT4duHXuQQJ1EIsgqW4xV6fceNgK0aVdi6-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/9mHGICFqNDIVxtG_JOCzcsNfuNbhZrNkxNPPbxaOdtXkiDnYn9hDnJWpdNaM_mZGgvPLq4femt8HxLfp0Lu_SzAnnfaF4YUAmdnwLvvyFNPS3FphJJ LIb_mKOS_Z0i2E0_Xr1b8lkhkQRKY1t8jeSreE9ye6NkUP2p7tZkSkrhBtMUUq7MmpxYx3ng644MLqCcJqArf-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/JOBlghCKYUvA_dGOC_Y9aI Ovr_LIbn8jDcugBU8X8Os8zGKN9LTiyTbi5 okUWzh5STTAWSv4i_nIh4tC1oWbmy Um5eRwzqlfmA9EnCEIMmH1whF63K0qPOZSuIgNXpTPm4qLruryX2xZX_0El6n8aAQoLK89M2jJ2XwNotWacKsaTOKrAHFZfXuJwClC_M1jfY5fE-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/V1iTQwJbotuHcXNsBW1 ThcAiogN1qTWWG1VIxn7fw0n7hYC3Ws0Uiai GY_uHXIOHdFwriEAPmOXGfDnTyOH2PTWEroJSNk0gHmO9Whi4458xcx5NWA9Z qYkZt_f LrT8mATcM4kY174nefEcYSdKvvkFOJh9DkgsjR4PjQ2EjVrORjbxkbuRs t TZrgw1CMq7I9K-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/2FAiLLfm6IJqKz3luP5Gsfhdy3bwgRoFaueHvxsi vvnAK17Qy5vKmUA Ppphpea6dVW07n4YC UoP3cM4soaCZitcNfZRn3Hpnp0IkkOjtAmKObPWcLMYMRiv3MuTL5neY eXkwKionqpZaAlvLozrx gELS20HFaIRCiy2tpIyVv6wwYoZbWSGpnyPKZmfY99T5fwL-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/Nm69cYXlqXK8s PwJ5EN0IywxgE4dlvwzfCZWXOk0N7qJP1e6B8VQqIotvSj9YTBrM068yBRd5LeQ681 RBKdFRR4tEBHotNI_lvBJXF86clBRdAXGLilmAhdMO0F41huTPgHthwYa3qCbzf507x6eVMkrWfUMeXqswylZDsiLywtg5xl85aLJhx89Bdp3Y6WgGAAxm5-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/7nxljFnvH8zG4UUSDVa6dLW8QpYssvjrVuzBrLiyBMUi8ze_0O39fKQtcIC_9QZ9YjHbFMqhbxyAvv8Se2M3x5jMuO48dPi6JFXW0bh06FJTdTPLKZbUjkiRUboxSJFXQGjjuLzz3GePSF__wB3U2hEAFZZyRemDhGZd9XimXEMNmNhDqcA0Q9rOzMFSKK586EZtBJsA-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/VATezRANIX TqoegHs8sO_5FiyEGeKMLBqrzl5jzJXj1p0cwz1ny1_7HPr71TS WuYFjzV0nPc_vTyuz8It7fV lw5cqCMAdSdsB5jScOlguHp2HQos9iNE7d5986cgr2CGrtKATeFvQbhU7MgFjpPaaKBrbEhQCKe7x0p7_ rHq1B8i8I njIP94b2bhXHG9u Ve7IQ-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/DRqKOSC S7RqLHRWvF7eIsHrkD_R5REion2XDGEK 3EA85EuLJAqFd1ZBWNypRJWydvL4hItHuXrp0e2Dqt3ALEEer64mmTB tvnt9MboVcaQ_ d1guO7XjOE8pPAwyRBS4XJ01ZxqwKpNvGsUDdaKloIX0EoL H5cEcWUcERb0K2jB4Hixts4rlafVdkP0OuKX48kkA-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/kTYs57p7QWLX1Xx_oB5bYF_KcxudDVFzYN21krpMnA6pQxaKCH4u_dQ_fb3FP1yojHvj2_UjcgKUbLeOZl_P1E8B7Ue8JP67ulKcxpOCT0KaMCJeFrxSjtczXo4WKtf4eFbssIcgQWIbjRwJ4YuMsIFqnwSfmAosfu_v2MbG4_BzdgbUkVzeVtp1 CeKNtPepq2dZ4gw-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/VoOETCvGSQe1qxYoHzeXMqpNfc0IIde4m7dpA9CQGba9CKnQPaKmCIcIfJCOGqxXIKY5Nu37gLKCyz_vZSrPcpjGRmAVZ7mBjJgCMzWLCpbfYLX5zmjcY05n1ucRcVVrI_PUPkcEx9bmdXwS_xRgwPrFC59VQOMePC3s5V8xX7WMYq0C6cdsW2q0eMSErpi53QTJNRbw-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/jfhMzqEOLoGxl84teY_XAoUR12attfJ4ZzY_DDsetIJ8etNOwpz_XSC2El8veDlaWpUN8U_ONjh2532pRbA9FcQWwyQE2_ooVtCNraqzzz_9ODZzvYiwAEsECzv_6enOB_5KhotbtoGrbLXQ2XxuGFpxcyjElVQVBk5b5L5IY0YusHKr5fagLVYEGI7Krc78aRasB7dx-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/aErdaVYbBu0Lc1Cr_ adne1iSXrrWhDPZf 7G4 tUGNiIUC4kpoYYeJzQa6caNHntZGahM0Wk21gsyQt_Rk56otl5EBMT5hvtaJMU2pazp8N_tUra8bvPVwTz3YZ4EhmV2mln0KFVFfpzxOSxxnujGaAz7Pn7c3T9TfD3wwFsWuYpbmBdOIZw99V5GMeL0A4glmKXdRQ-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

Latest 30 of 56 download URLs

Remove camstudio.exe - Powered by Reason Core Security