camstudio.exe

Path Quality (Alpha Criteria Ltd.)

The application camstudio.exe by Path Quality (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.giftcapitalbyte.com and multiple other hosts.
Publisher:
CamStudio  (signed by Path Quality (Alpha Criteria Ltd.))

Product:
CamStudio

Version:
2.0.5.a0.1_61161

MD5:
97448a6bfccb93a07ddb55bc8638dd28

SHA-1:
a35dc8eb508b69fa65fcfa7aad852fceb0763967

SHA-256:
248416266d760f55b3de69f68395b2f98706b64f1829f9995896d37cc6889ee1

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/1/2024 8:41:53 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC (M)
16.7.20.12

File size:
988.6 KB (1,012,368 bytes)

Product version:
2.0.5.a0.1_61161

Copyright:
CamStudio

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\camstudio.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/31/2015 2:09:15 PM

Valid to:
8/3/2016 4:53:56 PM

Subject:
CN=Path Quality (Alpha Criteria Ltd.), O=Path Quality (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121865442A968BACB1F4EC1956476A3AE8D

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:CTfX+OUopkvQikg+G0uJpX8rv6Wa3BmVTf/XvQyMBTlP0QjcpMXVJoa:CD1pkvqkKCWaYzGpfL

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9327

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file camstudio.exe has been seen being distributed by the following 18 URLs.

http://www.giftcapitalbyte.com/c?x=Xv6NFSjCv8VPtNBP3dkQh3bgDKgT6V6voFWeQXRFNsc=&e=0&c=hwvrp7Hndhjx/Ed1nvL6b5X0 0lj cd/V/O5/waK46EtqFv8 UqzYJqWQuZaX5BurjhiuTCX7MWXVaUM1wGaMtkL6plMgYpDS2sTC8YWovrihZ0s9HEkWC 81clvM2k7PwkvRY6hCxnYmx2D3Oe2SNkWft8guqaXI40IMEtakDM=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=V WvS0NTtvod8wdkqYZrDaD4cTfIFGVKMRF7 yib8w=&e=0&c=vv3VVONz3o8A/7HNPsXfJ9OKitR33U6kRLZqvZD8xN6W5iK99Qw2qntFstZd5XFb GbYxok2PidspYH v8sXevCCSqC0sB9HEm257TZAUdnBK1hEtMllKSgnTqZWqbzuMqC4oK5baeqDN6zf/A8g9qWmDzFomi1ZI7Fs4H41LOs=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=vkUpd97HvkK/znoDSXGh1QSJwxi3/0cn0tiso4rTUbY=&e=0&c=0cIvJ7HomuLsscyoG97zpIgcAMBPao1u48sgwu54 0Xi3SiQ zL6OoBJrcXsA 1 uqXz5QSHa8o1923elaRblLhoSw pgIJRoVeKyoZHPuzCsZeXljGwiv0OZ5FKvQ7tI2AvX3rKKcLNTpRxKC5OljL/3Dr6xo6qCf9LcKWPse8=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=flY0wtoHTzSrmwOqoM1MTgUKGoQ ab9CGOA3Vjij87s=&e=0&c=sBecf4a7tPTylGiD7tiLUUXed1WSQMsW51 MxjI9L7MGcCh/sB3jQ 3TGDrL7PCg095QDXgTzAQgfTnTfprh25v7e1moFFO 9neqWPkx5VpHu/eMsSzVr2Muf7AjSQjDERyZvibfVK27yhCKE0lAFbaNqFMc/Pxuv5tTNAsrUwk=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=NnWBUeAI8L1zs67PLdYlaW526GHPZgRqJAQG5T3/cf8=&e=0&c=oDYWTQ1Kvvm4uapO4spD5QJyBS/Z/yoC2izlqhtR9nbdTogwgpROaopArVsrJY/W3zL6u8ff7x/qqWRg PlrTHS/DRPYn/2XpuXukwA6Y/hqQcXfaJHUm4nX9Z93kb1oQcX0F6wacAS3idvfMEb8pn IN JCKsOKOuEucTQnzU=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=x2MSKkU2NRuhHlMaYGsKf1iAsLVBPzsKF jpgMVPL2g=&e=0&c=iFT8ad4EcKM1P4C/DAYWyE2uaurZuX3QL9nJFvxp165LILY7olyncVpAkApqo2qeF7bE50FPBzG4ka8ENd0zAZZPA6JZTXA1dzhn5tWS9gAac96xUpPPeZ iaNo9lpezPIJ1b fXgsHXH/VaLsPJDIY222FvbfUCJYOL4XPCTXo=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=8fpefh294KWc0yfzHWiHP1siBUzLYsJLY6LpkBoZ8SA=&e=0&c=7mUjXJUiu7JDUeVYpo3JH7YToEFBpeblzAFXAMK6i0y7fUmVvoZKA7IA8qtiHkHS1bkezDehKqMhwa9McK3L31yVPeTmmjdDbg024AY5XUeq5Ae4qhR/gAe7X/esp3JBMU8iZXzKWT4u7XjOQj7rKNtdGvKzw0RDncpU/z4SxXA=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=gze8wstqO41obntB03knwczKuPzQOoyG7YJA98MwMYA=&e=0&c=Tp8Naph5u4Lj OYB7zmhS/7Im7NJJ4BYeJPIKpLBtzUqFssh uf4m2QibYw7fYCQ4oU9RxicQaUYJZBW2Xz sWx2A90ySJQpdVZYbmpU9hEZ/IOT/lHtCGcWg2H3TtmktsTN9a6Qiorb0HSC4Db/5umQIz63rBBaX6K0e3nI6SM=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=cvbJfV9B8n2zmHMfq6U97sub3hsa5o8pfeEQLke1C40=&e=0&c=yaFCPGnK9mbOmPA7ekwE58JmqKjTdFN8qUie3DUGtLdtv4QgO8PTLOJVJiX9rp7hKPn9jKCEKgJscxDqn37P7dN/5UDtndIuM7qQ92TIIPsf0ueM vJRNleSST/dapZ4Fd/D9iiM/wPWKdAkGHZIV8RHOadTqNR3NEHvFdwz8Ug=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=JgAqMJaBoqNHCn/pf0xpcx6/51vwWaZRxxpwxovfT4Y=&e=0&c=b/xWG6F8fT5kitUIWS70m5W3ZgiyaLeYcrwuZRnQ8l9HQjHysE4OULH KthahpAEnGIrIZ1ik4f9BjyO5S7ekpwcBfROfYh0NbAkhr1K3L0Mkl2VBh//9dgrrgbzRl6y1/lft/1XHJrwrgXHJPkv OMEcTDpRBeLYn395ovPbrI=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=JBe80h7YJrB7bsEuqWnH1ROAANY2Oh2h9AYKoyV6pKU=&e=0&c=aJA/q/QHCRS5lyBWuwJgoCB8zuskX gZLYHe6aCsAeXaOjDQr6lqkVG3ZqzUgttBmeSx hQwMoO3H1791XgfENFi9wDpqqB/6giQl7E7Rmb9 bK1VjzyiJs3yuBw9r/p3/nrG vMMDfIM5moln63Ku6i68sw/BLOGnmQVaIwCZo=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=s0NO1PcWorLlMtsHBdEMBuzubyG6WymjK67ihhp5RSY=&e=0&c=A9YqkEF Ot6raF6DLdjm4WwlSZRthA8vRum1HpmBcq PgKL tP0Q501a7BHUSFAlCIZ3fEB85 zSba0qLdUHt0DtvOzjuS/tGLikj2AXTrWhk3j0fz0LhaXbQqFgqaLrm2 5yxh4QeWP0/jkEFQeZ6BR0OKrGFN5VifvM03ubQ=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=Xc2c4WxoNjq9plfKoP8re494UTSiRZmcbu2kJmFA1bQ=&e=0&c=5 JMMp5dwj8PpIp5ZVQR/vwQErwqnN7zZED3xbOxyi40HV9kxrqX6RRkNJ1WaQj94sRyn7nXiKWKjdFueWcdI2Rcx2tuRHZsRBJs3kpOL87yRiaerMPXsDWxX3fKXEcKwygY 8R2LYxXEOlg852c3R/XA4uJf0cewpHsMs NLrw=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=Aoaew4NRlPxwX/hvR X0YRJnV ld4xba8SpqkydyP9w=&e=0&c=OTWL3q8pLz78qgCpEghdWymiE6zRzzNrx1eFcpZrRONFU1UiR08NkYJSHDl YDfbHTwMn4GNT25sU5 buoZd3mlHiexffe0culFiFLbTuScFGjDfF1ulLCsdkY0Tuu GInGn05JlqqB2szSOFitPkVu fpjs5ummrN/mrDqWaVQ=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

Remove camstudio.exe - Powered by Reason Core Security