camstudio.exe

Path Quality (Alpha Criteria Ltd.)

The application camstudio.exe by Path Quality (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.giftcapitalbyte.com and multiple other hosts.
Publisher:
CamStudio  (signed by Path Quality (Alpha Criteria Ltd.))

Product:
CamStudio

Version:
2.0.5.a0.1_61161

MD5:
61a47eb707ca9f92296327801ce1f2d1

SHA-1:
bff41e6351eea74b1cccb9bd656172d6e7158678

SHA-256:
b58a1d5e8cff851cf7dc560c8da5dcc8061a9ac2d2e9a7bc6b4436b6023db46a

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
11/1/2024 8:31:25 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC (M)
16.7.17.9

File size:
988.6 KB (1,012,368 bytes)

Product version:
2.0.5.a0.1_61161

Copyright:
CamStudio

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\camstudio.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/31/2015 3:09:15 AM

Valid to:
8/3/2016 6:53:56 AM

Subject:
CN=Path Quality (Alpha Criteria Ltd.), O=Path Quality (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121865442A968BACB1F4EC1956476A3AE8D

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:BTfX+OUopkvQikg+G0uJpX8rv6Wa3BmVTf/XvQyMBTlP0QjcpMXVJoa:BD1pkvqkKCWaYzGpfL

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9327

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file camstudio.exe has been seen being distributed by the following 20 URLs.

http://www.giftcapitalbyte.com/c?x=g373QR73Z7PswlxjNjOBgRyXXDX/UPiXl7IBDGlbjGM=&e=0&c=yTBYEdJ7AU28AeODlFUtP3jQe7iysdTweIC0eTTBO4uVNDn1pY9ysQFa7hgoOrBM8z2lrEeJaZAeq4569Rpj1gj4IDuMH1AtuBQKMpCeK Afr4AToTokEbk7DCmmMiYcZRxvgkfEYQP doAPgafhyVHaJZQfywUdTktZaJPy23Y=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=W Q7RnDGwkcWLZSOwLywKa14wDeAJpcU/iatG7I5BT0=&e=0&c=/PHvhc/C7VX51gjkzIf6i4Dz2Gjl94jWsoAEEBfp6/WdBUMkbVWeIjOpP0mTVbKUOmgmpmCLIAmSCgEiawW0c4lq84YqA1oF05xOSNkoVizIaLhMgOmJw8vK2iQDRTx7HsX4Ue4juC1IqPD0iXXGmm1pooi32Y2 JfXaTb cmRo=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=M ozIF4fxNDTkf1CO89ZggRZHYF8SjEW/rbR6fNmxok=&e=0&c=fhOPVHZRrH6lfILppWInSKSwQp4vYrsfRMT3uULLWCNOPURzmHPd0P b4XRdp2qtJAVlCWk W6RVV8SWRsFfcCuPCab36WmYdcSmdvdAX4jo83aOERbfQvB7yeTt9rFNyBebMviNQYg 1WPXO0H6SIDoA3V5PmCzHBg9p8gWmTQ=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=7ixedb Zsxh3WtH1p4qdidWEWYhboXrygSXs0N/W5Ow=&e=0&c=OXn1GVFJ9XhHYobxcP4ImdEV78lTK /DXM0HFcmYZb2vhy oIpf8vKaS0fpFz2CE/LQirvYgRmsr 5RvzTvtc91iL uBdPEv4UD7POdUSfAIbUMX5OtVQuWDw4kVzbsEB8Pu1LPGDS6MoLskQ45vg/VKDSELEILuDouwU2pvop8=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=B Hi1nYNBIMV59Mv7WbLHiTTY6lM PTuBbW0Y7pTu9Y=&e=0&c=JzWWX958MHO/Y4GXds2MZV2FipOQVbVQf9pVufyjKSHKeUhCO8DEClTXJINfOIRHnIKKJxbJuprg3wY1x0H1Fx7F4SkSlRfZmK B3c2HZvHZmaCFq3h48tzyQ7A/uRmsXHomUTSADuGmehmPuY1Z8YNj29FT0CieWw4pHI62KIE=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=VEypaAvG12iyJiz5gohunPQf5bwMg7U/bIWje5bzbkE=&e=0&c=/qAwm QK/cqmDgTYDwgTTUmuEgwdTqM5icnIGz7NqjGdZROQslLm GCDh/yCesJ1pm4McoIIaK/y0W9HXdKAoenQ1UtC0na1/2 kzeGgrOG/u h51nL6hv otaboS7bp ZZi9pDXRDQj P1adf3DpGk4Bd6DMdYEpf3pCNjWVJU=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=icqmdTLeAEcc6KlgGBr PZWveuUbXGD1rg7eHyiJoIs=&e=0&c=0JCPr2TEaDV6aAiWLlQs7occ7QqOvjG SgNeGjy5Ne2fn pP9ZsS Gs1/03pFcyjaVZ1RQrDRD8Pw3eB3U/EXtfZRTK8N7e1n9YNQ1tOvWLjGsyMHu3DWOnz/oKbYRNkC5rmLtUtt4KhcbDyPkhzVtGJtRq5QnokTpzUbYpr7sw=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=Qd5sUD0mj6a hkySK UW3YTemJYxZWAiqwocQ1wM1qw=&e=0&c=iU4fLXgBua9dfscGDE08hRKBGAIdRfPZTO2n z0bQJMNm6aJ8 rA6jgcPRPvc0T6SIMhY26JCWMXMmn42VAgUPctqk 8X8YP2fBPKHNsovV/tunLP2oz5R3VJ0VQkNZMCT7z8Ilpy37n1GXtXu607pkyl6yu1JMaKPCAWF8 Qgw=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=tgzg8/daeNVSKAeRVLCpscSLq87mrJaJBoMslSXFKCk=&e=0&c=faa0EzScFrhitOvP7tOdg piwZGBdri1UiHHebn4OFrNiBdI1bIrRsI42TYZLg9YtXDhXeRGH/oe6G6xk5hSX5R2A0B0i4vy3WLwFYghs46lrAn8m5kU1NIQ8Sf6EfjyODb9wAObRP0wGnqEPjWhEdqaR7mi0V7Ahn0V72P9Xkc=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=p/wYhmd1d4dz0K7MKOzrbtRUx9imtKCgi0ju0A/FG2A=&e=0&c=v2FA/ru4bRIPUqgVp/1ntArAk167u5vyCk8lITSEQ8qr/Imic6CRo3tvxVrFuaf1/4iNkS8FH40BOO zAVZoyim1lU4Ca2CEwWGUbPJ4WHr8PBQ0yjfC3ipzZ9eeXnNg7HZNOE0Sr3V7o1O0e P85D/GXHi/qCbA L96iiiRzTA=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=RXSOc jzxbrnlSmxQjN/zLZyPHJpYP/DfOGWyAeupzQ=&e=0&c=BKjY2TarNr nZSZyfTVFZyr iqKnUKKuduLRHV2gnrt8q7MlUoRdLK0BxeEv7NPXJyGydivIJ 9ebpCwy1dqwYyUAkt/LNSgFBQTAqA9UqUvEaeasABM2eztMxudApg9sVIJRBUDTpU2rMXNI3rpFxzRKa4exJihriLJY3sO8UQ=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=PerdGZlyuTNMYILca0vvtd8wHjWXZh51PnL5CmNN1cI=&e=0&c=yQ7 SjzW6z2S0FDv2haNAMVtjjoDRbIwF8VVe8I22CIsPxerqvD/LiQ6IgUP9rVmJTb4Gty1OpKDx43SQCKDyEEHAhcPrgf/J/nzcGu6lD4sBaPdZ7qW3ht0sywQuXkfPfqiNVao4V/SR01fGgsw gLuNHnWqj9L/xsi2vzJris=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

Remove camstudio.exe - Powered by Reason Core Security