camstudio.exe

Path Quality (Alpha Criteria Ltd.)

The application camstudio.exe by Path Quality (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.conceptspresentmeta.com and multiple other hosts.
Publisher:
CamStudio  (signed by Path Quality (Alpha Criteria Ltd.))

Product:
CamStudio

Version:
2.0.5.a0.1_60682

MD5:
4534ade3318c236e0b7b6a27f9b03ee1

SHA-1:
cfc1b7f42c539c03e43b9f00b24c0de615b4ccce

SHA-256:
eed02e0544bed2f725e2a3a2c0520e41e17e8a57fc65355f03be3330756d4bd0

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/1/2024 10:31:29 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC (M)
16.7.10.13

File size:
990 KB (1,013,792 bytes)

Product version:
2.0.5.a0.1_60682

Copyright:
CamStudio

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\camstudio.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/31/2015 1:09:15 PM

Valid to:
8/3/2016 3:53:56 PM

Subject:
CN=Path Quality (Alpha Criteria Ltd.), O=Path Quality (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121865442A968BACB1F4EC1956476A3AE8D

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:01QPcnADHUAApXfhY/91+Q/C7vMFvaBEi5wsItQ:06ZepXfDQN17sqQ

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file camstudio.exe has been seen being distributed by the following 40 URLs.

http://www.conceptspresentmeta.com/c?x=YFoS7 XsLFLFZnUTHZEI6 W/1SsOkY/QH5k0b3J1 Vg=&e=0&c=Sb/FJavlXafPjWCImVDriEeCiUTWPPFxoDzcJdqaFkzvz8S8cOzY5SjUe2znJQjGFvvuWf3Sg35RSdDVxg7IIfKpm1cpi7NhXJs14ClBMGoVpOqxyu9LCs8ftlTyHBweKKQ7xxndzYPPZrP1aATg0hqmBRTnU5XFrJQgojrvQRI=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=KJQUSzAIw6eoSN5JMwCfYDnOQyAZDkqerG9qmlaXCmk=&e=0&c=dHJTMXsodExYNf6t72Ey9aaMzpMGMd/Tf/5jC3heoEuu/X/F04e5UJP7VDL5RKB2FerhTvaOcXy/QCtTk9KXJe0Z5jUyGKY9WhxEz UG1EEUmc2tw6uIYY/OxYFwGYsKuGGEu6Pz zelBevNwvWrXF47eXtJadbsAOlGjoeDajI=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=w37zpvF82tyvqfWR8CdUpDHIshSrSZw8y7ickfApyXs=&e=0&c=zR8kbkeBjEJleYkx6fvlOjauUOb8YWOtOBNR1/U7aKQ9APH8T2Wgev2Ksw9ya4f5eEWgNgiiAcoQO/hKxQTOWmBQXiJXZJpOIZDq6/6DsPHxlGG2jbPdVlms3X9cveMYcUv43E9uS3Fx9/tm8a6zabxcp/0pWgFe2ptoMrrt8ag=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=RxRX4DVek5O3d3lOoPtaOyrGwKy1UqHJcHYMBp 7LyQ=&e=0&c=qnSdl1eBb7vBtzTK TxOmNgkx6UeWFa1moPTKrFNKWb0lT ogPWU Hjg2GsKsHDUnSLYkjFKqFcGFBSMRYRg /I8NwJDQlkvFWqP ZIjFslbtamOeFfeD8fGZldGOfhmt7vMGQUg// 0nbSvDrbXdMteqcZQqSnPVsxMKVJpXYQ=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=gLdP30N007yAPYuUIl7a/HqqO3rrg4zEZF59nwTwh2c=&e=0&c=6 iRPKr/4ZQT8dkJbRYIEpJKOh6xLoYIgQTgjTgHNfJwthXzGIi8X2X4Kkp4/BPNRJTp8o/EMg0kR9ZCHoWiA3oA9IDywOSz4 LGj69DZ9BKQvrUuYgm/m7kqlxM2ogWQctt/8fQEdc7P2A6KX R9MS XBPRmKVa/eyEY6NA6Ig=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=gMnJilA9ex78XPIoubJDQ3CKj1LVFDXlcPGT0ajm2T0=&e=0&c=xtRvsr5/mHDPV9Onp0ZYnpo l0VlzMVaKo83QxCyBHgan6Y42g2pRsCmdvP/67nAQb4PVRfjYRKSCeOUIzAYCt5FoPRzEYl5hKXfraM1C6U9dNgO9VXWTzckpOQgRvrNxJ4ZeT14nuhO9AEt3iaT SH2P3exqvLupnW8cYqO9OQ=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=jlNJP3jii1GqBjC3JMO95p2wGHcQbpeBWkyq/mRyn I=&e=0&c=taucKgFotkw7pycrj9yj2vr5K3OzA3jo6lskGeFy/zhhKdLu6jZ0q8MXy5BB2kCpV EKkXAdZE/Sb0yIr3iHauW06ZqsTM9J89cH5/TzseP8y1DVIHLj6G YFWAOlD2t RQcZBzFJP0BhpZk1QLnBxgaq/0kS2Shi7LQtFC1f7I=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=R4Na4Wymtmj6GUqhD/mGoY5HoCih9LEvygfCFNAQBuU=&e=0&c=AiAWOZ ZBRglUTJVfqdm2ZPdoBW3aJTX0Vq63kavEsDGTjZ83cTK7M9qr fd5aYiAxpY21xmzROm4ElAZSDsLCKPm 6YOQiC1kLQQtPr/81Wzo 6mq4cwsl7BpdyTtuBxCGpFZmGtgj8D6eg0ITMOM2pCXbhQVI8E6mAmTS5poA=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=p2wJyAhZ1xkBE9 U8pgxwPh25hPVPJM4sHdu0UYAlM8=&e=0&c=pQ9hIF3SArd4bHBiGkKhOEdqmflff4vQJFCG8IkZvWFpaCyaAcaVcGDxk2eScWNxrC2f nytqA5JqDNfo0J62LhJREhZX1cPfye/L6D5QR fWy4E1OQfQP29am2e4rhph6Keo36ezdzKuneWMD3/uEZY07BdVzDSl /9cxf134Y=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=4 lu8hJjwdHlvqTq8EbFY1jhhyla3lC5l9UufWpPATg=&e=0&c=hqDhoTVbI11Pu szhn0wn13fNuErFA/2WUiRG9w78vMEZs6dKreXhdFL6p 3l4JG1U4SLypNIIEFhap3QpisK//M1dg825PeoMPnefz78yBt9t6UaK98WWtBVcvbCMOszkH9UiuRQZ U7f2nGiy csPqqgSZnfrVM60ksoxM2ZY=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=sgU2xyNd3Q14h6STMpfJLv3njm9PHfyneVh8YXdJyk0=&e=0&c=0j LyBP29VB57GReErmXNXqj0uqHKDRJXrGiD/I/ysyJV7oFbrdhgc5uNDPXcmeLXqpXV FO9pQCVf3T MeO6mk8bgZ8JwBEUrTQkwDRR Q34LK2aNEBalz0SJLydf/CZam8pFv0pXNnt6TowjgZj/RlAAEl4StX8HSzI5rptUM=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=3kgFEFrAuPHlzmAPuVlKtXg1lNDGIdox4pyESfvYo0g=&e=0&c=T6VBn6gGLjT2Cubw0UJyj45DinlswOm52HilraDHg5mI0iCuOjSIbKFpQF 4wdm04zt6jEnkeT8HgWVMjzQO4N8mp8V9 OBEpYSB5HZMOxhJOJpQI1F0AbMVJEVlSyjOrX6utYs9Z ua3YBxv3EONqz1bmVUYhRg4fbKTv0Lv/g=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.conceptspresentmeta.com/c?x=9A3Y2sgM7Xnu8qgEKKXY ReyddEjzkOK6eIf kt/Is=&c=Wt1ZD3rIdjCDl4f/zlefDEICahZquB/WPLOnRDtAI6GA9A6fv98SRPxDVlj1rPTHXGdjX on72CZQ6V7wQL7WB6ka213lXVhJ0aT1dIw7 EHU3FW1BCLyYJ1ltm5XoRcrsaneP95k1FYc17RW78ZGxpwscj47hDZTEdGMktBm/4=&e=0&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

Latest 30 of 40 download URLs

Remove camstudio.exe - Powered by Reason Core Security