camstudio.exe

SpeedyInstall (Alpha Criteria Ltd.)

The application camstudio.exe by SpeedyInstall (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.giftcapitalbyte.com and multiple other hosts.
Publisher:
CamStudio  (signed by SpeedyInstall (Alpha Criteria Ltd.))

Product:
CamStudio

Version:
2.0.5.a0.1_63980

MD5:
99c57e2a9b6b82c6a430920a46256422

SHA-1:
ee96783f556d5d6daaefef8ad772e16c2a0a47fb

SHA-256:
cac56f5faf8c063b055ed238f82285995382870336ffef2c5ccc4d4f3a0e169a

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/28/2024 6:48:09 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC (M)
16.8.6.15

File size:
1.6 MB (1,640,088 bytes)

Product version:
2.0.5.a0.1_63980

Copyright:
CamStudio

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/6/2016 6:35:52 PM

Valid to:
8/20/2016 6:45:01 PM

Subject:
CN=SpeedyInstall (Alpha Criteria Ltd.), O=SpeedyInstall (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121A6DC69485443ADA37B28455486E38F93

File PE Metadata
Compilation timestamp:
10/13/2013 12:19:32 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:rElbYOS5l07fR0j/tHeByNcdHzhsq9rS7hkd:SMqZ0TtHuyubsB9kd

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file camstudio.exe has been seen being distributed by the following 50 URLs.

http://www.giftcapitalbyte.com/MHbJePT2aKqX7Wv1NNaAI4_UkjRqTqj4yXptROhUcOQWN3ok8029vNOoaP_RfCuD1CsUsH7JoPopoojEQdt n9HIm6T8skcC7d FQVq46exqfhKIF_uQZfjFCg1w43xzydduEiEUQ0JTU6 saK1ZatEVjcBpjKNgrDfrzncekp4OimCNKP_F_Zjj6hfhTzIlUDt9UX4l-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/xaUp9lZnBL1U2OQtbEJlSgylBUAiCZiYRXtL6yJQqzTXTCnKMME8bpMzAlbtdgTQYkHm04bVURFqULiPH53yama2QTv8a00jWNWj644yIH3I KQALiYfhbRjESqwZ8EVpJBOLXwnMe1mH0ui qyqvKzJqsIDf6 JxKZnDKJf yxkp5M1Dz4HjTEuFYjCtdwUFVraiWHz-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/2ZFnJ3iRJRFRwIJ7BM60MNx Ew0ZO65T5ILgf8f753npXQT2qr InoIglHnfszgGyvAp7JHUnLs4coMZB9dZG35ji7G1d QC9Sy0s_0mknZAxV_v0OIsij3MAhK_73nM1P_5ssv aRymr9BFHQfog995diUvSFZt6Z ph0 sUke2GIiaRfX6Nt9C7gOeLqsI PEuGXsg-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/wjknOygRrlMxASYkRlQUuo99PjJadS1T41DI5VZPhMaEpfbZdW8QB4NgGM6EtZ 8ftApVQKWJngqMOys7wcvgNr7vsvas6J GGIUSsMEvOjDwxlOxzUlmWQkZ_vxJYALHF1v4TAmu 3ujhdRKx9k5eECMAXNvBMeYBWx2OgklGs MTaz0KxE0Ht9gjZ4PXPTa7LUgil5-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/MX6NEp9jW_Vi_9rtKOyi0OVju_ZuCTMw8pT1twVq2_5UzKGPWfOy7hA79oirRtNm6 2wkAvvUTMqIvVPZYd197Tob72uEL0Aqi2QcDuwrONqcje9oBFgz1SKNFH4gsAK2ZYYua 8WGBXjAg7UqJdjwCNuv7RlM6SQciPj0LAQGL7SL9uuWzQSkgQQ0qfJW_peEo_XMv6-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/ll9SlBnhyJRKgriYugkm9iggqYv2h8m3_gXO TYWle58O7em0AsOj5J6IVxuHL1OR5I6FsyPHd7F_IykJvpcN2oO Ur0XRskCL4heuux14Y xgY5U7jGQaST8ZRGpY3SO3lxwp47kGD8 N3sYYR2XdsBYHmqOf_g11 uGNcvnCzNsLaZFHX32HylDuOosYBpLS6iaRGL-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/x_PgHwIQK23drwJDqw_TzNfjmNFnBU4q6xOC fVSHQda4Kf3155wLBSdPamgDR3zgeGen6lzAL3zShVfuLL1IgnFieB33l7sL4klH_PmTOvGEHahb8eJ87HdE6Mgibe8 EafbvqwW b2ZEUT2lH3Q1kIlmDymx2fJAOng_BoTKgnwfTCci6Wqh4KXXwNNtJmvVaqTU9s-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/bXQ8ZJwQCWVIw60FM__qHs3bHH aCCPkqnBEOQAR9IbW6hiWPUgxOm10vnVAJRfz4w O6xv2iuyDRTi WNKAyA8bnMsZz6RfnRFB1wPflumFUAgrzP8mNN5nLZRbfVFf3GMO0K7GIJVt4h4ztV51sk8n5F4ue6_vOP 9vkk_EtzBVHF1hvuEizmQRVS6GMmEV4LhDx_b-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/FrdU7vo7qXTdObchgbSBkBncqxox2oma48YNtLU6jvzxSviBkmqur7pT2Ov0LaGZyYNpDutKa6swAdAs8DA1Svk7WARfsYU A1OXGmPKdy8CWZG2X Boddpgn 1m3hVlc8Kaxo7X89rTrNl4Pzhz9eQjTpzMir4J8rxVTUkHwJaHygFCTef8L8VJglqM_fx1q3xnYz t-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/CJ_YviEaCnx2_ePdjS88pcotOj2Y_2mNTynycAakHDW9lShOiDH1_EonW3oEYeUst1NyMDRN9TnRhuqcp v8w2zCrT9ER_kNDAnd2aYd_PNTG2aLoHU28gUFDJVX u7sj4qj5jc7sGFcmNXjWUEQ7Wi5lAmFOTA38a3mNJgzQI9Tv63BQHg9lNa JUsPWOXvsTY1UtXy-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/Wp0H7AJQgtWA1vFLqrEr Z3JWN5z0UVl_wa4x7sILVQI7B4_e7Xx2wG3RNz0ySKeMAG1VQM5kDUEpvucILi0nWRQo vcI6ssSvyR2nscNPNG7hBQFoGQZ SWhEl1ztj8jdn VHMldlSDVBc02WE2GTF7xD9_iMEYBaBTdiuc l 9djA0yQ6ANm6jGmsRgM9oZzd3_oAT-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/Q6ycvfK9EqR63IeTmZt09_N6SsEo0ekeioEp0xwJBV5Ipq37gazXQF365PpUgTajXXMs6rJoEMMkhFsonakw9M8qUmNJ02NCIu1HbVXnarynavxu_4ZZ8yKtw7vNxhgxtOd8ZMdS CKc gyVI7on3XmNx_EJXMOt1Fvy1i8yz_4W8QEh1Jqrdn LzhmIfxAep2z2 8-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/RoOWcRVTctcVJPKtzkkeqk4fZ46Vj3Uc5_4lgV YVOQRHGDitbDMStrzZIG52G0bNMo7rXW8_zCOdPs_CIZo8t6E8mz4BV_2Z jv10RmKDsOBl_JGh2e7pQPoeACt28RPfojt3mh3VC9ja5xGt3zBZ7bUhfSl7JyXiKmYQL2P3yVYQVJeRTTZRXZ5VVJkenU9uIJJWDO-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/uxZn8ptWKyOX0YNxpkQqd3qRX1IH3hpa7GrGb7n3VnIHh2iwQ6vFmAh1ufoSdh_yhxDPI5CT05uTificdnBiUQTbRjIKE2t3i6xrfIHPCoplLHOgSLr_q1UY9L90 jz R_0N3eRPHqy9Ltng9At44zrVU9Yc WK6T4nwewsQnNQ5WWJ5gXMVVNuAOCVwk_39OQQMDb1C-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/NE3jMxgt6 sIihgO Ge6KffZzzb06hnVOKgAH9iR2YT 1PuLDFN2dv_ u83hrmXyjamKcpI66HkXMUizLT C4fZZFmR2jusSwqMfUeNeAwMTRg67bL_WHEioTGyh OS0j d3ht5354T0Ya8Fy ZnXZfF48fv1iWhP4GMBr7AGj1xqr H9iFQMDEFzB1cfMMynZSEO1Hm1JZ4kO0FGXz7wbCvgkY9FA==-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==-e

http://www.giftcapitalbyte.com/iO26QX7SDkRJkPKlr67nn4wPVQxK_dGVPDGR52KqE4k3 BgUjt6tGTMgjqbExYkbS rgj3Td vd3NU8zD2IgAMBLaAB3JisfU_2sZV5cwjmmvCDQlIwPCeDt8vzWACGNmUhAOeGpCI1IiilmDoTzx3ebzDicTerZWEXrkQspOF7aQ50IIqMaIDeJKBpdWlimvpjn2ZmY2HeBdoLlsfE499YcEAjs8Q==-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==-e

http://www.giftcapitalbyte.com/uqtPhFdVli3vflHO9Ba7MHwjKuIFs83 qF_MbH7hmZe32GERx_bUFjWdOoJilWLmox8YrXW4iJplOIL44lRPBeVB7nk8Pr8icRUiAgQ_oM0vJC9RQYCUITx8 ljavrIRk93XKholjtqvjA xUL6mwRzFd7j3oWK pWAX0WAuEn2aBxieY FZd1ujrNUTKSgT6iRA UQ3-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/4s1j AyoLboDj3cOUNKtR1J9_ELe57 Q2H1Lyb4kZ7MqGr_YO96l F5pA1Bfxe60A3YpaHL6sWLFnflVPlhL_wG1VBCGPxgzCO3fbWA 8rJWiUD1_RXm5TTL1SWKS1oXpl5GTqnOCM6d_E_QmXoeWAgyVXyIWSzm_HFcJgO9uhJ3MF3mSuX5Wnf4TKBzX4SUeiKezB6pVKgH7KugeEaqwMfVZRM5jw==-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==-e

http://www.giftcapitalbyte.com/e2R_25wL30pjQnngcWdXIwO9weYNFis_l DMdLl0oZF_2QaCzL9mL4I3lgWqlvruF_ 9G8Z1MGrcfJ3QhY9r75rgcafVpVBAqI2dvIB4ITYhf6w it291TxTIx0Z4vK3TVu9M8CjTgggo GCujwZDWrSojRjldl_2f__iDxZ_6MIDCDQDl9dNeOL8 0XxDBtMvc8Fpb2Oprq1rjDe8uxlZdWXhBDdw==-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==-e

http://www.giftcapitalbyte.com/tAs_UhJyhlGbp3A gaGA HQF9WWUyLL4NkSwrz0dxsLheMHMI6qU 1Wykgxh8MEFCC0z_ EAVjG7NttjxKht1uQlqXeLHxqHpbKG_Y77JEsXGeGiqDF0S8BrrraHY2W9Gu3xTxLW4 gYfu_6qPhP0MzOLiZ0XjKsRE8mOYPinbxvNpUGuWf1hNzhv1o1FetmQR07oRlm-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/ntrU2VC6Rcg4lttEqX_QeitnOIclTcb17gkzd15RomrvWIMj79iFAhfnjpVaL6EqFLNdmuFsJtm17dyRfnozTQo2lMhWJ0PDWkMiY4PAiSaPvicLdN8CjSy64lgndhVm2AWvsDDJGCAtDlA62_syDpCVtkt2piqoSray2z1decXZ K9eHnrObDGMOXOSvexkrx 7KbLx-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/jd5AwtG9e3owU8q9_K4gsPXJ1Kz8jJg2k4oOInIOvnbgr_NXWBPvZiQu2Z5NeRQnlP rdJ8ELUrJcIwR_uWIeoI wukUu6lj6bBr8rLLdeCfv9Riuc_wIweyM mVbKw0teFbAfr7_Ub4Qy77K2UM05RC0GGPO82JG _czevl 8qSXaDo0s1jz75i7M1bTfxO03VmdbgH-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/Pz96kSvH8MOd18O0udmZ8QRlAdfrvKEchXbj4jMWik0Z_Z1cl EjLptVnU_cVi9xaTXpc8w38LzHYLqPlGpXsIcrNgKCS3aq1WYIiYcAD4DzlHLM8oTwM ci8Zoe s3CMMYiXp9SQkExpx_IFy6 RRZfM7tEG5pFA SJDeBfHo_KL2ERrxYCCFmKp OzSnwe1mNYkwC6-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/_T6vmjRqI0qVPubK4BMaH0gbZTlW5cSikgBsD2S9PnuGwzlSog2vGh6O1FutbRuIia_DnWFecJarPHgUna3dNpgRcQ_JWzNFfNXtCR92bMpo8xUYRSxUz1cReYa8XtQSk7kMqjTSpbilWSBLEAGyZZUlPkHjWMq39ni6 Gsr4jasPeNcSlVPbGmQr8kh4LXgHI98SqDJ-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/A6 ZxPonnt69CFm6BICSh_tyE5VwgZedSqs_KS6k2QNpXhIPvl3U9BBvoFzwuZJaEconc9TQ3DtARl WKWLmBQds5bwRj1VjwMdpVf9I_YpXKC1Mh01cB5ExdVBGLXX6whYQSenitJOKzVjtUrYoN8CDAEMp1zk2E4nbip5Wmj1up 6h6STI__hkQri6_VKKTNBUwLcJ-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/AXkVoIg7k0UJU_V3DnVVezCa3WWDKMf9BmEbWTc8BlMvy8Ax5qHeaAbZg_EgPEzd9dCdutzahLEDAQB_vrFtYtvU4STyImuPHzisV070WLu_kRbvbCxeJTtz26w5KFDMlr6fE94bOKFCkkoUF iPUNRziPO9ZlF_Tj8WlOnjIslajGrZJniyquJjs6gtzRYtrFlSHZ52-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/xXSG cPorP4CcjzylbZweW6LApw09QUtBqw pDadp3M0BOCFeDMiqr0 jg4OmSWXp_LyZv78chG8x6fUBuFj_gh0J4U3PFBazqJGxl8AW554z9WSzgyyA2Qxcb2mvZFRpwau2iROqlRB1xlKRh7zHguOqf_kHAu55OdQQ_feS9skC4M60JQ5H36om2MT2riPiowFQSNhNs5u9cjm8z4S0YB6x r2sQ==-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==-e

http://www.giftcapitalbyte.com/cKnTHmDvcdUf7DKwHOHQNkDKlxBB_0qVX2A6zdyjTSxrkPa5TS30fEaDgYVpDHdMP YAYOQ3Loy3Ongtm6bFW W_fBFXSs6AT1l7DzErM0h02AWAM1NY1PTveLo9G4MnBu AcMfzzBlxBxN7gURAXYA9XXxb Qv0crOqN9HYZbn5tLP6aCorHqfPzm5wAxjUIpwUddRg-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/UldxzzqDnPKLFXG3HAJAQnAlDUrbK3xPeHXp0SaQMtf4tVgaWzlstTYy85o9q3PmqSgS2HQhvw1 Tcq PZMZMnFFPKGjubyja7MHldbOIaPaHkopiwq2F_zLCb0C3TcsQYaGmZXl8z_wNNzSYUdUD s6Xrj0xyAm5KmhVlDlPeqzOEgyRpHpwKOkyzL9bGp3rGirnOAr-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/17i9A1Hm86iEFsoBhLPhR1PCmXSvJz2JedkFsKN3vPg5D_ggNUVSPm0Y1sCFr8Yd6ich1eKcRX1HMlDwgXy5KqbCGXvnLkqAgjhiCAvEBctnncnMAbBbei0iGs5x07Vyc7CoFlfS2nVpcTV7dWNoCOTK4gW2YL5mf8z9IahFPNyD8DswNg1cKN3YfqL6IvDcU6Tg53OKP0O77nHdqW6vgKG5PTAxdA==-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==-e

Latest 30 of 63 download URLs

Remove camstudio.exe - Powered by Reason Core Security