camstudio.exe

Path Quality (Alpha Criteria Ltd.)

The application camstudio.exe by Path Quality (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.giftcapitalbyte.com and multiple other hosts.
Publisher:
CamStudio  (signed by Path Quality (Alpha Criteria Ltd.))

Product:
CamStudio

Version:
2.0.5.a0.1_61161

MD5:
680bae7321e05b48ba752dab7c1d262f

SHA-1:
ef48f88e73fd5bba9cd6c886c3fdf0874ce75b77

SHA-256:
8bd127ab5d8824526612822603d3ea9c3e5c35bad0576fd1e441e28f7cd653a6

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/1/2024 8:31:07 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC (M)
16.7.20.11

File size:
988.6 KB (1,012,368 bytes)

Product version:
2.0.5.a0.1_61161

Copyright:
CamStudio

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\camstudio.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/31/2015 1:09:15 PM

Valid to:
8/3/2016 3:53:56 PM

Subject:
CN=Path Quality (Alpha Criteria Ltd.), O=Path Quality (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121865442A968BACB1F4EC1956476A3AE8D

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:yTfX+OUopkvQikg+G0uJpX8rv6Wa3BmVTf/XvQyMBTlP0QjcpMXVJoa:yD1pkvqkKCWaYzGpfL

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9327

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file camstudio.exe has been seen being distributed by the following 15 URLs.

http://www.giftcapitalbyte.com/c?x=wOtE2MW6WCLZ8EA3st4Y iZRoktBxxB4gaw1oUDvZno=&e=0&c=bw1zVFkbddJF9nhP0sFLWIUTDNdYrupgYwjnCVmenlg/FI7udhrrpU40dWE76GKoVE5NuYldfO8PlMGbSVNEr7HFEMapld8mPkYDQ6sJ/3Kwh7QemVptlYMPfrG RQy7EVwF6fqvf7InXZascsinxIepRMwxxLPLM/GTKZCd42o=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=pCsCZiief316GYvXKOWGjimev4K9Kb3G3NGg/U3r6lE=&e=0&c=pVC8tTtyElBmwcmNna7RGW IgnPEQysgJzArF39PM4SrCqQSNz8MgyGv9gvqX71ez4ED2FHH90 1XNMhRvZu53 uVkzLqpOZq667c6L0VgFjRfA9MHSsm1/pxeAlTu1SsGFNa3 4DlDTXu Eo3qa5ZUh6oWmIGJj4aNZfC24rjo=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=PeCWSkqnaZBW1R5m18ruOApp9OasVrrtFbBOGeYyvrw=&e=0&c=7bdjXhjQOcAhoxpqW5uI2UZf93QmyjnBOlAdFmimSqHjNv5i3PckRd8 qjI6TmqnAmo4tN9oH DvTBl1r6 z8 j/EwCKPT0oSomUQcFVdg4Uz84LOLiqby90TLeE pLD6G3ApUaQxxk1G0L3PXSpHY76t 4tSaDESfrQLDr9x2A=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=SSh8/QUQDTzkju0zGmgmfUz6YUglZ3jkvfEvyPu4Xjs=&e=0&c=o94Qrr0bpkTpmni8THhCMcs8/CAVht2/BQDwDpgt/r gWL13otBuZEPobSu3sr2kaQ04nG1oaECV0RQshCKKHD1v/O4PID/RjkP0KoEBcAKogVEOc6CJmFtxNzO1IU VcDXLfl48JvAh74x52YSM0SligN1b/B/ksdMo6hZvzNE=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=A9Gx0 pQp1d0lKphGSeWlBZhpEIVjERMP9bDiFkIwNs=&e=0&c=JC5izHxnIRBzzBpzyxgYyaP6MByKk8Gl7yIYWMy7upCMtJiACNfzREcpQzo5uVNwVYX6ZpDehRePHUHbHZgr/r7m2FO1qupBhGJmwp3YKuP3Lr4Z4B38itExNRcFozaYh7joUrHxA/BSaiKx8gE0K/oGqe8cVsKlcCEIg90abEM=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=AqRTwZSDz9GVNY8i1fJxP4cB7sLfpFoBwk8JFfoJKNo=&e=0&c=CcEUHX/qEuz63aMM5Ltr6PHJ5eR1GHD7Lej5cM7/Y2/dyZ5aBJ8e PXc 5hSRQIS0qpMfHM1zG28sMcG4GoRmv2PrtWDKAbdgubNihCGIHhz9Nbqp1cczXn 1/bqobpBhqnUdb3yHK4PFQXy1MEPHBvoihdzZfevs9RpXF1MaX4=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=Y2vMsQSg9oQCTgvkxbmyOciqulBnYy0z2DK1Hk/OppE=&e=0&c=59Dpgr3xGeEw4ARucuDKvUpmDaUK6cko7ljvQuS3cHfiFLDNEEPahppIN3bZstBbQ8t32MPAshTcEtNt rzHr9MDCr 1Fof3 YldcK eyR9LOElP391f71G1tC1sx2nS0g hkOEt/JSljOj0V7md3qOPB3Q i 86zaQa3MmQAy0=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=0pPo3zsqdLrlXJDe1/UGr8Uzupy6XmXb48M/gKU2K3E=&e=0&c=FEPp3UdleNTryWLSt8DzdEBloAPo5fycBLFwjCuCBceRsLbvdGX34BQIUHzdt4mkJdehNa Aj6EIJvaM0uZ3rRQilXM4M9ywuwklOLfJ/G/oPeh4oC6LuSYzoHomKsielFgnOOY37i9eTaVnil9neX4c9nKUl2M7VNkQmEYqc3g=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=KWOnHRnH EjI0bcp6rm/lC4oPsKMKvFo az2zlTeoNQ=&e=0&c=xjUUG7UQ8RfbqcFWQw6J8 Kn dcMnWquI6jPepKbwKPqsE4glUf4yZJCCHQEox/ZY0Wz5XICjWMSPWumEF30QAiSG0/K/sceHqHTEhZbfKb8VN/9N3301mJByd2Ll0wt1JWlL0wBmtU J2t gXUbO6Z/nkYEXTkHCc7LOWzfEcA=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

http://www.giftcapitalbyte.com/c?x=9jG VeqoefFY8yTrLx8Ojyb3ooJHI73jH1mMHXPi7CU=&e=0&c=oDYduKWc8uee1FgsPq0CjgjUKNeZOjzETY4yYUULleRQ6y 73sQ1rUjyUphE7wS7ZaLdxVxE3mYH1Mrh3KfdOpS4qee26QwpKlUVP1qC9vOS6v4Er7gvm nniSvj3vOZJwLrVIZIZHiTAUJxv38hLDzPwx/717SZmNXx6iGP46s=&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

Remove camstudio.exe - Powered by Reason Core Security