camstudio.exe

SpeedyInstall (Alpha Criteria Ltd.)

The application camstudio.exe by SpeedyInstall (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.giftcapitalbyte.com and multiple other hosts.
Publisher:
CamStudio  (signed by SpeedyInstall (Alpha Criteria Ltd.))

Product:
CamStudio

Version:
2.0.5.a0.1_63242

MD5:
34a0dbbea5a10d2140173f5471e95f98

SHA-1:
f89d9ed46e90eb20fc5326ba850fe89b10fa3a5e

SHA-256:
2d2ff8bb8f08ed4af364fcfde7f5abd4117e59f65bfff79b224f7bc5ad763b96

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/28/2024 1:58:42 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC (M)
16.8.1.16

File size:
990.4 KB (1,014,184 bytes)

Product version:
2.0.5.a0.1_63242

Copyright:
CamStudio

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\camstudio.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/6/2016 4:35:52 PM

Valid to:
8/20/2016 4:45:01 PM

Subject:
CN=SpeedyInstall (Alpha Criteria Ltd.), O=SpeedyInstall (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121A6DC69485443ADA37B28455486E38F93

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:7bR0DaELULPyWKs2GEoFHzjhSsCbylglmsHZ/w5+WBaNWl7ul:7NjLPyWKslEoFHx6HdwFYNWO

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9321

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file camstudio.exe has been seen being distributed by the following 10 URLs.

http://www.giftcapitalbyte.com/EqU 7qas 23oiF53bk8GKKYBNHnbsx poxUS 8hWG3hIcdrDoHmR4Mlcj1MEfhdLT6X0XCGEO1iqRcaB65yijPXvZ0T3dWf8j91sFTIOpAzIu09_1CAwqsX_QR918kn fNWG43_1Ndlofi8X2AiXvh_rwRV6ZMJ8dzvnw_s CoeE8yN_syB ZfP29iPxTpa6Qsk1JWIE-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/P 7WrGxgD0ouldzU BvIL6qcIvbr4v89xyuBwyX7weT7eTaSIIZ1AxN7CXVXng4LGFOzcHvgtDHQ4k0tHucicgquhL1oTwDLOI4zAzwGEgAB9E8i_q6PZYpZeMAap AIA0q7Fg060WQ8jCfqfdxXXmOvsXiL0Bz46SRZfca83qeBAHprpHEzYWz8BsZlAkJzlduVk0iX-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/oSvUM4M_ stfttbKD49i_HuVU60QHFwC swt Kqafob3Ja2wBmB1PG7WbLSkbN3WpkJbhdTP7uzfGVaY1HRcP _CEHBeC32Vi5sy5TCZvXY2wUBqcjSm5S_X55N1FtfYj2YfoCTASfPjybKaf txAdH1ai4gzMtbkCKPV9uO129ke0ZWZlcwsW7l0eaT1FiKtJorbqd9-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/WypokuUEyVzruIcmINtoxvf4 qBwJ4pzOpWrPW8Zm1KVS48Jt5Hs VbTWocHeLO8O4wzAqP0ZGr4Op5JC7t_CbDzudJyoqdfSsdjb4VAfV4nOxjrTaZKW0Q QL6eEcRr5Gefsr8BMIzXafp4Mb7paG_koqCwQP EFL5KQLYCqoP2BXrdrWwzQZUrbwH1yHHJasfZdTEF-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/JyH_f 2s4neaFVfr5zMuaHOPyao6SPbmbWJ9jxpBrlVk85C4jPzXbu2eE21IP5Ixt8yztHOn312AdY 4lAUPfoGbrK Et8wmemtok1Vp8RbtAnCoEQAu2TyiwOkZMZl7sO0LGaJ82bBFCVaB6D9OVf3f8zyPlhl1uZAgSKPfOel6rdytpRwbLasHRE9MHFdaLWcanNZ4-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/Dlnu4kh4JaTEmk6XmTGHkz2xQeBo1GSHwScX3_xvjnOHlP6JypPnElcFOPOqFgSY7_z9sQwNcviJpOwj_ioCkk2kHUWkJsAJDLbXDtQFkFOs5qgnbgaYFA_RRYxKk8wBf5iG5IYViDIUVf1SAOeYrpQekKxCKW 2PpipPx35GtDCkl0wNRnXY0H_ebR4AGga_owcJrUx-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/Qspo yY3Yq9looUewICzNySVaKjddAfbH5GufN_Zit5PWwtI8H0GyHDDKCTlDi6M9XjnUJlj4Tles81PACSm5qcls75axmRgzAHGEwnpHcZnXaLHzB1SjVet4VrFJ6VRJbkkEzYzs6SDujhEvdJibGnH1 x4DyuOYFB45fmk9zSWlnCACOlzqHLkH10lUxvVjTqmNoXb-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/RWaR9lCC6AVSg npjwE9vVK5SC8bJqIJocFSt64I0xh7xXrB6hnhcWrwfKtNXKBxBeW55MPsx meL0bc9UUzvtRJ A0EuU_k_NNPSycwX5fFKgr08 H2b_5kQeIsQFgyR2P7E5HW iRcOWvZsqIzqVCwNe1QNMyY2yL8dvJTXifEhWnvzQ0GGmkbrmsk2W527ajVSN5y-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

http://www.giftcapitalbyte.com/q 6qBMo5JeNY1GonAl3fxFQf_lYcTRyHDXg5Ckewkc_4H28AsABJcUhe8zp8RJ5kRt YNSbIKFWwvUGOS3FX_KZ5UQWRR0JV9t LCyFx8nb64Nv2Rr6q hSkvy9_egJ46O7qKuSTyE5GeikQzXoAsvMFmI9txI7AAzkJJDtNoLEKDsPvSRRMYQ9T7bdP 0Gl2K78DGkx-GzAAAMRtbD7PaUzHinBGEQXBRA4cWkRd6E1tHcgbYzSEZ7dGXVqZJ lTew29AA==

Remove camstudio.exe - Powered by Reason Core Security