manycamsetup.exe

ManyCam Virtual Webcam

ManyCam LLC

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
Publisher:
ManyCam LLC  (signed and verified)

Product:
ManyCam Virtual Webcam

Version:
3.0.0.91

MD5:
c471681a3dc68fd027ccba47dfe8800d

SHA-1:
1efc33dae08ab754ffabcaf42241dafb3627fc37

SHA-256:
6ec4b5e84cc8bff475b57c025c58488f9215214fda17fc9e38e0894512d93ea4

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/18/2024 8:01:56 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Bundled.Toolbar.Ask (variant)
8.9511

Rising Antivirus
PE:Malware.XPACK/RDM!5.1
23.00.65.14308

File size:
11.4 MB (11,970,272 bytes)

Copyright:
(c) 2006-2012 ManyCam LLC

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\manycamsetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/11/2010 1:00:00 AM

Valid to:
12/1/2012 12:59:59 AM

Subject:
CN=ManyCam LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=ManyCam LLC, L=Cupertino, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
448A3C314387BB9F14621500150B0289

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:a+ZGzB0CQjZ+oYOjjeACi1oR/NmX/QZHyg1dRYD7R2YPIx5+ZGzM:a+c0CKxYpAC6k/gQZRXKPm+1

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file manycamsetup.exe has been seen being distributed by the following 18 URLs.

https://dw.uptodown.com/dwn/g6xg-WWka2oPge59GgtlumfFIBBHQfzDs0gPf4jaarovqJfcjUM5Z2wE07O2V0NbusBkTGtA7BqVi9MR8OLXMrgieLaLP-5wI8QvNrtN1VDmtlVxzHXdvTUDw6IOTxv_/RzqzpcHvv4e5UHkVxUQHBOlj2xOQXs0NGQWhutUXR4GXXLD54wFJ7ks8W2Z9952qvr7MnoA0mKsyTJnA_60514wPy1h24SfrBkXR-pB9DAaKZrceNT7C6bhHUnv76gaw/VevQ71xqf9z9FSsoieneafW3sXkm1ELEcFKrgM5yrQXcHLhxrjedHCL7nPTcNX7ZnvuGs9SSOYQWEXhmJHHgC9SbEW1Kr0chd23A8D9ug0HVrQ0yJ6eCOJNHaEgfV4Ui/.../

https://dw.uptodown.com/dwn/jA3CZkVkdvcedljzfB1hO385XNjufydXp6s2mze70VLMgKpcqSjgXncjPXR4gaooj83999amqtytpf2KkorKEmFWOcuxygBWUUIj9AMqFhs6cPvUGqk-NJOcL-ZRnkwC/0ko39HRUr4y5bSeFoPGcWYxeGtX5kFrrje3bf5C1LEG0jz3eEcvqjQHPz041aGUYfyrAeiml-WyFFSksutBmkPwas6zx3YzJr3_sL5nCCyIT0O3D8EFR9H0atO1t0kEn/k3Y483HHwb-hQ-4ipTtX4P0jHG2JN5lDuwIgpvDFjcCzKwDyv9ZiKw-BnMMmtJleYOF3tikTmdIFffjX33wUXyrwKjulMspqP1nOjNUdJfw6tvART7kNwp1d0mHPgzXs/.../

https://dw.uptodown.com/dwn/A2kIhpGKvVvkAbc8ay4CKYrE698PqBYGGph9Y92MoBpAJ-XlOMYhQBzfOqL7d5LrZj5YlEjZBosqHdLAvKoVOhwhumsVAZZj23Vchh0941iJwtZhyewPlLV782fgdZcK/vg5XOl_Zd_8uupBM6A6bITDBd6EY_ucCj6LCV8EDl0wvwA9lelGdD16ZJzuorbLztl4ytDVqIGA_z2WBVmSViesLxA00YOKtCCdKbiCVHDn58P-igz_x2GSHSefmcRMn/PEi8SaXPxyS7EroyCZvag6VIQ0pQO3hiGEYIm-jpXqY4ImbVm5Q2M0wLAbNKH0HoNhk1QtVQdMOgByKaqwEG61pPsiOhQgeZChGGL5z1T2h3RmJZH3dYeXe3MrRj8hQO/.../

https://dw.uptodown.com/dwn/HlgSOQNGchJKQ6a0xinGKUqYDSxsJJ-8x8NVLnFJJacy0EMQT6lKJg0CoocP0Xj-AAk6ye6CvMwiTi_nKYI_QE6Dlm0OXx6k4OUbU39Dc2GmALuQEmyV_NbwCZc8o8yp/7QeQAu5dx-4MkbovVdzZ8pZAYa_FB8kiauW_-OylEcyeYnhT4tr_V5Hz-TcDPYPUYJM4oCgyvU7Cw2Kebm7t1UihmHPnCX_u0wqabnQmI5-HBQtln8i_o9HKHnXhBHRq/.../

https://dw.uptodown.com/dwn/C-PoWUwwsS7KVLOlvMgQsIF9STBhl7NYiiz9pqAUGJ5aBXSPalsUQbwS6cgdul1eTGTze1c_IKsx5ZpnViAYkQYE5BtzTxpMwTRvtCUuZA_yOYTfyH2Nb0XYHbihWSho/tX1D508c2vB4b6h53MiHAv_oCvJB4bSta0wY2j8ZNNaL72npaX0xDtlqS_eeOWxjIOAHf7-dIIbx7qeze4L7eXYzcgwRxlrd5U5oOUlf8cU7JTKnCo6GEe3XnbklbOSB/Fe0XYbnNQrSye9GjCrq8deqF64yhzztPRKp3tuEQGUgEsgmkIoXst0oUEkFZrOtoNN_aWD8PHGQUdXl1Zf5Q49upgpS6d06wYwuMFzYcuxMB1F2GID2JG0Ym1DOuM4za/.../

https://dw.uptodown.com/dwn/Cx8YLMwSDIno_HKS7Ly8ehvOvPK-Q_7kVNuYi01jyuD7pBU5vMjSkfPxvDIu59M4U-dQP8nBmLBjR112r0febYfHHIZ0WZATZortPWpsNMIDfqw3tBTwEyIuBg-rC7Pm/oj2ITy85Y263yd21YB_Mmj-TNlPvlPeilh2JDo6BNymLhKL2y8kLwxL5oM-AunvUSKn1UjXJ8eMp6lDk9SfqzCfL0-n9c94EnYVCoD4WiNVhgb0gA0ONAYdcyZtrEsWm/.../

http://113.171.224.167/.../ManyCamSetup.exe

Scan manycamsetup.exe - Powered by Reason Core Security