manycamsetup.exe

ManyCam Virtual Webcam

ManyCam LLC

The application manycamsetup.exe by ManyCam has been detected as a potentially unwanted program by 6 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from download2213.mediafire.com and multiple other hosts. While running, it connects to the Internet address server-54-230-197-66.lhr50.r.cloudfront.net on port 80 using the HTTP protocol.
Publisher:
ManyCam LLC  (signed and verified)

Product:
ManyCam Virtual Webcam

Version:
3.1.64.4151

MD5:
624c4581f364f09557551e3392356986

SHA-1:
8415588fe650f68ea4044f7d81e155448107ff15

SHA-256:
d5db80f9bd2dc07fa83588ec0843a919252aa907c16b0c33f27d6bfac28fd89d

Scanner detections:
6 / 68

Status:
Potentially unwanted

Explanation:
The setup program may install a variant of the Visicom Toolbar, a web browser extension that may modify the browser's home and search pages.

Analysis date:
4/18/2024 10:31:13 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Tool.InstallToolbar.129
9.0.1.013

Emsisoft Anti-Malware
Win32.Parite
8.14.01.13.08

ESET NOD32
Win32/Toolbar.Visicom (variant)
8.9190

Malwarebytes
PUP.Optional.MyStartTB.A
v2014.01.13.08

Rising Antivirus
PE:PUA.Infector!1.9C44
23.00.65.14111

Trend Micro House Call
TROJ_GEN.F47V1023
7.2.363

File size:
10.3 MB (10,799,192 bytes)

Copyright:
(c) 2006-2013 ManyCam LLC

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\manycamsetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/6/2012 12:00:00 AM

Valid to:
1/5/2015 11:59:59 PM

Subject:
CN=ManyCam LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=ManyCam LLC, L=Austin, S=Texas, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0290E3365D34DCFDF858AFFE04D77510

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:Q1g5ycm0/30NnUvVLvBjRrJZDP4zFWCpEF5ylgcFmRA3PQbR:QGJf3qUJvnJ1PI/piR8M

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file manycamsetup.exe has been seen being distributed by the following 11 URLs.

http://download2213.mediafire.com/5jtjaxfbdoog/.../ManyCam.exe

https://dl-mail.ymail.com/ws/download/mailboxes/@.id==VjJ-fpid_HNtOVqupo-t8lfcuazbT-cT8S4fRMe_UgRKamkCd9dAg09cs3c9T4CEnKrgGH4nkLovJSeSm65J69qU1w/messages/@.id==ACyvCmoAABr3V2DbBwPr6EtTimQ/content/parts/@.id==2/raw?appid=YahooMailNeo&token=zitEzqOML3j84e6ealFTT5U7-km5qEQF52lp7AcCuBbfLbAY6F-qt4h5jl5Ap5Wk_tmbZU_QP6bd5QzJLzvu9w&error=https://mg.mail.yahoo.com/.../iframemsg?id=9e9e8be4-7ec2-bb4e-9929-e2f32a3f589a&ymreqid=58f04841-7b71-ec4f-0117-a70072010000

http://download1354.mediafire.com/pwlp27d2eqqg/.../ManyCam.exe

http://download2213.mediafire.com/dnd947r600tg/.../ManyCamSetup (1).exe

http://download760.mediafire.com/284kkc1j23ug/.../ManyCam_Virtual_Webcam_v3.1.64.exe

http://dl15.afterdawn.com/download/e9be1e7e487db65a413d024ba1745fe1/57f4fd20/.../ManyCamSetup_v3.1.64.exe

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-54-230-197-66.lhr50.r.cloudfront.net  (54.230.197.66:80)

TCP (HTTP):
Connects to server-52-85-35-166.mia50.r.cloudfront.net  (52.85.35.166:80)

TCP (HTTP):
Connects to 32-127-232-198.static.unitasglobal.net  (198.232.127.32:80)

Remove manycamsetup.exe - Powered by Reason Core Security