clash of clans.exe

Delimax Concept

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The application clash of clans.exe by Delimax Concept has been detected as adware by 20 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. The file has been seen being downloaded from smugfile.com.
Publisher:
Delimax Concept  (signed and verified)

MD5:
64104a2c1950cd399f5ce8dfa988b7fb

SHA-1:
a38bb94464eea4ce0ee5d7cf37ef94b2f3659464

SHA-256:
cdfd27c6571df9188cf3ab2df9bb341793fa4f4c40560c71be3a2808684e3a68

Scanner detections:
20 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
1/14/2025 2:15:45 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.1004390
761

Avira AntiVirus
APPL/Firseria.Gen
7.11.195.250

AVG
Adware BundleApp_r.AJ
2014.0.4189

Bitdefender
Application.Generic.1004390
1.0.20.20

Comodo Security
Application.Win32.Firseria.GH
20516

Emsisoft Anti-Malware
Application.Generic.1004390
8.15.01.04.01

ESET NOD32
MSIL/Solimba.AK.gen potentially unwanted application
7.0.302.0

F-Secure
Riskware.Application.Generic.1004390
11.2015-04-01_1

G Data
Win32.Application.Morstar
14.12.24

IKARUS anti.virus
AdWare.BundleApp
t3scan.1.8.5.0

K7 AntiVirus
Unwanted-Program
13.188.14426

Malwarebytes
PUP.Optional.Solimba
v2014.12.16.05

MicroWorld eScan
Application.Generic.1004390
16.0.0.12

NANO AntiVirus
Trojan.Win32.Morstar.dkamdo
0.28.6.64267

Norman
Application.Generic.1004390
11.20150104

Panda Antivirus
Trj/Genetic.gen
14.12.16.05

Reason Heuristics
PUP.DelimaxConcept.O
15.1.4.13

Sophos
PUA 'Solimba Installer'
5.09

Vba32 AntiVirus
Downware.Morstar
3.12.26.3

VIPRE Antivirus
Threat.4758821
35418

File size:
562.7 KB (576,208 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Common path:
C:\users\{user}\downloads\clash of clans.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
9/23/2014 8:00:00 PM

Valid to:
9/23/2016 7:59:59 PM

Subject:
CN=Delimax Concept, O=Delimax Concept, L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
069CC4A932F0EBBF4CDE6CBB8C7AAD67

File PE Metadata
Compilation timestamp:
12/15/2014 1:26:19 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:97RqkfrlTY7nRAlivHaf0MSpfHmYim42mp/0AmOOkt:97Rq4lTGRAYe0MSDhJKmOvt

Entry address:
0xD44C

Entry point:
E8, AF, 6C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 60, 60, 42, 00, E8, FE, 15, 00, 00, E8, 80, 6E, 00, 00, 0F, B7, F0, 6A, 02, E8, 42, 6C, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 0B, 65, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.7659  (probably packed)

Code size:
111 KB (113,664 bytes)

The file clash of clans.exe has been seen being distributed by the following URL.

Remove clash of clans.exe - Powered by Reason Core Security