clash of clans.exe

LV-II fungor

Bechiro S.L.

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The application clash of clans.exe, “aufero detego tracto” by Bechiro S.L has been detected as adware by 25 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. While running, it connects to the Internet address cdn.solimba.com on port 80 using the HTTP protocol.
Publisher:
infidus vilitas facio  (signed by Bechiro S.L.)

Product:
LV-II fungor

Description:
aufero detego tracto

Version:
95.59.75.72

MD5:
13154210b55281e642203e8b8fea984e

SHA-1:
d7aeb7acc5b5c9da9a62e7b010b68f0fb77cbc60

SHA-256:
5be1054fe4d94f54e1b4a53236fbd44805a5738383126397e755f034d913f38b

Scanner detections:
25 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/24/2024 8:35:33 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.872462
826

Avira AntiVirus
APPL/Firseria.Gen8
7.11.182.126

avast!
MSIL:Solimba-V [PUP]
2014.9-141101

AVG
Adware BundleApp_r.AV
2014.0.4189

Baidu Antivirus
Adware.Win32.FirseriaInstaller
4.0.3.14111

Bitdefender
Application.Generic.872462
1.0.20.1525

Comodo Security
Application.Win32.Solimba.LSW
19950

Dr.Web
Adware.Downware.8808
9.0.1.0305

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.Kazy.132995
8.14.11.01.08

ESET NOD32
MSIL/Solimba.AH potentially unwanted application
8.7.0.302.0

Fortinet FortiGate
Riskware/Morstars
11/1/2014

F-Prot
W32/A-a1e0d357
v6.4.7.1.166

F-Secure
Application.Generic.872462
11.2014-01-11_7

G Data
Application.Generic.872462
14.11.24

K7 AntiVirus
Unwanted-Program
13.185.13853

Kaspersky
not-a-virus:AdWare.Win32.Fiseria
14.0.0.3013

Malwarebytes
PUP.Optional.Solimba
v2014.11.01.08

McAfee
Artemis!5B3CD2A83502
5600.6960

MicroWorld eScan
Gen:Variant.Application.Bundler.Kazy.132995
15.0.0.915

NANO AntiVirus
Trojan.Win32.Morstar.dhdhyl
0.28.6.62995

Quick Heal
Adware.Firseria.A5
11.14.14.00

Reason Heuristics
PUP.BechiroSL.O
14.11.1.8

Sophos
Solimba Installer
4.98

Vba32 AntiVirus
Downware.Morstar
3.12.26.3

VIPRE Antivirus
Threat.4782980
34232

File size:
537.7 KB (550,592 bytes)

Product version:
52.82.34.83

Copyright:
Copyright ferme

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\clash of clans.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
7/25/2014 3:30:00 AM

Valid to:
7/25/2016 3:29:59 AM

Subject:
CN=Bechiro S.L., O=Bechiro S.L., L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0DE376129471B42CE6BCA90326047A34

File PE Metadata
Compilation timestamp:
10/27/2014 4:54:21 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:KxBt8xZr6zDTMJECEvL+JTDZ3oIjFZ77UARmM7B36:Kx0sDTRJjkF3oIjHnUAZ56

Entry address:
0xDE2C

Entry point:
E8, A3, 6C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 58, 70, 42, 00, E8, FE, 15, 00, 00, E8, 74, 6E, 00, 00, 0F, B7, F0, 6A, 02, E8, 36, 6C, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, FF, 64, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.7046  (probably packed)

Code size:
113.5 KB (116,224 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to cdn.solimba.com  (95.211.6.35:80)

TCP (HTTP):
Connects to api.downloadmr.com  (95.211.39.161:80)

 
http://api.downloadmr.com/installer/38465442/launch

Remove clash of clans.exe - Powered by Reason Core Security