netcut.exe

Arcai.com's NetCut

Arcai.com

Publisher:
Arcai.com

Product:
Arcai.com's NetCut

Description:
NetCut Arp Spoof Application

Version:
214

MD5:
1cea2c2c9658d84a8e5e1207e1780e8c

SHA-1:
dd424cc0f586c745b6c5a3b1769a3d74d162cf87

SHA-256:
56d3226d9712699228adde1be57cede1fd941e06f9d6e68cc8a61431da3cdc3a

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/25/2024 1:05:19 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
hacktool program Tool.Arp.9
9.0.1.05190

ESET NOD32
Win32/NetTool.Netcut.A potentially unsafe application
6.3.12010.0

File size:
876 KB (897,024 bytes)

Product version:
214

Copyright:
(C) <Arcai.com> All right reserved

Original file name:
netcut.exe

File type:
Executable application (Win32 EXE)

Language:
Chinese

Common path:
C:\Program Files\netcut\netcut.exe

File PE Metadata
Compilation timestamp:
8/23/2011 9:52:42 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:+Yc7+LfKeRHPbs/huW1u6JZHzkDfWpOoYmTQAyzL/R:q+LSycx1bJZHzkKE39

Entry address:
0x5111D

Entry point:
E8, 4B, C0, 00, 00, E9, 16, FE, FF, FF, FF, 35, FC, 8C, 48, 00, E8, E6, 4F, 00, 00, 85, C0, 59, 74, 02, FF, D0, 6A, 19, E8, 0D, 85, 00, 00, 6A, 01, 6A, 00, E8, AB, C1, 00, 00, 83, C4, 0C, E9, B0, C0, 00, 00, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 8C, 4D, 48, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 8C...
 
[+]

Entropy:
6.1208

Code size:
424 KB (434,176 bytes)

The file netcut.exe has been discovered within the following program.

NetCut 2.1.4  by arcai.com
Publisher's description - “Discover who is on your network instantly. (IP/Device name/MAC address).”
www.arcai.com
About 8% of users remove it
 
Powered by Should I Remove It?

The file netcut.exe has been seen being distributed by the following URL.

temp:netcut.exe

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to li682-165.members.linode.com  (23.239.9.165:80)

Scan netcut.exe - Powered by Reason Core Security