netcutdefender.exe

NetCutDefender

arcai.com

The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from www.programosy.pl and multiple other hosts.
Publisher:
arcai.com

Product:
NetCutDefender

Description:
NetCutDefender Setup

MD5:
3166be8ba4b47f2633bd009eae5f4077

SHA-1:
45c34c109fadac7acc6c54364dc4fc358dafc88a

SHA-256:
2f20f5400c1f50659d07ad7adc2c5661963fb4963180426b1e87108ab46d852e

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/18/2024 12:24:57 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Tool.Siggen.6856
9.0.1.0357

ViRobot
JS.A.Iframe.1806490
2011.4.7.4223

File size:
1.7 MB (1,806,490 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\netcutdefender.exe

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:5a+Det8wUgq9NCXA6DGR/IuC5nGm6inXBgJ:Q+qULN/R/aHRgJ

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file netcutdefender.exe has been seen being distributed by the following 22 URLs.

http://www.programosy.pl/.../pobierz,netcut-defender,2.html

temp:netcutdefender.exe

http://download2216.mediafire.com/8b35bv8c8kgg/.../netcutdefender.exe

&onid=10435&oid=3001-10435_4-75453365&rsid=cbsidownloadcomsite&sl=en&sc=us&topicguid=security/firewall&topicbrcrm=&pid=12514111&mfgid=10146355&merid=10146355&ctype=dm&cval=NONE&devicetype=<!--esidesktop&pguid=287690064f8a0bceb69d7efc&viewguid=gzKRJ8PTqZUgI-KBUI6XEBr@MN6-IfkqVT-5&destUrl=http://files.downloadnow-5.com/s/software/12/51/41/.../netcutdefender.exe

http://download.findmysoft.com/2014/09/.../NetCut-Defender_2.1.5.exe

&onid=10435&oid=3001-10435_4-75453365&rsid=cbsidownloadcomsite&sl=en&sc=us&topicguid=security/firewall&topicbrcrm=&pid=12514111&mfgid=10146355&merid=10146355&ctype=dm&cval=SPIGOTWIN&devicetype=desktop&pguid=0b5dbeada433dcdf0d2f2421&viewguid=aqQMsgAl15PVQblDtqmsGwhxNgPfT21nS7nZ&destUrl=http://software-files-a.cnet.com/s/software/12/51/41/.../netcutdefender.exe

ftp://10.19.10.2/DATA-UCOK2/.../netcutdefender.exe

http://202.170.126.68/.../netcutdefender.exe

Scan netcutdefender.exe - Powered by Reason Core Security