netcut.exe

Delimax Concept

This belongs to a Solimba product that may be bundled with additional PUPs or may be part of an ad-supported software program. The application netcut.exe by Delimax Concept has been detected as adware by 20 anti-malware scanners. The program is a setup application that uses the Solimba DownloadMR installer. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. The file has been seen being downloaded from smugfile.com.
Publisher:
Delimax Concept  (signed and verified)

MD5:
2e1713ef8bab615d32ec4d322aee3e47

SHA-1:
6602c1d155628c72b90d920b0416e6e58a1e7859

SHA-256:
bb18b2efafa42fe9e07a4fd399ae78a22afad7dbf13e1d695a0f4257fe46571d

Scanner detections:
20 / 68

Status:
Adware

Explanation:
Uses the Solimba installer to bundle adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
1/14/2025 2:20:40 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.1004390
761

Avira AntiVirus
APPL/Firseria.Gen
7.11.195.250

AVG
Adware BundleApp_r.AJ
2014.0.4235

Bitdefender
Application.Generic.1004390
1.0.20.20

Comodo Security
Application.Win32.Firseria.GH
20516

Emsisoft Anti-Malware
Application.Generic.1004390
8.15.01.04.01

ESET NOD32
MSIL/Solimba.AK.gen potentially unwanted application
7.0.302.0

F-Secure
Riskware.Application.Generic.1004390
11.2015-04-01_1

G Data
Win32.Application.Morstar
14.12.24

IKARUS anti.virus
AdWare.BundleApp
t3scan.1.8.5.0

K7 AntiVirus
Unwanted-Program
13.188.14426

Malwarebytes
PUP.Optional.Solimba
v2014.12.17.07

MicroWorld eScan
Application.Generic.1004390
16.0.0.12

NANO AntiVirus
Trojan.Win32.Morstar.dkamdo
0.28.6.64267

Norman
Application.Generic.1004390
11.20150104

Panda Antivirus
Trj/Genetic.gen
14.12.17.07

Reason Heuristics
PUP.DelimaxConcept.G
15.1.4.13

Sophos
PUA 'Solimba Installer'
5.09

Vba32 AntiVirus
Downware.Morstar
3.12.26.3

VIPRE Antivirus
Threat.4758821
35418

File size:
562.7 KB (576,208 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Solimba DownloadMR

Common path:
C:\users\{user}\downloads\netcut.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
9/24/2014 2:00:00 AM

Valid to:
9/24/2016 1:59:59 AM

Subject:
CN=Delimax Concept, O=Delimax Concept, L=Barcelona, S=Barcelona, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
069CC4A932F0EBBF4CDE6CBB8C7AAD67

File PE Metadata
Compilation timestamp:
12/15/2014 7:26:19 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:97RqkfrlTY7nRAlivHaf0MSpfHmYim42mp/0AmOOkt:97Rq4lTGRAYe0MSDhJKmOvt

Entry address:
0xD44C

Entry point:
E8, AF, 6C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 60, 60, 42, 00, E8, FE, 15, 00, 00, E8, 80, 6E, 00, 00, 0F, B7, F0, 6A, 02, E8, 42, 6C, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 0B, 65, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
111 KB (113,664 bytes)

The file netcut.exe has been seen being distributed by the following URL.

Remove netcut.exe - Powered by Reason Core Security