netmonitor.exe

2IP NetMonitor

2IP

This is a setup program which is used to install the application. The file has been seen being downloaded from 2ip.ru and multiple other hosts.
Publisher:
2IP

Product:
2IP NetMonitor

Description:
Проверка сетевых соединений

Version:
1.0.0.1

MD5:
9ada2eefac2bad6e6c14e5c667aa5b1a

SHA-1:
63c8a7f1140c957a09da71db4a1894e2c0c90c29

SHA-256:
022113e86775ed7d600057e64fe5297d670dfbda4ee9c878fd3612cf29e82531

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/27/2024 12:45:59 AM UTC  (today)

Scan engine
Detection
Engine version

Trend Micro House Call
TROJ_GEN.F47V0314
7.2.86

File size:
294.5 KB (301,568 bytes)

Product version:
1.0.0.1

Copyright:
(c) 2IP. All rights reserved.

Original file name:
nettable.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\netmonitor.exe

File PE Metadata
Compilation timestamp:
8/31/2008 5:29:49 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:7ks2itNnAfBDP/fSeORzGD2c9fueTJ8teS/5YPMDdwut:7OfBD/s6D2c9fuCejBuwdn

Entry address:
0x1FB93

Entry point:
E8, EA, 6C, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 08, 0A, 44, 00, E8, C3, 2C, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, B0, A3, 44, 00, 77, 22, 6A, 04, E8, D5, 6E, 00, 00, 59, 83, 65, FC, 00, 56, E8, DC, 76, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, CF, 2C, 00, 00, C3, 6A, 04, E8, D0, 6D, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 0F, 87, A1, 00, 00, 00, 53, 57, 8B, 3D, 78, 62, 43, 00, 83, 3D, BC, 8F, 44, 00, 00, 75, 18, E8, 3C, 63, 00...
 
[+]

Code size:
210.5 KB (215,552 bytes)

The file netmonitor.exe has been seen being distributed by the following 2 URLs.

Scan netmonitor.exe - Powered by Reason Core Security