× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 1b26fcf0da549a47dceefb4e99fd520d63dec3a7cd539d3edcf1d7c1d4a95fd5
File name: LOIC.exe
Detection ratio: 20 / 43
Analysis date: 2012-02-19 08:38:20 UTC ( 6 years, 10 months ago ) View latest
Antivirus Result Update
AntiVir SPR/Tool.Oylecann.A.107 20120217
Antiy-AVL HackTool/MSIL.Loic.gen 20120213
Avast Win32:PUP-gen [PUP] 20120219
AVG Suspicion: unknown virus 20120219
CAT-QuickHeal HackTool.MSIL.Loic.de (Not a Virus) 20120219
ClamAV HackTool.DDOS.LOIC-2 20120219
Comodo UnclassifiedMalware 20120219
Emsisoft HackTool.Win32.Oylecann!IK 20120219
eSafe Win32.HackTool.DDOS 20120216
Fortinet W32/Loic.A!tr 20120219
Ikarus HackTool.Win32.Oylecann 20120219
Kaspersky HackTool.MSIL.Loic.de 20120219
McAfee HTool-Loic 20120219
McAfee-GW-Edition HTool-Loic 20120219
Microsoft HackTool:Win32/Oylecann.A 20120219
NOD32 a variant of MSIL/HackTool.LOIC.AA 20120219
Sophos AV Troj/Loic-A 20120219
Symantec Trojan.Gen.2 20120219
TheHacker Trojan/Loic.do 20120219
VIPRE Trojan.Win32.Generic!BT 20120219
AhnLab-V3 20120216
BitDefender 20120219
ByteHero 20120216
Commtouch 20120219
DrWeb 20120219
eTrust-Vet 20120217
F-Prot 20120218
F-Secure 20120219
GData 20120219
Jiangmin 20120218
K7AntiVirus 20120217
Norman 20120218
nProtect 20120219
Panda 20120218
PCTools 20120217
Prevx 20120219
Rising 20120217
SUPERAntiSpyware 20120206
TrendMicro 20120219
TrendMicro-HouseCall 20120219
VBA32 20120217
ViRobot 20120218
VirusBuster 20120218
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
Public domain

Product Low Orbit Ion Cannon
Original name LOIC.exe
Internal name LOIC.exe
File version 1.0.7.0
Description Low Orbit Ion Cannon
Comments TCP/IP stress-test tool
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2012-01-29 10:04:31
Entry Point 0x0001DE7E
Number of sections 3
.NET details
Module Version ID a738dc5d-52f7-492b-a893-87b70f60f6f4
TypeLib ID 312adafc-fdac-484b-84c5-5c5457e47f67
PE sections
PE imports
_CorExeMain
Number of PE resources by type
RT_ICON 4
RT_GROUP_ICON 1
RT_VERSION 1
RT_MANIFEST 1
Number of PE resources by language
NEUTRAL 7
PE resources
Debug information
ExifTool file metadata
SubsystemVersion
4.0

Comments
TCP/IP stress-test tool

LinkerVersion
8.0

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
1.0.7.0

LanguageCode
Neutral

FileFlagsMask
0x003f

FileDescription
Low Orbit Ion Cannon

ImageFileCharacteristics
Executable, 32-bit

CharacterSet
Unicode

InitializedDataSize
19968

EntryPoint
0x1de7e

OriginalFileName
LOIC.exe

MIMEType
application/octet-stream

LegalCopyright
Public domain

FileVersion
1.0.7.0

TimeStamp
2012:01:29 11:04:31+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
LOIC.exe

ProductVersion
1.0.7.0

UninitializedDataSize
0

OSVersion
4.0

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CodeSize
114688

ProductName
Low Orbit Ion Cannon

ProductVersionNumber
1.0.7.0

FileTypeExtension
exe

ObjectFileType
Executable application

AssemblyVersion
1.0.7.0

CarbonBlack CarbonBlack acts as a surveillance camera for computers
While monitoring an end-user machine in-the-wild, CarbonBlack noticed the following files in execution wrote this sample to disk.
Execution parents
PE resource-wise parents
Overlay parents
Compressed bundles
File identification
MD5 b596e7cacbad1e814b0cd053086c4900
SHA1 26ef60c870017ebc85901fb2fbce740b82032eb1
SHA256 1b26fcf0da549a47dceefb4e99fd520d63dec3a7cd539d3edcf1d7c1d4a95fd5
ssdeep
1536:g9hnd0LAv8k8h/OseMoZKAGRANEiNn8tW6zon4vW48N4Q+X/TsLLbyXPnDlzuZe0:KiLnkqtBoZ9B8ccW48kLcpZi4Vdf

authentihash afb6c89cd21524e953f4a8b1fc15f4809b689161f95729bd25b3955516f8bb3a
imphash f34d5f2d4577ed6d9ceec516c1f5a744
File size 132.0 KB ( 135168 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit Mono/.Net assembly

TrID Generic CIL Executable (.NET, Mono, etc.) (81.0%)
Win32 Dynamic Link Library (generic) (7.2%)
Win32 Executable (generic) (4.9%)
OS/2 Executable (generic) (2.2%)
Generic Win/DOS Executable (2.2%)
Tags
peexe assembly via-tor

VirusTotal metadata
First submission 2012-01-29 16:25:46 UTC ( 6 years, 10 months ago )
Last submission 2018-12-13 12:19:06 UTC ( 2 days, 12 hours ago )
File names HOIC.exe
b596e7cacbad1e814b0cd053086c4900
LOIC.exe
LOIC1.0.7.42.exe
LOIC_2.exe
HackTool.exe
LOIC.exe
2شيس2شسب.exe
184029647.exe
493049615.exe
LOIC.exe
4.LOIC ПРОГРАММА.exe
HaXoRaXoR's IP Flooder.exe
1B26FCF0DA549A47DCEEFB4E99FD520D63DEC3A7CD539D3EDCF1D7C1D4A95FD5.exe
cascalot2.exe
Loic.exe
LOIC-1.exe
2079093940.LOIC.exe
LOIC.exe
يloic.exe
LOIC - Original From sourceforge.net.exe
When everything else fails.exe
LOIC1.0.7.0.exe
loic-skid-virus-dontrun.exe
5a229d59d6fcb7789026.png
Advanced heuristic and reputation engines
ClamAV
Possibly Unwanted Application. While not necessarily malicious, the scanned file presents certain characteristics which depending on the user policies and environment may or may not represent a threat. For full details see: https://www.clamav.net/documents/potentially-unwanted-applications-pua .

No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!