Sunday, May 12, 2013

LOIC INFORMATION

SourceForge:
Low Orbit Ion Cannon.

The project just keeps and maintenances (bug fixing) the code written by the original author - Praetox, but is not associated or related with it.

DISCLAIMER: USE ON YOUR OWN RISK. THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDER OR CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES.

RESULT: HackTool.MSIL.Loic.de (Not a Virus)


Virus Total:
SHA256: 1b26fcf0da549a47dceefb4e99fd520d63dec3a7cd539d3edcf1d7c1d4a95fd5
SHA1: 26ef60c870017ebc85901fb2fbce740b82032eb1
MD5: b596e7cacbad1e814b0cd053086c4900
File size: 132.0 KB ( 135168 bytes )
File name: LOIC.exe
File type: Win32 EXE
Tags: peexe assembly mz
Detection ratio: 36 / 46
Analysis date: 2013-05-12 16:34:34 UTC





ssdeep
1536:g9hnd0LAv8k8h/OseMoZKAGRANEiNn8tW6zon4vW48N4Q+X/TsLLbyXPnDlzuZe0:KiLnkqtBoZ9B8ccW48kLcpZi4Vdf
TrID
Generic CIL Executable (.NET, Mono, etc.) (81.0%)
Win32 Dynamic Link Library (generic) (7.2%)
Win32 Executable (generic) (7.2%)
Generic Win/DOS Executable (2.2%)
DOS Executable Generic (2.2%)
ExifTool
FileDescription..........: Low Orbit Ion Cannon
Comments.................: TCP/IP stress-test tool
LinkerVersion............: 8.0
ImageVersion.............: 0.0
ProductName..............: Low Orbit Ion Cannon
FileVersionNumber........: 1.0.7.0
LanguageCode.............: Neutral
FileFlagsMask............: 0x003f
CharacterSet.............: Unicode
InitializedDataSize......: 19968
OriginalFilename.........: LOIC.exe
MIMEType.................: application/octet-stream
Subsystem................: Windows GUI
FileVersion..............: 1.0.7.0
TimeStamp................: 2012:01:29 10:04:31+00:00
FileType.................: Win32 EXE
PEType...................: PE32
InternalName.............: LOIC.exe
SubsystemVersion.........: 4.0
FileAccessDate...........: 2013:05:12 17:34:13+01:00
ProductVersion...........: 1.0.7.0
UninitializedDataSize....: 0
OSVersion................: 4.0
FileCreateDate...........: 2013:05:12 17:34:13+01:00
FileOS...................: Win32
LegalCopyright...........: Public domain
MachineType..............: Intel 386 or later, and compatibles
CodeSize.................: 114688
FileSubtype..............: 0
ProductVersionNumber.....: 1.0.7.0
EntryPoint...............: 0x1de7e
ObjectFileType...........: Executable application
AssemblyVersion..........: 1.0.7.0
Sigcheck
product..................: Low Orbit Ion Cannon
description..............: Low Orbit Ion Cannon
file version.............: 1.0.7.0
original name............: LOIC.exe
strong name..............: Signed
comments.................: TCP/IP stress-test tool
version..................: 1.0.7.0
internal name............: LOIC.exe
copyright................: Public domain
link date................: 11:04 AM 1/29/2012
Portable Executable structural information
Compilation timedatestamp.....: 2012-01-29 10:04:31
Target machine................: Intel 386 or later processors and compatible processors
Entry point address...........: 0x0001DE7E

PE Sections...................:

Name        Virtual Address  Virtual Size  Raw Size  Entropy  MD5
.text                  8192        114308    114688     7.59  0d080ec0ea8cc25e0170d587dd63ac47
.rsrc                122880         19264     19456     6.52  f21a95feec6e9209f5fc1cbccc1ed6f6
.reloc               147456            12       512     0.10  825a5e453d530acd3dbd4031046c9db5

PE Imports....................:

[[mscoree.dll]]
_CorExeMain

PE Resources..................:

Resource type            Number of resources
RT_ICON                  4
RT_GROUP_ICON            1
RT_VERSION               1
RT_MANIFEST              1

Resource language        Number of resources
NEUTRAL                  7
ClamAV PUA Engine
Possibly Unwanted Application. While not necessarily malicious, the scanned file presents certain characteristics which depending on the user policies and environment may or may not represent a threat. For full details see: http://www.clamav.net/index.php?s=pua&lang=en .
First seen by VirusTotal
2012-01-29 16:25:46 UTC ( 1 year, 3 months ago )
Last seen by VirusTotal
2013-05-12 16:34:34 UTC ( 6 minutes ago )
File names (max. 25)
  1. HOIC.exe
  2. Extreme%20Ddoser%20v2.122%20loic.exe
  3. LOIC.exe
  4. LOIC.exe_
  5. b596e7cacbad1e814b0cd053086c4900
  6. LOIC-1.exe
  7. LOIC1.0.7.42.exe
  8. LOIC 2.exe
  9. LOIC (2).exe
  10. 077
  11. LOIC.exe
  12. HackTool.exe
  13. Low Orbit Ion Cannon.exe
  14. LOWORBITIONCANNON.exe
  15. LOIC 1.0.7.42.exe
  16. Low Orbbit Ion Cannon.exe
  17. LOIC.exe
  18. 4.LOIC ПРОГРАММА.exe
  19. 1B26FCF0DA549A47DCEEFB4E99FD520D63DEC3A7CD539D3EDCF1D7C1D4A95FD5.exe
  20. LOIC (2012_11_02 16_22_21 UTC).exe
  21. 26EF60C870017EBC85901FB2FBCE740B82032EB1
  22. LOIC1.exe
  23. sospechoso.txt
  24. LOIC.EXE
  25. ('LOIC', '.exe')

    RESULT: HackTool.MSIL.Loic.de (Not a Virus)

    What is PUA : http://www.clamav.net/index.php?s=pua&lang=en

No comments:

Post a Comment