File name: | LOIC-1.0.8-binary.zip |
Full analysis: | https://app.any.run/tasks/6c13d262-f3a1-4d18-93fd-a2f18bc7cdde |
Verdict: | No threats detected |
Analysis date: | November 13, 2019, 21:51:43 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | C615DA1584CF050CF81A08D40309D735 |
SHA1: | FF00F68B03F7BBC785284ABD95A54D5B98F7DB9B |
SHA256: | B6D6E0D1DCE867836A684A0AF278E46ED4A50BE49A784AB7BFCB3ED59841C9D0 |
SSDEEP: | 3072:n1sQ9BKWms487f1j/XjSGrJmjJ7cAs1QRls:nuQ9Tmd41jfD0lgXQRG |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 20 |
---|---|
ZipBitFlag: | - |
ZipCompression: | Deflated |
ZipModifyDate: | 2014:12:12 21:09:00 |
ZipCRC: | 0x3aef8268 |
ZipCompressedSize: | 103047 |
ZipUncompressedSize: | 136192 |
ZipFileName: | LOIC.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2172 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\LOIC-1.0.8-binary.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
3132 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2172.43710\LOIC.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2172.43710\LOIC.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Low Orbit Ion Cannon Exit code: 0 Version: 1.0.8.0 Modules
|
(PID) Process: | (2172) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (2172) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (2172) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2172) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\LOIC-1.0.8-binary.zip | |||
(PID) Process: | (2172) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (2172) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (2172) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (2172) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (2172) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (2172) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3132 | LOIC.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@azurewebsites[2].txt | — | |
MD5:— | SHA256:— | |||
3132 | LOIC.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@azurewebsites[1].txt | text | |
MD5:— | SHA256:— | |||
2172 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2172.43710\LOIC.exe | executable | |
MD5:E6FA3028CD03318496852718143D256F | SHA256:F60A52512773B52DEF9BA9CE8AAD61144D2CF351F6BC04D1C5A13ABEF8F3B89B | |||
3132 | LOIC.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\LOIC[1].gif | image | |
MD5:389AF7889E62038B8405E883A407F52C | SHA256:64D2AB59CF13621CA806EEEDA91333E5CDF865722209574D6F41C396BD9F8A34 | |||
3132 | LOIC.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\analytics[1].js | text | |
MD5:B66B3B5D54E154C81A50880CDCD7E5F8 | SHA256:DBB67C620EAABF6679A314DB18D3AE43037AEF71AB27422E6FEEC08EE987CC0A | |||
3132 | LOIC.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\loicweb_azurewebsites_net[1].htm | html | |
MD5:E6FC871A88CFA788E5D802B173BAACA7 | SHA256:9CCA30A977359CA1D12B298598C511BE887C01F2C24DAF04D8457C1D366C0A35 | |||
3132 | LOIC.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\ai.0[1].js | text | |
MD5:EC98422B0BCB8E85284B937F9CDF4B44 | SHA256:013819105EFFB1832CBCBCFCC6317B0045170A7F671BD953A21F0847FA1A2E6E | |||
3132 | LOIC.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\linkid[1].js | text | |
MD5:0CC3A63FE10060AF4A349E5DF666EEFE | SHA256:92FCA55833F48B4289AC8F1CEDD48752B580FCE4EC4B5D81670B8193D6E51B54 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3132 | LOIC.exe | GET | 301 | 185.60.216.35:80 | http://185.60.216.35:80/ | IE | — | — | whitelisted |
3132 | LOIC.exe | GET | 301 | 185.60.216.35:80 | http://185.60.216.35:80/ | IE | — | — | whitelisted |
3132 | LOIC.exe | GET | 301 | 185.60.216.35:80 | http://185.60.216.35:80/ | IE | — | — | whitelisted |
3132 | LOIC.exe | GET | 301 | 185.60.216.35:80 | http://185.60.216.35:80/ | IE | — | — | whitelisted |
3132 | LOIC.exe | GET | 301 | 185.60.216.35:80 | http://185.60.216.35:80/ | IE | — | — | whitelisted |
3132 | LOIC.exe | GET | 301 | 185.60.216.35:80 | http://185.60.216.35:80/ | IE | — | — | whitelisted |
3132 | LOIC.exe | GET | 301 | 185.60.216.35:80 | http://185.60.216.35:80/ | IE | — | — | whitelisted |
3132 | LOIC.exe | GET | 301 | 185.60.216.35:80 | http://185.60.216.35:80/ | IE | — | — | whitelisted |
3132 | LOIC.exe | GET | 301 | 185.60.216.35:80 | http://185.60.216.35:80/ | IE | — | — | whitelisted |
3132 | LOIC.exe | GET | 301 | 185.60.216.35:80 | http://185.60.216.35:80/ | IE | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3132 | LOIC.exe | 67.199.248.17:443 | j.mp | Bitly Inc | US | shared |
3132 | LOIC.exe | 185.60.216.35:80 | facebook.com | Facebook, Inc. | IE | whitelisted |
3132 | LOIC.exe | 52.179.188.206:443 | loicweb.azurewebsites.net | Microsoft Corporation | US | unknown |
3132 | LOIC.exe | 172.217.21.238:443 | www.google-analytics.com | Google Inc. | US | whitelisted |
3132 | LOIC.exe | 152.199.19.160:443 | az416426.vo.msecnd.net | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3132 | LOIC.exe | 66.102.1.155:443 | stats.g.doubleclick.net | Google Inc. | US | whitelisted |
— | — | 185.60.216.35:80 | facebook.com | Facebook, Inc. | IE | whitelisted |
Domain | IP | Reputation |
---|---|---|
facebook.com |
| whitelisted |
j.mp |
| shared |
loicweb.azurewebsites.net |
| whitelisted |
az416426.vo.msecnd.net |
| whitelisted |
www.google-analytics.com |
| whitelisted |
stats.g.doubleclick.net |
| whitelisted |