loic ddos v2.5.exe

New IT Limited

This is part of a bundled installer which provides applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application loic ddos v2.5.exe by New IT Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from dc758.4shared.com.
Publisher:
New IT Limited  (signed and verified)

MD5:
05cc47d5a5f25f9be55591f0b9e0eb9f

SHA-1:
847e0620571e83cab958c8c8b9f34f8c910bb928

SHA-256:
fddb7c3566b7b9b0c3e4322670364596ffcda5d0fed485b2129e0c099eb6a599

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/11/2025 1:13:30 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.New IT Limited.NewIT (M)
16.6.28.0

File size:
291.5 KB (298,528 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\loic ddos v2.5.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
11/16/2012 7:16:05 PM

Valid to:
11/16/2013 5:30:34 PM

Subject:
CN=New IT Limited, O=New IT Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B2A165690BBAA

File PE Metadata
Compilation timestamp:
12/4/2012 4:03:30 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:vjlmvsEmbieuTEbjxbrrVqFyjDndWMtkUiLODp9Hkn0H9Nr8rb/wNWyrj36sR6:vhmKGeQIxbruM8KkUiLAfPa6fXV6

Entry address:
0x16F9C

Entry point:
E8, C8, C9, 00, 00, E9, 79, FE, FF, FF, 6A, 10, 68, B0, 4B, 43, 00, E8, 6A, 3C, 00, 00, 33, C0, 33, F6, 39, 75, 08, 0F, 95, C0, 3B, C6, 75, 20, E8, CC, 07, 00, 00, C7, 00, 16, 00, 00, 00, 56, 56, 56, 56, 56, E8, CD, E0, FF, FF, 83, C4, 14, 83, C8, FF, E9, C4, 00, 00, 00, 33, C0, 8B, 7D, 0C, 3B, FE, 0F, 95, C0, 3B, C6, 74, D2, F6, 47, 0C, 40, 75, 5F, 57, E8, 7E, 5B, 00, 00, 59, 83, F8, FF, 74, 1B, 83, F8, FE, 74, 16, 8B, D0, C1, FA, 05, 8B, C8, 83, E1, 1F, C1, E1, 06, 03, 0C, 95, E0, A4, 43, 00, EB, 05, B9...
 
[+]

Entropy:
6.3386

Code size:
184.5 KB (188,928 bytes)

The file loic ddos v2.5.exe has been seen being distributed by the following URL.

Remove loic ddos v2.5.exe - Powered by Reason Core Security