Threat Database Hacktool Hacktool.TelegramHack.C

Hacktool.TelegramHack.C

By CagedTech in Hacktool

Threat Scorecard

Popularity Rank: 18,806
Threat Level: 50 % (Medium)
Infected Computers: 19
First Seen: March 2, 2023
Last Seen: June 27, 2026
OS(es) Affected: Windows

The detection of Hacktool.TelegramHack.C on your system indicates a potential security threat that requires immediate attention. This hacktool is designed to compromise the security and integrity of your computer, and its presence can lead to a range of problems, including unauthorized access to sensitive information and disruption of normal system functioning.

What Is Hacktool.TelegramHack.C?

Hacktool.TelegramHack.C is a type of malicious software, or malware, that is categorized as a hacktool. Hacktools are programs designed to bypass security mechanisms or exploit vulnerabilities in software and systems. The specific name Hacktool.TelegramHack.C suggests it may be related to hacking or exploiting vulnerabilities, potentially in messaging applications or services, but without more specific information, it's crucial to understand the general risks associated with such threats.

How Hacktool.TelegramHack.C Operates

Malicious software like Hacktool.TelegramHack.C typically operates by exploiting vulnerabilities in operating systems, applications, or user behavior. It may spread through various means, including phishing emails, infected software downloads, or by exploiting weaknesses in network security. Once installed, it can perform a variety of malicious actions, such as data theft, unauthorized access to system resources, or the installation of additional malware. Understanding how such threats operate is key to preventing their spread and mitigating their impact.

Symptoms of Infection

The symptoms of an infection can vary widely, depending on the specific goals of the malware and the systems it targets. Common indicators of a malware infection include unusual system behavior, such as slow performance, unexpected pop-ups, or changes to system settings without user intervention. Additionally, users may notice suspicious network activity, unfamiliar programs, or data that has been altered or stolen. Recognizing these symptoms early can help in taking prompt action to secure the system.

How to Remove Hacktool.TelegramHack.C

  1. Enter Safe Mode with Networking to limit the malware's ability to spread or interfere with the removal process. This mode allows you to use the internet to download removal tools while limiting the execution of malicious programs.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated with the latest definitions to improve the chances of detecting and removing the malware.
  3. Uninstall suspicious programs that were installed around the time the malware was detected. Be cautious and only remove programs you are certain are malicious or unnecessary.
  4. Reset your browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the malware.
  5. After completing the above steps, reboot your system and perform another full scan to ensure the malware has been completely removed.

Conclusion

The detection and removal of Hacktool.TelegramHack.C require careful and immediate action to protect your system and data. By understanding the nature of this threat and following the steps outlined for removal, you can significantly reduce the risk of further compromise. It's also essential to maintain good security practices, including keeping your operating system and software up to date, using strong antivirus software, and being cautious with emails and downloads from unknown sources. Preventing malware infections is a continuous process that requires vigilance and proactive measures to ensure the security and integrity of your digital environment.

Analysis Report

General information

Family Name: Hacktool.TelegramHack.C
Signature status: No Signature

Known Samples

MD5: c7c9ff34b56993d53357bcbb206a33fe
SHA1: 68059c3fdb1490acbd7fb2c36b0f82a634305303
SHA256: 7C4500D27A2B1364B78CC609825A0B3916C15BCA02F3AD44E4C8EF24A26CC1C7
File Size: 388.10 KB, 388096 bytes
MD5: c5c50c2b67c8f9a07ba5f02d79a4c18e
SHA1: 401b3b76d1e22aea02d3c434211c41bba6f620a7
SHA256: EF0D276104CF78FCB9B79A34AF29C67A90B6E8CC7402A8EC321B4F934025E1D6
File Size: 3.51 MB, 3508736 bytes
MD5: eeb787536c2820ef55bae05cf23a3384
SHA1: add8d9ffc78ee59c1bde5e1edb0c065f219cb0b9
SHA256: 298CE70F9FB97A76790820721D9452BA07C4A4236D0EB368112E68DB7BFB6B5B
File Size: 3.27 MB, 3270672 bytes
MD5: 9e204acd3ef7bac0ac5f3dd8ec4cbb7c
SHA1: 53f9c024f03c007ce1db49a02b2db39d35e340b2
SHA256: EBD5D2BDC7DCD3671A59737C856356828E911822FC171C96F9E3CE91329C07A5
File Size: 2.81 MB, 2814464 bytes
MD5: 043033eb6cb9b319cb95bf3fb0065efb
SHA1: ce461280c076565d48acfaca5b88f0c4abad9494
SHA256: 654FDE3946C7FB2187051E63F8E163A41028F3C1BA6D3DECCB15B1885A9816C2
File Size: 421.89 KB, 421888 bytes
Show More
MD5: f864c8dcabb299b734140e324abaefe3
SHA1: e3585a7d70e0d51e93be511a775dac3ca70a520d
SHA256: 8FFA6B09184B463191558BD8D3FD1130D291339F2134E759E20DD6AC8F05C91D
File Size: 3.51 MB, 3508736 bytes
MD5: c1b9d9b529f1f3fdfd17bd242f312e1d
SHA1: d8aa34210d91e04832cabafd9e757a62e5ead415
SHA256: 8E75808A372A1F08D6188353C5FFC255445CC4936535D02C3F93BC9B7DF100F0
File Size: 350.21 KB, 350208 bytes
MD5: b2787a37a4fda00974852619030b8b28
SHA1: be620bf1bfd2eda1590d8d1f2863c8e297a6a79f
SHA256: EB7C3F6CD33BB625EA83CF86DF37696927F919DE72B48226CFC5CE9BB67E79D3
File Size: 2.52 MB, 2522624 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • GetConsoleWindow
  • HighEntropy
  • imgui
  • No Version Info
  • ntdll
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 5,924
Potentially Malicious Blocks: 374
Whitelisted Blocks: 5,446
Unknown Blocks: 104

Visual Map

x x 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 x 0 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 x x ? 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 x ? x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 x x x x x x x x x 0 0 0 x x 0 0 0 ? ? 0 ? ? x ? x 0 0 x ? 0 x ? 0 0 0 ? 0 x x 0 x 0 ? ? x ? 0 ? 0 ? ? x ? x 0 ? x x x x 0 x x x x 0 x x x x 0 x x x x x x x x x x 0 x x x x 0 x x x x x 0 x x x x 0 x x x x x x x 0 0 x x x x x 0 x x 0 0 ? ? ? ? ? ? 0 x x x x 0 x x x 0 ? x x x x ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? x x 0 x x x x 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 x 0 x 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 1 0 0 0 0 0 1 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x 0 x x x x x x 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 x 0 x 0 x 0 0 x 0 x 0 x 0 x 0 x 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 ? 0 0 x 0 x x x ? 0 x x 0 x ? x ? x ? ? ? x x ? 0 0 0 x ? ? ? ? ? 0 ? x ? x 0 x 0 0 0 ? 0 0 ? 0 0 x x 0 0 x 0 0 x 0 0 0 0 ? 0 x 0 0 x x 0 x x 0 x 0 x 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 x x x x 0 0 x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 0 0 0 0 0 0 0 x x x 0 0 x 0 x x x x x x x x 0 0 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 x x x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 ? x x 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x x 0 0 0 0 x 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 x x 0 x 0 0 x x 0 0 0 0 0 0 0 x 0 x 0 0 x x 0 0 0 0 0 0 x 0 0 1 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 x 0 x x 0 x x 0 0 x 1 x x 0 0 x 1 x x x 0 0 0 0 x 1 0 0 0 0 x 1 0 x 1 0 x 1 0 x 1 0 x 1 0 x 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x x x 0 0 0 0 x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 x x 0 0 x 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 x 1 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 ? x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 x x x x x 0 0 x 0 x ? 0 x x x 0 x x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 ? x 0 0 0 x 0 0 0 0 0 0 0 x 0 x x 0 x 0 0 x 0 0 0 x 0 0 x x 0 0 0 0 0 0 x 0 0 ? 0 x 0 0 x x x 0 0 0 0 x 0 x x x 0 0 0 0 x 0 x x x 0 0 0 0 x 0 x 0 x x 0 0 0 0 0 x x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 x 0 x x x x x x 0 x x x x ? x ? 0 ? ? ? ? x 0 ? 0 0 x ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 ? 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Gamehack.EBB
  • Gamehack.GDDG
  • Gamehack.GDDH
  • Injector.KFSC
  • Kryptik.EFJ
Show More
  • Kryptik.LDA
  • Kryptik.NPB
  • TelegramHack.C
  • TelegramHack.EE

Files Modified

File Attributes
c:\users\user\appdata\local\temp\dwm.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 鐸灅ǜ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateUserProcess
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPrivilegeCheck
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationToken
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserCallNoParam
  • win32u.dll!NtUserGetGUIThreadInfo
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserMoveWindow
  • win32u.dll!NtUserSetLayeredWindowAttributes
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Terminate
  • TerminateProcess

Shell Command Execution

C:\Users\Mrumgmmk\AppData\Local\Temp\dwm.exe (NULL)

Related Posts

Trending

Most Viewed

Loading...