Threat Database Hacktool Hacktool.TelegramHack.EC

Hacktool.TelegramHack.EC

By CagedTech in Hacktool

Threat Scorecard

Popularity Rank: 16,688
Threat Level: 50 % (Medium)
Infected Computers: 69
First Seen: August 28, 2024
Last Seen: June 2, 2026
OS(es) Affected: Windows

The detection of Hacktool.TelegramHack.EC on your system indicates a potential security threat that requires immediate attention. This detection name suggests a tool designed to compromise the security of Telegram, a popular messaging platform, but without more specific information, it's crucial to understand the general nature of such threats and how to mitigate them.

What Is Hacktool.TelegramHack.EC?

Hacktool.TelegramHack.EC is identified as a hacktool, which is a type of software designed to bypass security mechanisms or exploit vulnerabilities in applications or operating systems. Hacktools can be used for a variety of malicious purposes, including unauthorized access to user accounts, data theft, and the distribution of other types of malware. The specific capabilities and intentions of Hacktool.TelegramHack.EC cannot be detailed without further analysis, but its classification as a hacktool indicates it poses a significant risk to system security and user privacy.

How Hacktool.TelegramHack.EC Operates

The operational details of Hacktool.TelegramHack.EC are not provided, but generally, hacktools operate by exploiting vulnerabilities in software or manipulating user interactions to gain unauthorized access or control. They may spread through various means, including phishing emails, infected software downloads, or vulnerabilities in network services. Once installed, a hacktool can perform a range of malicious activities, from stealing sensitive information to using the compromised system as a launchpad for further attacks.

Symptoms of Infection

Identifying a hacktool infection can be challenging due to the stealthy nature of these threats. However, some common symptoms that may indicate the presence of malicious software like Hacktool.TelegramHack.EC include unusual system behavior, unexpected changes in software settings, appearance of unwanted programs or toolbars, and slowed system performance. Additionally, if you notice unauthorized access to your Telegram or other online accounts, it could be a sign of a hacktool at work.

How to Remove Hacktool.TelegramHack.EC

  1. Enter Safe Mode with Networking: This will allow you to use the internet to download removal tools while limiting the ability of the malware to interfere with the removal process.
  2. Perform a Full Scan with a Reputable Tool: Utilize a trusted anti-malware tool, such as SpyHunter, to scan your system thoroughly for any traces of the hacktool and other potential threats.
  3. Uninstall Suspicious Programs: Review the list of installed programs on your system and uninstall any that are unfamiliar or were installed around the time the issue began.
  4. Reset Web Browsers: Resetting browsers like Chrome, Firefox, and Edge to their default settings can help remove any malicious extensions or settings changes made by the hacktool.
  5. Reboot and Re-scan: After taking the above steps, reboot your system and perform another full scan with your anti-malware tool to ensure that all components of the hacktool have been removed.

Conclusion

The removal of Hacktool.TelegramHack.EC requires careful and thorough action to ensure that all malicious components are eradicated from your system. By following the steps outlined above and maintaining vigilant security practices, such as regularly updating software, using strong and unique passwords, and being cautious with emails and downloads, you can significantly reduce the risk of future infections. Remember, the security of your digital life depends on proactive measures and prompt responses to detected threats.

Analysis Report

General information

Family Name: Hacktool.TelegramHack.EC
Signature status: No Signature

Known Samples

MD5: 1abb7ef9ab461c3996c26ab4689f79fb
SHA1: 52dc52cf0994002e9eff339a0a2932e2d0994130
SHA256: B87A4B828CB5C4EF73C7BD478822705D3AF8FB582E7E6BAF903BB3CD8EB6AF56
File Size: 1.26 MB, 1257984 bytes
MD5: 81f3fbf35b0e53a63201bf09fde26ed8
SHA1: 47c95b7a46cb35fafa577b33091bb24044491296
SHA256: A12EAC8CDAE93D4B7734275403BB96D8F733C3BE9489F4054447696129747C52
File Size: 1.23 MB, 1232896 bytes
MD5: 62abd1204f524ce716f7776e75e1eb70
SHA1: a615493f6ffcc9700c7649c63445cf353e08a502
SHA256: C372D8815B9212465919E04E17439F0AFD35DD3B31AEF42F428126DDF558C963
File Size: 4.02 MB, 4020736 bytes
MD5: d9ff8be4aa3d28ffd28ec4e6c8500264
SHA1: bc788837aca9cbb7fec4a9e07beaca19dc80cebf
SHA256: 7B2524648505FA51A26FEE3511177474F69AB20A77042C1694811ED87D772102
File Size: 560.13 KB, 560128 bytes
MD5: 3ecaa6ae1ae1c5012924f3f28894d889
SHA1: 1d6c6d66b71e93a630795dd8760c47205bd57467
SHA256: F1217B184F2495251296722B99C21AD92D62789A388230F75CF868D600CCB178
File Size: 470.02 KB, 470016 bytes
Show More
MD5: e503146b1f9613ecdb00194b6ca22dc1
SHA1: f3a2baababf03b371f863dfda759141495659a02
SHA256: EEF3EED66AC75F89936AA12A133C992D7E245527876AEEE5EF39F2B3F834ED10
File Size: 2.28 MB, 2280960 bytes
MD5: 5f8ba87a175a1bb3f1d969331c555900
SHA1: c82c8b4488b38c52529876c355e6bfe2ed105ecd
SHA256: 26DEC246D2CCCFF13CBCAFBCF16B6534C8F7C1B87DCE194CE8C140584567455E
File Size: 491.52 KB, 491520 bytes
MD5: 8a169b5d12322647923124061bb05bec
SHA1: 2d47260db882aaff1f65b6a5dbbeeeb66ebc6e68
SHA256: E7C9207D936D866ABAA15BC6E5EB4FE501616E8B6BA5A26E8F1E86036AB6784D
File Size: 2.42 MB, 2416640 bytes
MD5: 1d70d62a927f36b5501b2914750941fa
SHA1: aa04985144411b35cf730092b089eaa7c6027614
SHA256: 4E1D6EF0E8D9573FC806CBE2F50A286771173DBD7835770C8C63BC035E2EBAF5
File Size: 589.31 KB, 589312 bytes
MD5: 7878d2b866afb056e225780b6699b2b3
SHA1: d43ca55b3587fd0c99cdd2603d15bb8ae95466b7
SHA256: 0AD004315C3FA17F7E1E6C817F7E9461B4E5392DC927B132B174F2001F735224
File Size: 622.59 KB, 622592 bytes
MD5: f8cc94808963cdeb8e6f9f121d2529a0
SHA1: d83ab6ab3f0b0f8f5067b5bfbd9111041f8bc639
SHA256: 4D4B3FEF5C41E188A7B788BED84CCFD29567C3C5714B069A3F28ED24AE52812C
File Size: 1.55 MB, 1548288 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Igor Pavlov
File Description LZMA library
File Version 19.00
Internal Name LZMA
Legal Copyright Igor Pavlov : Public domain
Original Filename LZMA.dll
Product Name 7-Zip
Product Version 19.00

File Traits

  • fptable
  • GetConsoleWindow
  • HighEntropy
  • imgui
  • No Version Info
  • VirtualQueryEx
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 5,123
Potentially Malicious Blocks: 145
Whitelisted Blocks: 4,752
Unknown Blocks: 226

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? 0 0 0 0 ? ? 0 ? ? 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 x 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 ? 1 0 ? ? 0 ? ? 0 0 ? ? 0 0 0 0 1 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 x x 0 ? 0 ? ? ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? x ? 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x ? ? ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 1 0 ? 1 0 x ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 1 ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 x 0 0 0 0 0 ? 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 1 0 x 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 ? ? 0 0 0 0 ? ? ? 0 0 0 0 0 x 0 0 0 0 ? 0 0 0 x 0 x 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x ? 0 0 x ? 0 ? ? ? 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 ? 0 0 0 0 0 ? 0 ? ? x 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 ? 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 ? x 0 0 0 0 0 0 ? 0 0 0 0 x 0 ? ? x ? x 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 1 0 0 0 ? 0 0 0 0 0 ? x 0 0 0 ? x x ? x 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 x 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 1 ? 0 ? ? ? ? 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 1 0 0 ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 1 0 0 0 1 ? 0 0 0 0 1 0 0 1 0 0 1 0 0 1 0 0 1 0 0 1 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? x 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Files Modified

File Attributes
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes
c:\users\user\appdata\local\isabelle_new\logs\isabelle-client_log_2025-12-21 (03 06).txt Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe U���ir� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ���ir� RegNtPreCreateKey
HKLM\software\microsoft\cryptography\oid\encodingtype 0\cryptdllfindoidinfo\1.3.6.1.4.1.311.60.3.1!7::name szOID_ROOT_PROGRAM_AUTO_UPDATE_CA_REVOCATION RegNtPreCreateKey
HKLM\software\microsoft\cryptography\oid\encodingtype 0\cryptdllfindoidinfo\1.3.6.1.4.1.311.60.3.2!7::name szOID_ROOT_PROGRAM_AUTO_UPDATE_END_REVOCATION RegNtPreCreateKey
HKLM\software\microsoft\cryptography\oid\encodingtype 0\cryptdllfindoidinfo\1.3.6.1.4.1.311.60.3.3!7::name szOID_ROOT_PROGRAM_NO_OCSP_FAILOVER_TO_CRL RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe :ex�ir� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ~�z�ir� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe KL��ir� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ~���ir� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 刟㌦ǜ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAllocateReserveObject
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcCreateSecurityContext
Show More
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateNamedPipeFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateUserProcess
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtRemoveIoCompletionEx
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetIoCompletionEx
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetValueKey
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx

16 additional items are not displayed above.

Process Manipulation Evasion
  • NtUnmapViewOfSection
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserObjectInformation
Process Shell Execute
  • CreateProcess
  • WriteConsole
Process Terminate
  • TerminateProcess
Network Winsock2
  • WSAStartup
Network Winsock
  • accept
  • bind
  • closesocket
  • connect
  • freeaddrinfo
  • getaddrinfo
  • getpeername
  • getsockname
  • recv
  • send
Show More
  • setsockopt
  • socket
Network Wininet
  • InternetOpen
  • InternetOpenUrl
  • InternetReadFile
Keyboard Access
  • GetAsyncKeyState

Shell Command Execution

C:\WINDOWS\system32\certutil.exe certutil -hashfile "c:\users\user\downloads\a615493f6ffcc9700c7649c63445cf353e08a502_0004020736" MD5
C:\WINDOWS\system32\find.exe find /i /v "md5"
C:\WINDOWS\system32\find.exe find /i /v "certutil"
C:\WINDOWS\system32\cmd.exe cmd /C "color b && title Error && echo CURL Error: SSL connect error && timeout /t 5"
WriteConsole: CURL Error: SSL
Show More
C:\WINDOWS\system32\timeout.exe timeout /t 5
WriteConsole: Waiting for 5
WriteConsole: seconds, press

Related Posts

Trending

Most Viewed

Loading...