Threat Database Hacktool Hacktool.TelegramHack.G

Hacktool.TelegramHack.G

By CagedTech in Hacktool

Threat Scorecard

Threat Level: 50 % (Medium)
Infected Computers: 2
First Seen: October 27, 2025
Last Seen: December 26, 2025
OS(es) Affected: Windows

The detection of Hacktool.TelegramHack.G on your system indicates a potential security threat that requires immediate attention. This hacktool is designed to compromise the security of your system, and its presence can lead to unauthorized access to your sensitive information. In this report, we will provide you with an overview of what Hacktool.TelegramHack.G is, how it operates, and the steps you can take to remove it from your system.

What Is Hacktool.TelegramHack.G?

Hacktool.TelegramHack.G is a type of malicious software that is classified as a hacktool. Hacktools are programs that are designed to bypass security mechanisms or exploit vulnerabilities in software applications. In the case of Hacktool.TelegramHack.G, its primary purpose is to compromise the security of Telegram, a popular messaging app. However, the exact nature and capabilities of Hacktool.TelegramHack.G can vary, and it is essential to take a comprehensive approach to remove it from your system.

How Hacktool.TelegramHack.G Operates

The exact operating methods of Hacktool.TelegramHack.G are not known, but it is likely that it uses various techniques to evade detection and gain unauthorized access to sensitive information. Hacktools, in general, can spread through phishing emails, infected software downloads, or exploited vulnerabilities in operating systems or applications. Once installed, Hacktool.TelegramHack.G may attempt to communicate with its command and control servers to receive further instructions or transmit stolen data.

Symptoms of Infection

The symptoms of Hacktool.TelegramHack.G infection can vary, but common signs include unusual system behavior, slow performance, and unexpected changes to system settings. You may also notice suspicious activity, such as unfamiliar programs or processes running in the background. If you suspect that your system is infected with Hacktool.TelegramHack.G, it is crucial to take immediate action to prevent further damage.

How to Remove Hacktool.TelegramHack.G

  1. Boot your system in Safe Mode with Networking to prevent Hacktool.TelegramHack.G from loading and to allow for a safe removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all components of Hacktool.TelegramHack.G.
  3. Uninstall any suspicious programs or applications that may be related to Hacktool.TelegramHack.G.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan to ensure that Hacktool.TelegramHack.G has been completely removed.

Conclusion

The removal of Hacktool.TelegramHack.G requires a comprehensive approach to ensure that all components of the malware are eliminated. By following the steps outlined in this report, you can help protect your system and sensitive information from further compromise. It is essential to remain vigilant and take proactive measures to prevent future infections, such as keeping your operating system and software up-to-date, using strong passwords, and avoiding suspicious emails and downloads.

Analysis Report

General information

Family Name: Hacktool.TelegramHack.G
Signature status: No Signature

Known Samples

MD5: c28cb35ee4726bd6a8202c46da28d8b2
SHA1: 89d069fb71d53b93a92c1d69b04e4c8f90e0dc04
SHA256: 9A92C7A207955650C1D9E06F851C7E6A0186AF896D7C4588148F525950A67DD3
File Size: 2.93 MB, 2932736 bytes
MD5: bab16e39c4e8edba2251a3dc1dee5f38
SHA1: 63d648076b3bb742599d1e552d9db36ec305e99b
SHA256: 94297F488CCD15049BAD2B505113A2DB9EA338863143EF4F0ECF3D2A8CFC23A7
File Size: 1.48 MB, 1484800 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • GetConsoleWindow
  • imgui
  • No Version Info
  • x64

Block Information

Total Blocks: 4,457
Potentially Malicious Blocks: 222
Whitelisted Blocks: 4,081
Unknown Blocks: 154

Visual Map

0 0 0 ? ? x ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 x 0 0 0 0 0 0 0 ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 x 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 1 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? 0 x ? ? ? ? 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 1 0 0 1 ? ? ? 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? ? 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 x 0 ? ? 0 ? ? ? 0 0 0 0 x 0 x x 0 x x 0 ? ? ? ? ? ? ? 0 x 0 0 ? 0 0 0 0 0 0 0 x 0 0 0 0 x ? 0 x 0 0 1 x x ? 0 0 1 0 0 1 x 0 x x x x 0 0 x ? x 0 0 x x x x x ? x 0 ? 0 0 0 0 0 0 x 0 ? 0 ? ? ? 0 0 ? ? ? 0 ? 0 ? x ? x x x x 0 x 0 0 x ? x x x x 0 x 0 0 x ? x x x x 0 x 0 0 x ? x x x x 0 0 x 0 0 x x ? 0 x x ? 0 x 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 x x ? ? x ? x 0 x x x 0 x ? ? ? x x ? 0 0 0 1 0 0 0 0 x 0 0 x 0 x x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 x 0 x x 0 x 0 x 0 0 0 x 0 x 0 0 0 ? 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 ? ? ? x ? 0 ? 1 0 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 ? 0 ? ? 0 ? 0 ? 0 0 0 0 0 0 0 ? 0 0 x 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x 0 x 0 0 0 0 x 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 x 0 x 0 0 0 x ? 0 0 0 0 x 0 0 0 0 0 0 0 x 1 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 x 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 x 0 0 0 0 0 1 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 x 0 x 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 x ? ? x ? x x x x x 0 0 x 0 ? x 0 0 0 0 x x x 0 0 0 x 0 x 0 0 0 0 0 0 x 0 x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 x 0 0 0 x x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.TRG
  • Gamehack.GACH
  • TelegramHack.G

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenSection
Show More
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Related Posts

Trending

Most Viewed

Loading...