DO NOT DOWNLOAD THIS
I did my own research and came to the following conclusion :
9/10 Sandbox Score ( Malicious ) -> tria.ge/260825-ztscmsv1dv/be…
They used a password protected zip, hosted on a throwaway domain with the "keygen" as the trigger. When someone clicks " generate", the real executable runs.
Before doing anything malicious, it checks whether it's running in a VM/Sandbox (Security Research environment ) or a personal machine, and behaves accordingly.
Once it decides its on a real victims machine, it likely does something close to what info stealer malware does. This gives access to saved browser passwords, session cookies ( Which can hijack logins without needing passwords), and most importantly your broker logins.
Whatever the malware collects is being sent back to the attackers server hosted at 178.104.211.128, and from there it is in their hands.
Please be careful, and don't trust what you see on the internet.