D. Burke

TechnoSavage

View on GitHub

Invite Only (Easy)

Starting point

Flagged IP: 101[.]99[.]76[.]120 Flagged SHA256 hash: 5d0509f68a9b7c415a726be75a078180e3f02e59866f193b0a99eee8e39c874f

Launch TryDetectThis2.0

What is the name of the file identified with the flagged SHA256 hash?

syshelpers.exe

syshelpers.exe

What is the file type associated with the flagged SHA256 hash?

Win32 EXE

What are the execution parents of the flagged hash? List the names chronologically, using a comma as a separator. Note down the hashes for later use.

execution parents

Hashes of the following files:

361GJX7J,installer.exe

What is the name of the file being dropped? Note down the hash value for later use.

AClient.exe

AClient.exe

Research the second hash in question 3 and list the four malicious dropped files in the order they appear (from up to down), separated by commas.

Dropped Files

searchHost.exe, syshelpers.exe, nat.vbs, runsys.vbs

Asyncrat Report

Asyncrat

What is the title of the original report where these flagged indicators are mentioned? Use Google to find the report.

From Trust to Threat: Hijacked Discord Invites Used for Multi-Stage Malware Delivery

Which tool did the attackers use to steal cookies from the Google Chrome browser?

google search

ChromeKatz

Which phishing technique did the attackers use? Use the report to answer the question.

ClickFix google search

What is the name of the platform that was used to redirect a user to malicious servers?

Discord