Post

TryHackMe — Invite Only

TryHackMe — Invite Only

You are an SOC analyst at Managed Server Provider TrySecureMe. An L1 analyst has flagged two suspicious indicators — an IP address and a SHA256 hash — and escalated them for deeper analysis. The task: investigate these indicators using the in-house threat intelligence tool TryDetectThis2.0, trace the attack chain, and extract actionable threat intelligence.

This room is pure analysis — no exploitation, no shells. It simulates the kind of IOC investigation SOC analysts perform daily, combining file analysis with OSINT research to map out a malware campaign.

FieldDetails
PlatformTryHackMe
Room/MachineInvite Only
DifficultyEasy
Tagsvirustotal, osint, threat-intelligence, malware-analysis, asyncrat

Theory

Indicators of Compromise (IOCs)

IOCs are forensic artefacts that indicate a potential security breach — file hashes, IP addresses, domain names, URLs, or behavioural patterns. In a SOC workflow, L1 analysts flag suspicious indicators during monitoring, and higher-tier analysts investigate them further. This room simulates exactly that handoff.

VirusTotal

VirusTotal aggregates results from dozens of antivirus engines. Beyond simple detection, it provides context that turned out to be essential here: file relations (which files spawned which), community comments from researchers, and detection labels. I’d used VirusTotal before for basic hash lookups (like in the TryHackMe — Mr Phisher room), but this was the first time I actively navigated its Relations and Community tabs to trace an attack chain.

AsyncRAT

AsyncRAT is a Remote Access Trojan — open-source, commonly delivered through multi-stage infection chains, frequently used alongside other tools for data theft. The room doesn’t require deep knowledge of AsyncRAT, but understanding what it is helps make sense of the attack chain.


Reconnaissance

The Flagged Indicators

  • Flagged SHA256 Hash: 5d0509f68a9b7c415a726be75a078180e3f02e59866f193b0a99eee8e39c874f
  • Flagged IP: 101.99.76.120

The VM includes TryDetectThis2.0 — an offline VirusTotal catalogue.

Hash Analysis — File Identification

Searching the flagged hash in TryDetectThis2.0 immediately returns the file name and type.

Mapping the Attack Chain — Relations

The Relations tab reveals how the flagged file fits into a larger attack chain:

Execution Parents — the files that spawned the flagged hash. These are the upstream components that delivered the malware.

VirusTotal Relations tab showing Execution Parents, Bundled Files, and Dropped Files

Dropped Files — files the flagged executable created on disk. Following the second execution parent’s hash into its own Relations tab reveals additional downstream payloads.


Enumeration

Identifying the Malware Family

The offline catalogue doesn’t explicitly label the malware family. Searching the flagged IP on live VirusTotal and navigating to the Community tab reveals researcher comments — including a malpedia reference identifying the family as AsyncRAT.

VirusTotal Community Comments showing AsyncRAT malpedia label

Finding the Original Report

The same community comment references the original report: “From Trust to Threat: Hijacked Discord Invites Used for Multi-Stage Malware Delivery” by Check Point Research. The title and URL are right there — no need to Google.

Security Vendors — Detection Labels

VirusTotal Security Vendors showing asyncrat detection labels


Data Extraction & Recovery

Answering from the Report

The remaining questions are answered by reading the Check Point Research report.

The campaign exploits a flaw in Discord’s invitation system: attackers hijack expired or deleted Discord invite links by registering them as custom vanity URLs on boosted servers. Users following previously trusted links end up on malicious Discord servers.

From there: ClickFix phishing lures users into executing malicious code, multi-stage loaders deliver AsyncRAT and a Skuld Stealer targeting crypto wallets, and ChromeKatz bypasses Chrome’s App Bound Encryption to steal browser cookies.

Tools Used

  • TryDetectThis2.0 — hash lookup, file relations, detection results
  • VirusTotal (live) — malware family identification via community comments
  • Check Point Research report — campaign details, TTPs, tool identification

Lessons Learned

Pivot, pivot, pivot. The investigation starts with a hash and an IP, but the answers come from following the connections: hash → execution parents → dropped files → IP → community comments → external report. No single source gives the full picture.

Community comments are underrated. The VirusTotal Community tab provided both the malware family identification and the report title — information not available through automated detection labels alone.

Read the report, not just the summary. The Check Point report answers multiple questions, but more importantly it tells the story of the full attack chain.

Trusted platforms can become attack vectors. Expired Discord invite links can be silently hijacked — a design flaw with real consequences, especially for younger users in gaming communities.

Defensive Takeaways

This room is pure threat intelligence analysis, so the defensive angle sits at two levels: what could end users do, and what could a SOC or security team do with this kind of intelligence.

For end users: treat links as untrusted, regardless of source. The attack works because users follow Discord invite links embedded in forum posts, official community pages, or game wikis without questioning them. A link that looks safe today may have been silently redirected to a malicious server. The practical habit: verify the destination of any invite link before joining, particularly if the server you land on looks different from what you expected. Hovering over a link to preview the URL costs nothing.

For organisations: block or monitor macro execution. The initial payload delivery relies on ClickFix — a technique that tricks users into running malicious commands themselves, typically through a fake CAPTCHA or “verification” prompt. Security policies that restrict PowerShell execution in user sessions, combined with endpoint detection rules for unusual process spawning (e.g. a browser spawning cmd.exe), would flag or block this delivery mechanism.

For SOC teams: IOC feeds are not enough on their own. The attack chain in this room — from hijacked Discord links to AsyncRAT to ChromeKatz — uses techniques that generate predictable indicators: C2 IPs, file hashes, JNDI-style callback patterns. But individual IOCs age out quickly. The Check Point report shows that understanding the full campaign context makes the IOCs more actionable: knowing the delivery method (ClickFix), the payload family (AsyncRAT + Skuld), and the target (crypto wallets, browser cookies) lets a SOC prioritise and tune detections beyond a simple hash blocklist.

Expired platform features are an attack surface. Discord’s vanity URL system allowed expired invite codes to be claimed by anyone. This is a product design issue, not a user error — and it’s a useful reminder that any feature on a trusted platform that involves user-controlled identifiers (invite codes, usernames, redirect URLs) can potentially be abused. When evaluating third-party platforms for internal or community use, it’s worth asking: what happens when a resource expires or is deleted?


References

This post is licensed under CC BY 4.0 by the author.