Skip to main contentSkip to main content
Room Banner
Room Icon

TryHack3M: Bricks Heist

Crack the code, command the exploit! Dive into the heart of the system with just an RCE CVE as your key.

easy

60 min

67,473

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Score updated
Score updated

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Target Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Lab machine
Status:Off
From Three Million Bricks to Three Million Transactions!

Brick Press Media Co. was working on creating a brand-new web theme that represents a renowned wall using three million byte bricks. Agent Murphy comes with a streak of bad luck. And here we go again: the server is compromised, and they've lost access.

Can you hack back the server and identify what happened there?

Note: Add MACHINE_IP bricks.thm to your /etc/hosts file.
Answer the questions below
What is the content of the hidden .txt file in the web folder?

What is the name of the suspicious process?

What is the service name affiliated with the suspicious process?

What is the log file name of the miner instance?

What is the wallet address of the miner instance?

The wallet address used has been involved in transactions between wallets belonging to which threat group?