10341000x800000000000000034Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000033Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000032Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000031Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000030Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000029Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000028Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000027Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000026Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000025Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000024Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000023Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000022Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000021Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000020Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000019Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000018Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000017Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000016Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000015Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.259{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000014Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.244{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000013Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.244{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000012Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.244{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000011Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.213{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F502-000000007E01}3364C:\Windows\system32\wbem\unsecapp.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000010Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.213{F97E5129-0A07-5F7F-0500-000000007E01}6402964C:\Windows\system32\csrss.exe{F97E5129-0B7A-5F7F-F502-000000007E01}3364C:\Windows\system32\wbem\unsecapp.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000009Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.213{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F502-000000007E01}3364C:\Windows\system32\wbem\unsecapp.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000008Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.217{F97E5129-0B7A-5F7F-F502-000000007E01}3364C:\Windows\System32\wbem\unsecapp.exe10.0.14393.2515 (rs1_release_1.180830-1044)Sink to receive asynchronous callbacks for WMI client applicationMicrosoft® Windows® Operating SystemMicrosoft Corporationunsecapp.dllC:\Windows\system32\wbem\unsecapp.exe -EmbeddingC:\Windows\system32\NT AUTHORITY\SYSTEM{F97E5129-0A0E-5F7F-E703-000000000000}0x3e70SystemMD5=2E49BB6C9F6599F518FE30BE2F000247,SHA256=20F499D581CF4AF331D8EC8B1E07A32CC1A695EF6790B51DA5EE223C5867154F,IMPHASH=A3CC49DF67C2278F822C9EBB9908BF09{F97E5129-0A10-5F7F-0C00-000000007E01}572C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x80000000000000007Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.197{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000006Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.197{F97E5129-0A0D-5F7F-0A00-000000007E01}8523044C:\Windows\system32\services.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000005Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.181{F97E5129-0A07-5F7F-0500-000000007E01}6401168C:\Windows\system32\csrss.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000004Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.181{F97E5129-0A0D-5F7F-0A00-000000007E01}8521148C:\Windows\system32\services.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\services.exe+12bee|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d608|C:\Windows\system32\services.exe+4c6c|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000003Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:10.171{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe12.0System activity monitorSysinternals SysmonSysinternals - www.sysinternals.com-C:\Windows\sysmon64.exeC:\Windows\system32\NT AUTHORITY\SYSTEM{F97E5129-0A0E-5F7F-E703-000000000000}0x3e70SystemMD5=0475D48604B7C8E7D9DD7605B6A5930F,SHA256=55BAD23D049A2FD801B8DECDC5D960D4E27D7F92541E8B37557B7495CA5561A2,IMPHASH=49AAA307415968B34D3FD1A72DEE6C71{F97E5129-0A0D-5F7F-0A00-000000007E01}852C:\Windows\System32\services.exeC:\Windows\system32\services.exe 434400x80000000000000002Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local2020-10-08 12:52:10.244Started12.04.40 16341600x80000000000000001Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local2020-10-08 12:52:10.150c:\Program Files\ansible\AttackRangeSysmon.xmlSHA1=662E68DD6B3360E156BDE1F54FD3ED5BB76E8AFC 10341000x8000000000000000128Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.712{F97E5129-0B7B-5F7F-F702-000000007E01}35601360C:\Windows\system32\conhost.exe{F97E5129-0B7B-5F7F-FB02-000000007E01}4400C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000127Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.712{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000126Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.712{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000125Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.712{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000124Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.712{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000123Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.712{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000122Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.712{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000121Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.712{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000120Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.712{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000119Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.712{F97E5129-0A07-5F7F-0500-000000007E01}6401168C:\Windows\system32\csrss.exe{F97E5129-0B7B-5F7F-FB02-000000007E01}4400C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000118Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.712{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000117Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.712{F97E5129-0B7B-5F7F-FA02-000000007E01}12362784C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{F97E5129-0B7B-5F7F-FB02-000000007E01}4400C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+b1932ed(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a634177(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a633e48(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+b0e54ad(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a5f49de(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a652ead(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a636512(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a636512(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a6363a3(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a628328(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a63485b(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a63444e(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a634177(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a633e48(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+b0e54ad(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a61aca9(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a61a279(wow64) 154100x8000000000000000116Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.719{F97E5129-0B7B-5F7F-FB02-000000007E01}4400C:\Windows\System32\chcp.com10.0.14393.0 (rs1_release.160715-1616)Change CodePage UtilityMicrosoft® Windows® Operating SystemMicrosoft CorporationCHCP.COM"C:\Windows\system32\chcp.com" 65001C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7B-5F7F-4F5C-110000000000}0x115c4f0HighMD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD{F97E5129-0B7B-5F7F-FA02-000000007E01}1236C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA== 10341000x8000000000000000115Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.697{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000114Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.697{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000113Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.697{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000112Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.650{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0B7B-5F7F-FA02-000000007E01}1236C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000111Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.650{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0B7B-5F7F-FA02-000000007E01}1236C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000110Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.619{F97E5129-0B7B-5F7F-FA02-000000007E01}1236C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_r4bavfap.u25.ps12020-10-08 12:52:11.619 10341000x8000000000000000109Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.603{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7B-5F7F-FA02-000000007E01}1236C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000108Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.587{F97E5129-0B7B-5F7F-F702-000000007E01}35601360C:\Windows\system32\conhost.exe{F97E5129-0B7B-5F7F-FA02-000000007E01}1236C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000107Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.587{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000106Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.587{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000105Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.587{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000104Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.587{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000103Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.587{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000102Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.587{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000101Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.587{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000100Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.587{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000099Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.587{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000098Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.587{F97E5129-0A07-5F7F-0500-000000007E01}640760C:\Windows\system32\csrss.exe{F97E5129-0B7B-5F7F-FA02-000000007E01}1236C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x800000000000000097Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.587{F97E5129-0B7B-5F7F-F902-000000007E01}44044484C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{F97E5129-0B7B-5F7F-FA02-000000007E01}1236C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|UNKNOWN(00007FFA0B5A331B)|UNKNOWN(00007FFA0AA441A5)|UNKNOWN(00007FFA0AA43E76)|UNKNOWN(00007FFA0B4F54DB)|UNKNOWN(00007FFA0AA04A0C)|UNKNOWN(00007FFA0AA62EDB)|UNKNOWN(00007FFA0AA46540)|UNKNOWN(00007FFA0AA46540)|UNKNOWN(00007FFA0AA463D1)|UNKNOWN(00007FFA0AA38356)|UNKNOWN(00007FFA0AA44889)|UNKNOWN(00007FFA0AA4447C)|UNKNOWN(00007FFA0AA441A5)|UNKNOWN(00007FFA0AA43E76)|UNKNOWN(00007FFA0B4F54DB)|UNKNOWN(00007FFA0AA2ACD7)|UNKNOWN(00007FFA0AA2A2A7) 154100x800000000000000096Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.591{F97E5129-0B7B-5F7F-FA02-000000007E01}1236C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXE"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7B-5F7F-4F5C-110000000000}0x115c4f0HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{F97E5129-0B7B-5F7F-F902-000000007E01}4404C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exePowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA= 10341000x800000000000000095Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.541{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0B7B-5F7F-F902-000000007E01}4404C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000094Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.541{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0B7B-5F7F-F902-000000007E01}4404C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x800000000000000093Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.494{F97E5129-0B7B-5F7F-F902-000000007E01}4404C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_w1zdgi4m.zpd.ps12020-10-08 12:52:11.494 10341000x800000000000000092Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.494{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7B-5F7F-F902-000000007E01}4404C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000091Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.462{F97E5129-0B7B-5F7F-F702-000000007E01}35601360C:\Windows\system32\conhost.exe{F97E5129-0B7B-5F7F-F902-000000007E01}4404C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000090Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.462{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000089Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.462{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000088Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.462{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000087Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.462{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000086Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.462{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000085Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.462{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000084Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.462{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000083Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.462{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000082Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.462{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000081Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.462{F97E5129-0A07-5F7F-0500-000000007E01}640656C:\Windows\system32\csrss.exe{F97E5129-0B7B-5F7F-F902-000000007E01}4404C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x800000000000000080Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.462{F97E5129-0B7B-5F7F-F802-000000007E01}35244020C:\Windows\system32\cmd.exe{F97E5129-0B7B-5F7F-F902-000000007E01}4404C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x800000000000000079Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.461{F97E5129-0B7B-5F7F-F902-000000007E01}4404C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXEPowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7B-5F7F-4F5C-110000000000}0x115c4f0HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{F97E5129-0B7B-5F7F-F802-000000007E01}3524C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA= 10341000x800000000000000078Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.447{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000077Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.447{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000076Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.447{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000075Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.447{F97E5129-0B7B-5F7F-F702-000000007E01}35601360C:\Windows\system32\conhost.exe{F97E5129-0B7B-5F7F-F802-000000007E01}3524C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000074Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.447{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000073Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.447{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000072Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.447{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000071Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.447{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000070Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.447{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000069Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.447{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000068Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.447{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000067Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.447{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000066Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.447{F97E5129-0A07-5F7F-0500-000000007E01}6402964C:\Windows\system32\csrss.exe{F97E5129-0B7B-5F7F-F802-000000007E01}3524C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x800000000000000065Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.447{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000064Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.447{F97E5129-0B7B-5F7F-F602-000000007E01}50642536C:\Windows\system32\WinrsHost.exe{F97E5129-0B7B-5F7F-F802-000000007E01}3524C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\WinrsHost.exe+2c94|C:\Windows\system32\WinrsHost.exe+2eb1|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb 154100x800000000000000063Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.450{F97E5129-0B7B-5F7F-F802-000000007E01}3524C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7B-5F7F-4F5C-110000000000}0x115c4f0HighMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{F97E5129-0B7B-5F7F-F602-000000007E01}5064C:\Windows\System32\winrshost.exeC:\Windows\system32\WinrsHost.exe -Embedding 10341000x800000000000000062Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.447{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000061Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.447{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000060Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.431{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000059Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.431{F97E5129-0A10-5F7F-1300-000000007E01}13361444C:\Windows\system32\svchost.exe{F97E5129-0B7B-5F7F-F602-000000007E01}5064C:\Windows\system32\WinrsHost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\winrscmd.dll+8d36|C:\Windows\system32\winrscmd.dll+92d5|C:\Windows\system32\winrscmd.dll+af31|C:\Windows\system32\winrscmd.dll+23dc|c:\windows\system32\wsmsvc.dll+155ac7|c:\windows\system32\wsmsvc.dll+13f76d|c:\windows\system32\wsmsvc.dll+13f3cf|c:\windows\system32\wsmsvc.dll+13fcb2|c:\windows\system32\wsmsvc.dll+9ab10|c:\windows\system32\wsmsvc.dll+9b611|c:\windows\system32\wsmsvc.dll+4495|c:\windows\system32\wsmsvc.dll+16816c|c:\windows\system32\wsmsvc.dll+1689b8|c:\windows\system32\wsmsvc.dll+16345b|c:\windows\system32\wsmsvc.dll+163125|c:\windows\system32\wsmsvc.dll+14ce9c|c:\windows\system32\wsmsvc.dll+130049|c:\windows\system32\wsmsvc.dll+13571a|c:\windows\system32\wsmsvc.dll+12f47e|c:\windows\system32\wsmsvc.dll+125587|c:\windows\system32\wsmsvc.dll+11f562|c:\windows\system32\wsmsvc.dll+124574 10341000x800000000000000058Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.431{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7B-5F7F-F602-000000007E01}5064C:\Windows\system32\WinrsHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000057Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.416{F97E5129-0B7B-5F7F-F702-000000007E01}35601360C:\Windows\system32\conhost.exe{F97E5129-0B7B-5F7F-F602-000000007E01}5064C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000056Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.416{F97E5129-0A07-5F7F-0500-000000007E01}640760C:\Windows\system32\csrss.exe{F97E5129-0B7B-5F7F-F702-000000007E01}3560C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x800000000000000055Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.400{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000054Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.400{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000053Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.400{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000052Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.400{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000051Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.400{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000050Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.400{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000049Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.400{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000048Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.400{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000047Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.400{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000046Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.400{F97E5129-0A07-5F7F-0500-000000007E01}6402964C:\Windows\system32\csrss.exe{F97E5129-0B7B-5F7F-F602-000000007E01}5064C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x800000000000000045Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.400{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7B-5F7F-F602-000000007E01}5064C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x800000000000000044Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.412{F97E5129-0B7B-5F7F-F602-000000007E01}5064C:\Windows\System32\winrshost.exe10.0.14393.0 (rs1_release.160715-1616)Host Process for WinRM's Remote Shell pluginMicrosoft® Windows® Operating SystemMicrosoft Corporationwinrshost.exeC:\Windows\system32\WinrsHost.exe -EmbeddingC:\Windows\system32\ATTACKRANGE\Administrator{F97E5129-0B7B-5F7F-4F5C-110000000000}0x115c4f0HighMD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96{F97E5129-0A10-5F7F-0C00-000000007E01}572C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x800000000000000043Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.400{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000042Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.400{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000041Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.400{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000040Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.322{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000039Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.322{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000038Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.322{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000037Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.306{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000036Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.306{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000035Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:11.306{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000238Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.978{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0B7C-5F7F-0203-000000007E01}5080C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000237Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.978{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0B7C-5F7F-0203-000000007E01}5080C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000236Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.947{F97E5129-0B7C-5F7F-0203-000000007E01}5080C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_wcntpwxp.3lp.ps12020-10-08 12:52:12.947 10341000x8000000000000000235Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.931{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7C-5F7F-0203-000000007E01}5080C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000234Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.915{F97E5129-0B7C-5F7F-FF02-000000007E01}47845096C:\Windows\system32\conhost.exe{F97E5129-0B7C-5F7F-0203-000000007E01}5080C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000233Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.915{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000232Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.915{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000231Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.915{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000230Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.915{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000229Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.915{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000228Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.915{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000227Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.915{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000226Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.915{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000225Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.915{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000224Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.915{F97E5129-0A07-5F7F-0500-000000007E01}6401168C:\Windows\system32\csrss.exe{F97E5129-0B7C-5F7F-0203-000000007E01}5080C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000223Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.915{F97E5129-0B7C-5F7F-0103-000000007E01}41564464C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{F97E5129-0B7C-5F7F-0203-000000007E01}5080C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+b1932ed(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a634177(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a633e48(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+b0e54ad(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a5f49de(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a652ead(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a636512(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a636512(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a6363a3(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a628328(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a63485b(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a63444e(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a634177(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a633e48(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+b0e54ad(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a61aca9(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a61a279(wow64) 154100x8000000000000000222Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.920{F97E5129-0B7C-5F7F-0203-000000007E01}5080C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXE"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7C-5F7F-318C-110000000000}0x118c310HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{F97E5129-0B7C-5F7F-0103-000000007E01}4156C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exePowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA= 10341000x8000000000000000221Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.868{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0B7C-5F7F-0103-000000007E01}4156C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000220Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.868{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0B7C-5F7F-0103-000000007E01}4156C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000219Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.822{F97E5129-0B7C-5F7F-0103-000000007E01}4156C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_55qunrep.lts.ps12020-10-08 12:52:12.822 10341000x8000000000000000218Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.822{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7C-5F7F-0103-000000007E01}4156C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000217Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000216Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0B7C-5F7F-FF02-000000007E01}47845096C:\Windows\system32\conhost.exe{F97E5129-0B7C-5F7F-0103-000000007E01}4156C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000215Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000214Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000213Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000212Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000211Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000210Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000209Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000208Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000207Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000206Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000205Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A07-5F7F-0500-000000007E01}640760C:\Windows\system32\csrss.exe{F97E5129-0B7C-5F7F-0103-000000007E01}4156C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000204Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0B7C-5F7F-0003-000000007E01}42844652C:\Windows\system32\cmd.exe{F97E5129-0B7C-5F7F-0103-000000007E01}4156C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000203Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.798{F97E5129-0B7C-5F7F-0103-000000007E01}4156C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXEPowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7C-5F7F-318C-110000000000}0x118c310HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{F97E5129-0B7C-5F7F-0003-000000007E01}4284C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA= 10341000x8000000000000000202Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000201Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0B7C-5F7F-FF02-000000007E01}47845096C:\Windows\system32\conhost.exe{F97E5129-0B7C-5F7F-0003-000000007E01}4284C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000200Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000199Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000198Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000197Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000196Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000195Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000194Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000193Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000192Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000191Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A07-5F7F-0500-000000007E01}640656C:\Windows\system32\csrss.exe{F97E5129-0B7C-5F7F-0003-000000007E01}4284C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000190Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0B7C-5F7F-FE02-000000007E01}41322952C:\Windows\system32\WinrsHost.exe{F97E5129-0B7C-5F7F-0003-000000007E01}4284C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\WinrsHost.exe+2c94|C:\Windows\system32\WinrsHost.exe+2eb1|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb 154100x8000000000000000189Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.793{F97E5129-0B7C-5F7F-0003-000000007E01}4284C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7C-5F7F-318C-110000000000}0x118c310HighMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{F97E5129-0B7C-5F7F-FE02-000000007E01}4132C:\Windows\System32\winrshost.exeC:\Windows\system32\WinrsHost.exe -Embedding 10341000x8000000000000000188Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000187Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.790{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000186Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.775{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000185Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.775{F97E5129-0A10-5F7F-1300-000000007E01}13361444C:\Windows\system32\svchost.exe{F97E5129-0B7C-5F7F-FE02-000000007E01}4132C:\Windows\system32\WinrsHost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\winrscmd.dll+8d36|C:\Windows\system32\winrscmd.dll+92d5|C:\Windows\system32\winrscmd.dll+af31|C:\Windows\system32\winrscmd.dll+23dc|c:\windows\system32\wsmsvc.dll+155ac7|c:\windows\system32\wsmsvc.dll+13f76d|c:\windows\system32\wsmsvc.dll+13f3cf|c:\windows\system32\wsmsvc.dll+13fcb2|c:\windows\system32\wsmsvc.dll+9ab10|c:\windows\system32\wsmsvc.dll+9b611|c:\windows\system32\wsmsvc.dll+4495|c:\windows\system32\wsmsvc.dll+16816c|c:\windows\system32\wsmsvc.dll+1689b8|c:\windows\system32\wsmsvc.dll+16345b|c:\windows\system32\wsmsvc.dll+163125|c:\windows\system32\wsmsvc.dll+14ce9c|c:\windows\system32\wsmsvc.dll+130049|c:\windows\system32\wsmsvc.dll+13571a|c:\windows\system32\wsmsvc.dll+12f47e|c:\windows\system32\wsmsvc.dll+125587|c:\windows\system32\wsmsvc.dll+11f562|c:\windows\system32\wsmsvc.dll+124574 10341000x8000000000000000184Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.775{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7C-5F7F-FE02-000000007E01}4132C:\Windows\system32\WinrsHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000183Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.759{F97E5129-0B7C-5F7F-FF02-000000007E01}47845096C:\Windows\system32\conhost.exe{F97E5129-0B7C-5F7F-FE02-000000007E01}4132C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000182Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.759{F97E5129-0A07-5F7F-0500-000000007E01}6401168C:\Windows\system32\csrss.exe{F97E5129-0B7C-5F7F-FF02-000000007E01}4784C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000181Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.759{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000180Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.759{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000179Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.759{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000178Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.759{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000177Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.759{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000176Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.759{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000175Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.759{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000174Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.759{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000173Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.759{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000172Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.759{F97E5129-0A07-5F7F-0500-000000007E01}640656C:\Windows\system32\csrss.exe{F97E5129-0B7C-5F7F-FE02-000000007E01}4132C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000171Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.759{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7C-5F7F-FE02-000000007E01}4132C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000170Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.761{F97E5129-0B7C-5F7F-FE02-000000007E01}4132C:\Windows\System32\winrshost.exe10.0.14393.0 (rs1_release.160715-1616)Host Process for WinRM's Remote Shell pluginMicrosoft® Windows® Operating SystemMicrosoft Corporationwinrshost.exeC:\Windows\system32\WinrsHost.exe -EmbeddingC:\Windows\system32\ATTACKRANGE\Administrator{F97E5129-0B7C-5F7F-318C-110000000000}0x118c310HighMD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96{F97E5129-0A10-5F7F-0C00-000000007E01}572C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x8000000000000000169Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.759{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000168Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.759{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000167Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.743{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000166Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.665{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000165Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.665{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000164Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.665{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000163Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.665{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000162Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.665{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000161Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.665{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000160Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.290{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000159Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.290{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000158Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.290{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000157Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.localDLL2020-10-08 12:52:12.275{F97E5129-0B7C-5F7F-FC02-000000007E01}3556C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exeC:\Users\Administrator\AppData\Local\Temp\ew2nnek2.dll2020-10-08 12:52:12.150 10341000x8000000000000000156Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.275{F97E5129-0B7B-5F7F-F702-000000007E01}35601360C:\Windows\system32\conhost.exe{F97E5129-0B7C-5F7F-FD02-000000007E01}4516C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000155Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.275{F97E5129-0A07-5F7F-0500-000000007E01}6402964C:\Windows\system32\csrss.exe{F97E5129-0B7C-5F7F-FD02-000000007E01}4516C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000154Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.275{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000153Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.275{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000152Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.275{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000151Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.275{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000150Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.275{F97E5129-0B7C-5F7F-FC02-000000007E01}35563644C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe{F97E5129-0B7C-5F7F-FD02-000000007E01}4516C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+b181|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+3d58|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+3ed0|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+3fa6|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+274e|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+27a0|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+28e4|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+7e38f|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+45d22|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+448ef|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+445e6|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+44303|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+18321|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+17b76|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+9e0d|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+1edf02|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000149Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.275{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000148Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.275{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000147Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.275{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000146Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.275{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000145Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.275{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000144Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.274{F97E5129-0B7C-5F7F-FD02-000000007E01}4516C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe12.00.52519.0 built by: VSWINSERVICINGMicrosoft® Resource File To COFF Object Conversion UtilityMicrosoft® .NET FrameworkMicrosoft CorporationCVTRES.EXEC:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\ADMINI~1\AppData\Local\Temp\RESC55B.tmp" "c:\Users\Administrator\AppData\Local\Temp\CSC8F1918B0931D48A68035F14C856B11BC.TMP"C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7B-5F7F-4F5C-110000000000}0x115c4f0HighMD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF{F97E5129-0B7C-5F7F-FC02-000000007E01}3556C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\ADMINI~1\AppData\Local\Temp\ew2nnek2.cmdline" 10341000x8000000000000000143Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.181{F97E5129-0B7B-5F7F-F702-000000007E01}35601360C:\Windows\system32\conhost.exe{F97E5129-0B7C-5F7F-FC02-000000007E01}3556C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000142Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.181{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000141Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.181{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000140Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.181{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000139Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.181{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000138Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.181{F97E5129-0A07-5F7F-0500-000000007E01}6402964C:\Windows\system32\csrss.exe{F97E5129-0B7C-5F7F-FC02-000000007E01}3556C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000137Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.181{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000136Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.181{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000135Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.181{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000134Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.181{F97E5129-0B7B-5F7F-FA02-000000007E01}12362784C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{F97E5129-0B7C-5F7F-FC02-000000007E01}3556C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+270222|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26fe9f|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26f9ee|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26f97a|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26e48b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+7c1edb|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+7c19a9|UNKNOWN(00007FF9B76FB68F) 10341000x8000000000000000133Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.181{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000132Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.181{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000131Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.156{F97E5129-0B7C-5F7F-FC02-000000007E01}3556C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe4.7.2053.0 built by: NET47REL1Visual C# Command Line CompilerMicrosoft® .NET FrameworkMicrosoft Corporationcsc.exe"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\ADMINI~1\AppData\Local\Temp\ew2nnek2.cmdline"C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7B-5F7F-4F5C-110000000000}0x115c4f0HighMD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52{F97E5129-0B7B-5F7F-FA02-000000007E01}1236C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA== 11241100x8000000000000000130Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:12.150{F97E5129-0B7B-5F7F-FA02-000000007E01}1236C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\ew2nnek2.cmdline2020-10-08 12:52:12.150 11241100x8000000000000000129Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.localDLL2020-10-08 12:52:12.150{F97E5129-0B7B-5F7F-FA02-000000007E01}1236C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\ew2nnek2.dll2020-10-08 12:52:12.150 10341000x8000000000000000293Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.978{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000292Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.978{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000291Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.978{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000290Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.962{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000289Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.962{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000288Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.962{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 13241300x8000000000000000287Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-SetValue2020-10-08 12:52:13.884{F97E5129-0B7C-5F7F-0203-000000007E01}5080C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Sysmon/Operational\MaxSizeDWORD (0x12d2c000) 10341000x8000000000000000286Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.618{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000285Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.618{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000284Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.618{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000283Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.localDLL2020-10-08 12:52:13.571{F97E5129-0B7D-5F7F-0403-000000007E01}1188C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exeC:\Users\Administrator\AppData\Local\Temp\k2rcnv03.dll2020-10-08 12:52:13.478 10341000x8000000000000000282Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.571{F97E5129-0B7C-5F7F-FF02-000000007E01}47845096C:\Windows\system32\conhost.exe{F97E5129-0B7D-5F7F-0503-000000007E01}4232C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000281Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.571{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000280Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.571{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000279Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.571{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000278Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.571{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000277Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.571{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000276Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.571{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000275Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.571{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000274Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.571{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000273Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.571{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000272Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.571{F97E5129-0A07-5F7F-0500-000000007E01}6401168C:\Windows\system32\csrss.exe{F97E5129-0B7D-5F7F-0503-000000007E01}4232C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000271Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.571{F97E5129-0B7D-5F7F-0403-000000007E01}11882828C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe{F97E5129-0B7D-5F7F-0503-000000007E01}4232C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+b181|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+3d58|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+3ed0|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+3fa6|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+274e|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+27a0|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+28e4|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+7e38f|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+45d22|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+448ef|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+445e6|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+44303|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+18321|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+17b76|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+9e0d|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+1edf02|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000270Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.572{F97E5129-0B7D-5F7F-0503-000000007E01}4232C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe12.00.52519.0 built by: VSWINSERVICINGMicrosoft® Resource File To COFF Object Conversion UtilityMicrosoft® .NET FrameworkMicrosoft CorporationCVTRES.EXEC:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\ADMINI~1\AppData\Local\Temp\RESCA6C.tmp" "c:\Users\Administrator\AppData\Local\Temp\CSC59AACE9F88CD45E1B9B8447ED0F34E2C.TMP"C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7C-5F7F-318C-110000000000}0x118c310HighMD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF{F97E5129-0B7D-5F7F-0403-000000007E01}1188C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\ADMINI~1\AppData\Local\Temp\k2rcnv03.cmdline" 10341000x8000000000000000269Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.478{F97E5129-0B7C-5F7F-FF02-000000007E01}47845096C:\Windows\system32\conhost.exe{F97E5129-0B7D-5F7F-0403-000000007E01}1188C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000268Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.478{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000267Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.478{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000266Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.478{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000265Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.478{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000264Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.478{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000263Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.478{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000262Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.478{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000261Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.478{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000260Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.478{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000259Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.478{F97E5129-0A07-5F7F-0500-000000007E01}640760C:\Windows\system32\csrss.exe{F97E5129-0B7D-5F7F-0403-000000007E01}1188C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000258Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.478{F97E5129-0B7C-5F7F-0203-000000007E01}50802776C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{F97E5129-0B7D-5F7F-0403-000000007E01}1188C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+270222|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26fe9f|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26f9ee|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26f97a|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26e48b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+7c1edb|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+7c19a9|UNKNOWN(00007FF9B771B68F) 154100x8000000000000000257Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.486{F97E5129-0B7D-5F7F-0403-000000007E01}1188C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe4.7.2053.0 built by: NET47REL1Visual C# Command Line CompilerMicrosoft® .NET FrameworkMicrosoft Corporationcsc.exe"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\ADMINI~1\AppData\Local\Temp\k2rcnv03.cmdline"C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7C-5F7F-318C-110000000000}0x118c310HighMD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52{F97E5129-0B7C-5F7F-0203-000000007E01}5080C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA== 11241100x8000000000000000256Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.478{F97E5129-0B7C-5F7F-0203-000000007E01}5080C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\k2rcnv03.cmdline2020-10-08 12:52:13.478 11241100x8000000000000000255Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.localDLL2020-10-08 12:52:13.478{F97E5129-0B7C-5F7F-0203-000000007E01}5080C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\k2rcnv03.dll2020-10-08 12:52:13.478 10341000x8000000000000000254Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.040{F97E5129-0B7C-5F7F-FF02-000000007E01}47845096C:\Windows\system32\conhost.exe{F97E5129-0B7D-5F7F-0303-000000007E01}4208C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000253Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.040{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000252Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.040{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000251Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.040{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000250Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.040{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000249Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.040{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000248Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.040{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000247Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.040{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000246Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.040{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000245Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.040{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000244Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.040{F97E5129-0A07-5F7F-0500-000000007E01}6402964C:\Windows\system32\csrss.exe{F97E5129-0B7D-5F7F-0303-000000007E01}4208C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000243Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.040{F97E5129-0B7C-5F7F-0203-000000007E01}50802776C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{F97E5129-0B7D-5F7F-0303-000000007E01}4208C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+ae632a6(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a304130(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a303e01(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+adb5466(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a2c4997(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a322e66(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a3064cb(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a3064cb(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a30635c(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a2f82e1(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a304814(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a304407(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a304130(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a303e01(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+adb5466(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a2eac62(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a2ea232(wow64) 154100x8000000000000000242Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.046{F97E5129-0B7D-5F7F-0303-000000007E01}4208C:\Windows\System32\chcp.com10.0.14393.0 (rs1_release.160715-1616)Change CodePage UtilityMicrosoft® Windows® Operating SystemMicrosoft CorporationCHCP.COM"C:\Windows\system32\chcp.com" 65001C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7C-5F7F-318C-110000000000}0x118c310HighMD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD{F97E5129-0B7C-5F7F-0203-000000007E01}5080C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA== 10341000x8000000000000000241Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.025{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000240Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.025{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000239Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:13.025{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000413Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.915{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000412Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.915{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000411Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.915{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000410Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.localDLL2020-10-08 12:52:14.884{F97E5129-0B7E-5F7F-0C03-000000007E01}4316C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exeC:\Users\Administrator\AppData\Local\Temp\nzkhdhs0.dll2020-10-08 12:52:14.790 10341000x8000000000000000409Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.884{F97E5129-0B7E-5F7F-0703-000000007E01}47203312C:\Windows\system32\conhost.exe{F97E5129-0B7E-5F7F-0D03-000000007E01}4480C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000408Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.884{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000407Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.884{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000406Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.884{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000405Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.884{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000404Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.884{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000403Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.884{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000402Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.884{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000401Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.884{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000400Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.884{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000399Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.884{F97E5129-0A07-5F7F-0500-000000007E01}6402964C:\Windows\system32\csrss.exe{F97E5129-0B7E-5F7F-0D03-000000007E01}4480C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000398Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.884{F97E5129-0B7E-5F7F-0C03-000000007E01}43164948C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe{F97E5129-0B7E-5F7F-0D03-000000007E01}4480C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+b181|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+3d58|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+3ed0|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+3fa6|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+274e|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+27a0|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+28e4|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+7e38f|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+45d22|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+448ef|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+445e6|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+44303|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+18321|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+17b76|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+9e0d|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+1edf02|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000397Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.891{F97E5129-0B7E-5F7F-0D03-000000007E01}4480C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe12.00.52519.0 built by: VSWINSERVICINGMicrosoft® Resource File To COFF Object Conversion UtilityMicrosoft® .NET FrameworkMicrosoft CorporationCVTRES.EXEC:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\ADMINI~1\AppData\Local\Temp\RESCF9C.tmp" "c:\Users\Administrator\AppData\Local\Temp\CSC4B8D925FBEC843038DDF47185C3E8B46.TMP"C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7E-5F7F-1DB4-110000000000}0x11b41d0HighMD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF{F97E5129-0B7E-5F7F-0C03-000000007E01}4316C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\ADMINI~1\AppData\Local\Temp\nzkhdhs0.cmdline" 10341000x8000000000000000396Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.806{F97E5129-0B7E-5F7F-0703-000000007E01}47203312C:\Windows\system32\conhost.exe{F97E5129-0B7E-5F7F-0C03-000000007E01}4316C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000395Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.806{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000394Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.806{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000393Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.806{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000392Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.806{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000391Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.806{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000390Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.806{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000389Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.806{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000388Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.806{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000387Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.806{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000386Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.806{F97E5129-0A07-5F7F-0500-000000007E01}640656C:\Windows\system32\csrss.exe{F97E5129-0B7E-5F7F-0C03-000000007E01}4316C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000385Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.806{F97E5129-0B7E-5F7F-0A03-000000007E01}45724392C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{F97E5129-0B7E-5F7F-0C03-000000007E01}4316C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+270222|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26fe9f|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26f9ee|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26f97a|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26e48b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+7c1edb|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+7c19a9|UNKNOWN(00007FF9B770B68F) 154100x8000000000000000384Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.806{F97E5129-0B7E-5F7F-0C03-000000007E01}4316C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe4.7.2053.0 built by: NET47REL1Visual C# Command Line CompilerMicrosoft® .NET FrameworkMicrosoft Corporationcsc.exe"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\ADMINI~1\AppData\Local\Temp\nzkhdhs0.cmdline"C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7E-5F7F-1DB4-110000000000}0x11b41d0HighMD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52{F97E5129-0B7E-5F7F-0A03-000000007E01}4572C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA== 11241100x8000000000000000383Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.790{F97E5129-0B7E-5F7F-0A03-000000007E01}4572C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\nzkhdhs0.cmdline2020-10-08 12:52:14.790 11241100x8000000000000000382Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.localDLL2020-10-08 12:52:14.790{F97E5129-0B7E-5F7F-0A03-000000007E01}4572C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\nzkhdhs0.dll2020-10-08 12:52:14.790 10341000x8000000000000000381Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.353{F97E5129-0B7E-5F7F-0703-000000007E01}47203312C:\Windows\system32\conhost.exe{F97E5129-0B7E-5F7F-0B03-000000007E01}4520C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000380Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.353{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000379Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.353{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000378Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.353{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000377Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.353{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000376Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.353{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000375Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.353{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000374Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.353{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000373Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.353{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000372Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.353{F97E5129-0A07-5F7F-0500-000000007E01}6401168C:\Windows\system32\csrss.exe{F97E5129-0B7E-5F7F-0B03-000000007E01}4520C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000371Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.353{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000370Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.353{F97E5129-0B7E-5F7F-0A03-000000007E01}45724392C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{F97E5129-0B7E-5F7F-0B03-000000007E01}4520C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+b1932ed(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a634177(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a633e48(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+b0e54ad(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a5f49de(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a652ead(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a636512(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a636512(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a6363a3(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a628328(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a63485b(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a63444e(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a634177(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a633e48(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+b0e54ad(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a61aca9(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a61a279(wow64) 154100x8000000000000000369Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.364{F97E5129-0B7E-5F7F-0B03-000000007E01}4520C:\Windows\System32\chcp.com10.0.14393.0 (rs1_release.160715-1616)Change CodePage UtilityMicrosoft® Windows® Operating SystemMicrosoft CorporationCHCP.COM"C:\Windows\system32\chcp.com" 65001C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7E-5F7F-1DB4-110000000000}0x11b41d0HighMD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD{F97E5129-0B7E-5F7F-0A03-000000007E01}4572C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA== 10341000x8000000000000000368Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.353{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000367Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.353{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000366Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.353{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000365Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.306{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0B7E-5F7F-0A03-000000007E01}4572C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000364Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.306{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0B7E-5F7F-0A03-000000007E01}4572C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000363Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.259{F97E5129-0B7E-5F7F-0A03-000000007E01}4572C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_xinsplxh.r4p.ps12020-10-08 12:52:14.259 10341000x8000000000000000362Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.259{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7E-5F7F-0A03-000000007E01}4572C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000361Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.228{F97E5129-0B7E-5F7F-0703-000000007E01}47203312C:\Windows\system32\conhost.exe{F97E5129-0B7E-5F7F-0A03-000000007E01}4572C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000360Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.228{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000359Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.228{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000358Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.228{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000357Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.228{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000356Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.228{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000355Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.228{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000354Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.228{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000353Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.228{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000352Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.228{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000351Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.228{F97E5129-0A07-5F7F-0500-000000007E01}640760C:\Windows\system32\csrss.exe{F97E5129-0B7E-5F7F-0A03-000000007E01}4572C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000350Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.228{F97E5129-0B7E-5F7F-0903-000000007E01}20684236C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{F97E5129-0B7E-5F7F-0A03-000000007E01}4572C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+ae632a6(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a304130(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a303e01(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+adb5466(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a2c4997(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a322e66(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a3064cb(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a3064cb(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a30635c(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a2f82e1(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a304814(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a304407(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a304130(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a303e01(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+adb5466(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a2eac62(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a2ea232(wow64) 154100x8000000000000000349Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.237{F97E5129-0B7E-5F7F-0A03-000000007E01}4572C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXE"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7E-5F7F-1DB4-110000000000}0x11b41d0HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{F97E5129-0B7E-5F7F-0903-000000007E01}2068C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exePowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA= 10341000x8000000000000000348Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.181{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0B7E-5F7F-0903-000000007E01}2068C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000347Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.181{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0B7E-5F7F-0903-000000007E01}2068C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000346Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.149{F97E5129-0B7E-5F7F-0903-000000007E01}2068C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_bqsvnqyc.nyk.ps12020-10-08 12:52:14.149 10341000x8000000000000000345Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.118{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7E-5F7F-0903-000000007E01}2068C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000344Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.103{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000343Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.103{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000342Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.103{F97E5129-0B7E-5F7F-0703-000000007E01}47203312C:\Windows\system32\conhost.exe{F97E5129-0B7E-5F7F-0903-000000007E01}2068C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000341Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.103{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000340Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.103{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000339Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.103{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000338Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.103{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000337Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.103{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000336Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.103{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000335Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.103{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000334Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.103{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000333Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0A07-5F7F-0500-000000007E01}640656C:\Windows\system32\csrss.exe{F97E5129-0B7E-5F7F-0903-000000007E01}2068C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000332Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000331Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0B7E-5F7F-0803-000000007E01}46964432C:\Windows\system32\cmd.exe{F97E5129-0B7E-5F7F-0903-000000007E01}2068C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000330Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.102{F97E5129-0B7E-5F7F-0903-000000007E01}2068C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXEPowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7E-5F7F-1DB4-110000000000}0x11b41d0HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{F97E5129-0B7E-5F7F-0803-000000007E01}4696C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA= 10341000x8000000000000000329Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000328Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0B7E-5F7F-0703-000000007E01}47203312C:\Windows\system32\conhost.exe{F97E5129-0B7E-5F7F-0803-000000007E01}4696C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000327Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000326Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000325Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000324Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000323Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000322Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000321Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000320Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000319Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0A07-5F7F-0500-000000007E01}6402964C:\Windows\system32\csrss.exe{F97E5129-0B7E-5F7F-0803-000000007E01}4696C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000318Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000317Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0B7E-5F7F-0603-000000007E01}47004628C:\Windows\system32\WinrsHost.exe{F97E5129-0B7E-5F7F-0803-000000007E01}4696C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\WinrsHost.exe+2c94|C:\Windows\system32\WinrsHost.exe+2eb1|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb 154100x8000000000000000316Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.097{F97E5129-0B7E-5F7F-0803-000000007E01}4696C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7E-5F7F-1DB4-110000000000}0x11b41d0HighMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{F97E5129-0B7E-5F7F-0603-000000007E01}4700C:\Windows\System32\winrshost.exeC:\Windows\system32\WinrsHost.exe -Embedding 10341000x8000000000000000315Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000314Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000313Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000312Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.087{F97E5129-0A10-5F7F-1300-000000007E01}13363640C:\Windows\system32\svchost.exe{F97E5129-0B7E-5F7F-0603-000000007E01}4700C:\Windows\system32\WinrsHost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\winrscmd.dll+8d36|C:\Windows\system32\winrscmd.dll+92d5|C:\Windows\system32\winrscmd.dll+af31|C:\Windows\system32\winrscmd.dll+23dc|c:\windows\system32\wsmsvc.dll+155ac7|c:\windows\system32\wsmsvc.dll+13f76d|c:\windows\system32\wsmsvc.dll+13f3cf|c:\windows\system32\wsmsvc.dll+13fcb2|c:\windows\system32\wsmsvc.dll+9ab10|c:\windows\system32\wsmsvc.dll+9b611|c:\windows\system32\wsmsvc.dll+4495|c:\windows\system32\wsmsvc.dll+16816c|c:\windows\system32\wsmsvc.dll+1689b8|c:\windows\system32\wsmsvc.dll+16345b|c:\windows\system32\wsmsvc.dll+163125|c:\windows\system32\wsmsvc.dll+14ce9c|c:\windows\system32\wsmsvc.dll+130049|c:\windows\system32\wsmsvc.dll+13571a|c:\windows\system32\wsmsvc.dll+12f47e|c:\windows\system32\wsmsvc.dll+125587|c:\windows\system32\wsmsvc.dll+11f562|c:\windows\system32\wsmsvc.dll+124574 10341000x8000000000000000311Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.071{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7E-5F7F-0603-000000007E01}4700C:\Windows\system32\WinrsHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000310Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.071{F97E5129-0B7E-5F7F-0703-000000007E01}47203312C:\Windows\system32\conhost.exe{F97E5129-0B7E-5F7F-0603-000000007E01}4700C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000309Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.056{F97E5129-0A07-5F7F-0500-000000007E01}640760C:\Windows\system32\csrss.exe{F97E5129-0B7E-5F7F-0703-000000007E01}4720C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000308Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.056{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000307Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.056{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000306Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.056{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000305Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.056{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000304Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.056{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000303Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.056{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000302Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.056{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000301Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.056{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000300Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.056{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000299Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.056{F97E5129-0A07-5F7F-0500-000000007E01}6402964C:\Windows\system32\csrss.exe{F97E5129-0B7E-5F7F-0603-000000007E01}4700C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000298Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.056{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7E-5F7F-0603-000000007E01}4700C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000297Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.065{F97E5129-0B7E-5F7F-0603-000000007E01}4700C:\Windows\System32\winrshost.exe10.0.14393.0 (rs1_release.160715-1616)Host Process for WinRM's Remote Shell pluginMicrosoft® Windows® Operating SystemMicrosoft Corporationwinrshost.exeC:\Windows\system32\WinrsHost.exe -EmbeddingC:\Windows\system32\ATTACKRANGE\Administrator{F97E5129-0B7E-5F7F-1DB4-110000000000}0x11b41d0HighMD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96{F97E5129-0A10-5F7F-0C00-000000007E01}572C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x8000000000000000296Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.056{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000295Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.056{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000294Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:14.056{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000604Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0B7F-5F7F-1703-000000007E01}50324452C:\Windows\system32\conhost.exe{F97E5129-0B7F-5F7F-1903-000000007E01}4580C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000603Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000602Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000601Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000600Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000599Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000598Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000597Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000596Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000595Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000594Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A07-5F7F-0500-000000007E01}640760C:\Windows\system32\csrss.exe{F97E5129-0B7F-5F7F-1903-000000007E01}4580C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000593Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000592Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000591Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0B7F-5F7F-1803-000000007E01}27844048C:\Windows\system32\cmd.exe{F97E5129-0B7F-5F7F-1903-000000007E01}4580C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000590Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.982{F97E5129-0B7F-5F7F-1903-000000007E01}4580C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXEPowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUAC:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7F-5F7F-9D0F-120000000000}0x120f9d0HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{F97E5129-0B7F-5F7F-1803-000000007E01}2784C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA 10341000x8000000000000000589Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000588Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0B7F-5F7F-1703-000000007E01}50324452C:\Windows\system32\conhost.exe{F97E5129-0B7F-5F7F-1803-000000007E01}2784C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000587Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000586Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000585Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000584Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000583Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000582Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000581Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000580Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000579Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000578Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0A07-5F7F-0500-000000007E01}6401168C:\Windows\system32\csrss.exe{F97E5129-0B7F-5F7F-1803-000000007E01}2784C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000577Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.962{F97E5129-0B7F-5F7F-1603-000000007E01}41003436C:\Windows\system32\WinrsHost.exe{F97E5129-0B7F-5F7F-1803-000000007E01}2784C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\WinrsHost.exe+2c94|C:\Windows\system32\WinrsHost.exe+2eb1|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb 154100x8000000000000000576Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.977{F97E5129-0B7F-5F7F-1803-000000007E01}2784C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUAC:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7F-5F7F-9D0F-120000000000}0x120f9d0HighMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{F97E5129-0B7F-5F7F-1603-000000007E01}4100C:\Windows\System32\winrshost.exeC:\Windows\system32\WinrsHost.exe -Embedding 10341000x8000000000000000575Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.962{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000574Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.962{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000573Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.962{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000572Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.962{F97E5129-0A10-5F7F-1300-000000007E01}13363624C:\Windows\system32\svchost.exe{F97E5129-0B7F-5F7F-1603-000000007E01}4100C:\Windows\system32\WinrsHost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\winrscmd.dll+8d36|C:\Windows\system32\winrscmd.dll+92d5|C:\Windows\system32\winrscmd.dll+af31|C:\Windows\system32\winrscmd.dll+23dc|c:\windows\system32\wsmsvc.dll+155ac7|c:\windows\system32\wsmsvc.dll+13f76d|c:\windows\system32\wsmsvc.dll+13f3cf|c:\windows\system32\wsmsvc.dll+13fcb2|c:\windows\system32\wsmsvc.dll+9ab10|c:\windows\system32\wsmsvc.dll+9b611|c:\windows\system32\wsmsvc.dll+4495|c:\windows\system32\wsmsvc.dll+16816c|c:\windows\system32\wsmsvc.dll+1689b8|c:\windows\system32\wsmsvc.dll+16345b|c:\windows\system32\wsmsvc.dll+163125|c:\windows\system32\wsmsvc.dll+14ce9c|c:\windows\system32\wsmsvc.dll+130049|c:\windows\system32\wsmsvc.dll+13571a|c:\windows\system32\wsmsvc.dll+12f47e|c:\windows\system32\wsmsvc.dll+125587|c:\windows\system32\wsmsvc.dll+11f562|c:\windows\system32\wsmsvc.dll+124574 10341000x8000000000000000571Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.962{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7F-5F7F-1603-000000007E01}4100C:\Windows\system32\WinrsHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000570Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.946{F97E5129-0B7F-5F7F-1703-000000007E01}50324452C:\Windows\system32\conhost.exe{F97E5129-0B7F-5F7F-1603-000000007E01}4100C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000569Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.946{F97E5129-0A07-5F7F-0500-000000007E01}6402964C:\Windows\system32\csrss.exe{F97E5129-0B7F-5F7F-1703-000000007E01}5032C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000568Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.946{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000567Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.946{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000566Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.946{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000565Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.946{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000564Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.946{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000563Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.946{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000562Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.946{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000561Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.946{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000560Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.946{F97E5129-0A10-5F7F-0C00-000000007E01}5721116C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000559Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.946{F97E5129-0A07-5F7F-0500-000000007E01}6401168C:\Windows\system32\csrss.exe{F97E5129-0B7F-5F7F-1603-000000007E01}4100C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000558Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.946{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7F-5F7F-1603-000000007E01}4100C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000557Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.947{F97E5129-0B7F-5F7F-1603-000000007E01}4100C:\Windows\System32\winrshost.exe10.0.14393.0 (rs1_release.160715-1616)Host Process for WinRM's Remote Shell pluginMicrosoft® Windows® Operating SystemMicrosoft Corporationwinrshost.exeC:\Windows\system32\WinrsHost.exe -EmbeddingC:\Windows\system32\ATTACKRANGE\Administrator{F97E5129-0B7F-5F7F-9D0F-120000000000}0x120f9d0HighMD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96{F97E5129-0A10-5F7F-0C00-000000007E01}572C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x8000000000000000556Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.930{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000555Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.930{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000554Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.930{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000553Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.915{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000552Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.915{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000551Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.915{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000550Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.868{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0A0B-5F7F-0700-000000007E01}716C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000549Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.868{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0A0B-5F7F-0700-000000007E01}716C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000548Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.868{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0A0B-5F7F-0700-000000007E01}716C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000547Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.868{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0A0B-5F7F-0700-000000007E01}716C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000546Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.868{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0A0B-5F7F-0700-000000007E01}716C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000545Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.868{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0A0B-5F7F-0700-000000007E01}716C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000544Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.852{F97E5129-0B7F-5F7F-0F03-000000007E01}35242796C:\Windows\system32\conhost.exe{F97E5129-0B7F-5F7F-1503-000000007E01}2736C:\Windows\system32\shutdown.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000543Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.852{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000542Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.852{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000541Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.852{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000540Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.852{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000539Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.852{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000538Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.852{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000537Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.852{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000536Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.852{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000535Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.852{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000534Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.852{F97E5129-0A07-5F7F-0500-000000007E01}640656C:\Windows\system32\csrss.exe{F97E5129-0B7F-5F7F-1503-000000007E01}2736C:\Windows\system32\shutdown.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000533Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.852{F97E5129-0B7F-5F7F-1403-000000007E01}2724168C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{F97E5129-0B7F-5F7F-1503-000000007E01}2736C:\Windows\system32\shutdown.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+af132a9(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a3b4133(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a3b3e04(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+ae65469(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a37499a(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a3d2e69(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a3b64ce(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a3b64ce(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a3b635f(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a3a82e4(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a3b4817(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a3b440a(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a3b4133(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a3b3e04(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+ae65469(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a39ac65(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+a39a235(wow64) 154100x8000000000000000532Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.864{F97E5129-0B7F-5F7F-1503-000000007E01}2736C:\Windows\System32\shutdown.exe10.0.14393.0 (rs1_release.160715-1616)Windows Shutdown and Annotation ToolMicrosoft® Windows® Operating SystemMicrosoft CorporationSHUTDOWN.EXE"C:\Windows\system32\shutdown.exe" /r /t 2 /c "Reboot initiated by Ansible"C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7F-5F7F-32DC-110000000000}0x11dc320HighMD5=547993395376742A437D3145AF6B0309,SHA256=F96073C3442EA0A99B4945394007602772DB36732D1511DC2068519526678F8A,IMPHASH=609F1D7580ED496A3076AEBA77DAFC7E{F97E5129-0B7F-5F7F-1403-000000007E01}2724C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UwBlAHQALQBTAHQAcgBpAGMAdABNAG8AZABlACAALQBWAGUAcgBzAGkAbwBuACAATABhAHQAZQBzAHQACgBzAGgAdQB0AGQAbwB3AG4AIAAvAHIAIAAvAHQAIAAyACAALwBjACAAIgBSAGUAYgBvAG8AdAAgAGkAbgBpAHQAaQBhAHQAZQBkACAAYgB5ACAAQQBuAHMAaQBiAGwAZQAiAAoASQBmACAAKAAtAG4AbwB0ACAAJAA/ACkAIAB7ACAASQBmACAAKABHAGUAdAAtAFYAYQByAGkAYQBiAGwAZQAgAEwAQQBTAFQARQBYAEkAVABDAE8ARABFACAALQBFAHIAcgBvAHIAQQBjAHQAaQBvAG4AIABTAGkAbABlAG4AdABsAHkAQwBvAG4AdABpAG4AdQBlACkAIAB7ACAAZQB4AGkAdAAgACQATABBAFMAVABFAFgASQBUAEMATwBEAEUAIAB9ACAARQBsAHMAZQAgAHsAIABlAHgAaQB0ACAAMQAgAH0AIAB9AA== 10341000x8000000000000000531Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.805{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0B7F-5F7F-1403-000000007E01}2724C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000530Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.805{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0B7F-5F7F-1403-000000007E01}2724C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000529Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.774{F97E5129-0B7F-5F7F-1403-000000007E01}2724C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_tixlykan.zyd.ps12020-10-08 12:52:15.774 10341000x8000000000000000528Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.759{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7F-5F7F-1403-000000007E01}2724C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000527Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.727{F97E5129-0B7F-5F7F-0F03-000000007E01}35242796C:\Windows\system32\conhost.exe{F97E5129-0B7F-5F7F-1403-000000007E01}2724C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000526Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.727{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000525Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.727{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000524Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.727{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000523Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.727{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000522Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.727{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000521Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.727{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000520Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.727{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000519Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.727{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000518Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.727{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000517Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.727{F97E5129-0A07-5F7F-0500-000000007E01}640760C:\Windows\system32\csrss.exe{F97E5129-0B7F-5F7F-1403-000000007E01}2724C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000516Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.727{F97E5129-0B7F-5F7F-1303-000000007E01}27764620C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{F97E5129-0B7F-5F7F-1403-000000007E01}2724C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+b5a321b(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+aa440a5(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+aa43d76(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+b4f53db(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+aa0490c(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+aa62ddb(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+aa46440(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+aa46440(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+aa462d1(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+aa38256(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+aa44789(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+aa4437c(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+aa440a5(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+aa43d76(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+b4f53db(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+aa2abd7(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+aa2a1a7(wow64) 154100x8000000000000000515Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.740{F97E5129-0B7F-5F7F-1403-000000007E01}2724C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXE"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UwBlAHQALQBTAHQAcgBpAGMAdABNAG8AZABlACAALQBWAGUAcgBzAGkAbwBuACAATABhAHQAZQBzAHQACgBzAGgAdQB0AGQAbwB3AG4AIAAvAHIAIAAvAHQAIAAyACAALwBjACAAIgBSAGUAYgBvAG8AdAAgAGkAbgBpAHQAaQBhAHQAZQBkACAAYgB5ACAAQQBuAHMAaQBiAGwAZQAiAAoASQBmACAAKAAtAG4AbwB0ACAAJAA/ACkAIAB7ACAASQBmACAAKABHAGUAdAAtAFYAYQByAGkAYQBiAGwAZQAgAEwAQQBTAFQARQBYAEkAVABDAE8ARABFACAALQBFAHIAcgBvAHIAQQBjAHQAaQBvAG4AIABTAGkAbABlAG4AdABsAHkAQwBvAG4AdABpAG4AdQBlACkAIAB7ACAAZQB4AGkAdAAgACQATABBAFMAVABFAFgASQBUAEMATwBEAEUAIAB9ACAARQBsAHMAZQAgAHsAIABlAHgAaQB0ACAAMQAgAH0AIAB9AA==C:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7F-5F7F-32DC-110000000000}0x11dc320HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{F97E5129-0B7F-5F7F-1303-000000007E01}2776C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exePowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAAVQB3AEIAbABBAEgAUQBBAEwAUQBCAFQAQQBIAFEAQQBjAGcAQgBwAEEARwBNAEEAZABBAEIATgBBAEcAOABBAFoAQQBCAGwAQQBDAEEAQQBMAFEAQgBXAEEARwBVAEEAYwBnAEIAegBBAEcAawBBAGIAdwBCAHUAQQBDAEEAQQBUAEEAQgBoAEEASABRAEEAWgBRAEIAegBBAEgAUQBBAEMAZwBCAHoAQQBHAGcAQQBkAFEAQgAwAEEARwBRAEEAYgB3AEIAMwBBAEcANABBAEkAQQBBAHYAQQBIAEkAQQBJAEEAQQB2AEEASABRAEEASQBBAEEAeQBBAEMAQQBBAEwAdwBCAGoAQQBDAEEAQQBJAGcAQgBTAEEARwBVAEEAWQBnAEIAdgBBAEcAOABBAGQAQQBBAGcAQQBHAGsAQQBiAGcAQgBwAEEASABRAEEAYQBRAEIAaABBAEgAUQBBAFoAUQBCAGsAQQBDAEEAQQBZAGcAQgA1AEEAQwBBAEEAUQBRAEIAdQBBAEgATQBBAGEAUQBCAGkAQQBHAHcAQQBaAFEAQQBpAEEAQQBvAEEAUwBRAEIAbQBBAEMAQQBBAEsAQQBBAHQAQQBHADQAQQBiAHcAQgAwAEEAQwBBAEEASgBBAEEALwBBAEMAawBBAEkAQQBCADcAQQBDAEEAQQBTAFEAQgBtAEEAQwBBAEEASwBBAEIASABBAEcAVQBBAGQAQQBBAHQAQQBGAFkAQQBZAFEAQgB5AEEARwBrAEEAWQBRAEIAaQBBAEcAdwBBAFoAUQBBAGcAQQBFAHcAQQBRAFEAQgBUAEEARgBRAEEAUgBRAEIAWQBBAEUAawBBAFYAQQBCAEQAQQBFADgAQQBSAEEAQgBGAEEAQwBBAEEATABRAEIARgBBAEgASQBBAGMAZwBCAHYAQQBIAEkAQQBRAFEAQgBqAEEASABRAEEAYQBRAEIAdgBBAEcANABBAEkAQQBCAFQAQQBHAGsAQQBiAEEAQgBsAEEARwA0AEEAZABBAEIAcwBBAEgAawBBAFEAdwBCAHYAQQBHADQAQQBkAEEAQgBwAEEARwA0AEEAZABRAEIAbABBAEMAawBBAEkAQQBCADcAQQBDAEEAQQBaAFEAQgA0AEEARwBrAEEAZABBAEEAZwBBAEMAUQBBAFQAQQBCAEIAQQBGAE0AQQBWAEEAQgBGAEEARgBnAEEAUwBRAEIAVQBBAEUATQBBAFQAdwBCAEUAQQBFAFUAQQBJAEEAQgA5AEEAQwBBAEEAUgBRAEIAcwBBAEgATQBBAFoAUQBBAGcAQQBIAHMAQQBJAEEAQgBsAEEASABnAEEAYQBRAEIAMABBAEMAQQBBAE0AUQBBAGcAQQBIADAAQQBJAEEAQgA5AEEAQQA9AD0A 10341000x8000000000000000514Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.680{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0B7F-5F7F-1303-000000007E01}2776C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000513Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.680{F97E5129-0A0E-5F7F-0B00-000000007E01}8603736C:\Windows\system32\lsass.exe{F97E5129-0B7F-5F7F-1303-000000007E01}2776C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000512Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.649{F97E5129-0B7F-5F7F-1303-000000007E01}2776C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_icooe3sa.ulg.ps12020-10-08 12:52:15.649 10341000x8000000000000000511Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.634{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7F-5F7F-1303-000000007E01}2776C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000510Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.618{F97E5129-0B7F-5F7F-0F03-000000007E01}35242796C:\Windows\system32\conhost.exe{F97E5129-0B7F-5F7F-1303-000000007E01}2776C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000509Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.618{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000508Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.618{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000507Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.618{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000506Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.618{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000505Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.618{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000504Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.618{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000503Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.618{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000502Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.618{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000501Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.618{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000500Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.618{F97E5129-0A07-5F7F-0500-000000007E01}6401168C:\Windows\system32\csrss.exe{F97E5129-0B7F-5F7F-1303-000000007E01}2776C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000499Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.618{F97E5129-0B7F-5F7F-1203-000000007E01}23882308C:\Windows\system32\cmd.exe{F97E5129-0B7F-5F7F-1303-000000007E01}2776C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000498Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.618{F97E5129-0B7F-5F7F-1303-000000007E01}2776C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXEPowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAAVQB3AEIAbABBAEgAUQBBAEwAUQBCAFQAQQBIAFEAQQBjAGcAQgBwAEEARwBNAEEAZABBAEIATgBBAEcAOABBAFoAQQBCAGwAQQBDAEEAQQBMAFEAQgBXAEEARwBVAEEAYwBnAEIAegBBAEcAawBBAGIAdwBCAHUAQQBDAEEAQQBUAEEAQgBoAEEASABRAEEAWgBRAEIAegBBAEgAUQBBAEMAZwBCAHoAQQBHAGcAQQBkAFEAQgAwAEEARwBRAEEAYgB3AEIAMwBBAEcANABBAEkAQQBBAHYAQQBIAEkAQQBJAEEAQQB2AEEASABRAEEASQBBAEEAeQBBAEMAQQBBAEwAdwBCAGoAQQBDAEEAQQBJAGcAQgBTAEEARwBVAEEAWQBnAEIAdgBBAEcAOABBAGQAQQBBAGcAQQBHAGsAQQBiAGcAQgBwAEEASABRAEEAYQBRAEIAaABBAEgAUQBBAFoAUQBCAGsAQQBDAEEAQQBZAGcAQgA1AEEAQwBBAEEAUQBRAEIAdQBBAEgATQBBAGEAUQBCAGkAQQBHAHcAQQBaAFEAQQBpAEEAQQBvAEEAUwBRAEIAbQBBAEMAQQBBAEsAQQBBAHQAQQBHADQAQQBiAHcAQgAwAEEAQwBBAEEASgBBAEEALwBBAEMAawBBAEkAQQBCADcAQQBDAEEAQQBTAFEAQgBtAEEAQwBBAEEASwBBAEIASABBAEcAVQBBAGQAQQBBAHQAQQBGAFkAQQBZAFEAQgB5AEEARwBrAEEAWQBRAEIAaQBBAEcAdwBBAFoAUQBBAGcAQQBFAHcAQQBRAFEAQgBUAEEARgBRAEEAUgBRAEIAWQBBAEUAawBBAFYAQQBCAEQAQQBFADgAQQBSAEEAQgBGAEEAQwBBAEEATABRAEIARgBBAEgASQBBAGMAZwBCAHYAQQBIAEkAQQBRAFEAQgBqAEEASABRAEEAYQBRAEIAdgBBAEcANABBAEkAQQBCAFQAQQBHAGsAQQBiAEEAQgBsAEEARwA0AEEAZABBAEIAcwBBAEgAawBBAFEAdwBCAHYAQQBHADQAQQBkAEEAQgBwAEEARwA0AEEAZABRAEIAbABBAEMAawBBAEkAQQBCADcAQQBDAEEAQQBaAFEAQgA0AEEARwBrAEEAZABBAEEAZwBBAEMAUQBBAFQAQQBCAEIAQQBGAE0AQQBWAEEAQgBGAEEARgBnAEEAUwBRAEIAVQBBAEUATQBBAFQAdwBCAEUAQQBFAFUAQQBJAEEAQgA5AEEAQwBBAEEAUgBRAEIAcwBBAEgATQBBAFoAUQBBAGcAQQBIAHMAQQBJAEEAQgBsAEEASABnAEEAYQBRAEIAMABBAEMAQQBBAE0AUQBBAGcAQQBIADAAQQBJAEEAQgA5AEEAQQA9AD0AC:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7F-5F7F-32DC-110000000000}0x11dc320HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{F97E5129-0B7F-5F7F-1203-000000007E01}2388C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAAVQB3AEIAbABBAEgAUQBBAEwAUQBCAFQAQQBIAFEAQQBjAGcAQgBwAEEARwBNAEEAZABBAEIATgBBAEcAOABBAFoAQQBCAGwAQQBDAEEAQQBMAFEAQgBXAEEARwBVAEEAYwBnAEIAegBBAEcAawBBAGIAdwBCAHUAQQBDAEEAQQBUAEEAQgBoAEEASABRAEEAWgBRAEIAegBBAEgAUQBBAEMAZwBCAHoAQQBHAGcAQQBkAFEAQgAwAEEARwBRAEEAYgB3AEIAMwBBAEcANABBAEkAQQBBAHYAQQBIAEkAQQBJAEEAQQB2AEEASABRAEEASQBBAEEAeQBBAEMAQQBBAEwAdwBCAGoAQQBDAEEAQQBJAGcAQgBTAEEARwBVAEEAWQBnAEIAdgBBAEcAOABBAGQAQQBBAGcAQQBHAGsAQQBiAGcAQgBwAEEASABRAEEAYQBRAEIAaABBAEgAUQBBAFoAUQBCAGsAQQBDAEEAQQBZAGcAQgA1AEEAQwBBAEEAUQBRAEIAdQBBAEgATQBBAGEAUQBCAGkAQQBHAHcAQQBaAFEAQQBpAEEAQQBvAEEAUwBRAEIAbQBBAEMAQQBBAEsAQQBBAHQAQQBHADQAQQBiAHcAQgAwAEEAQwBBAEEASgBBAEEALwBBAEMAawBBAEkAQQBCADcAQQBDAEEAQQBTAFEAQgBtAEEAQwBBAEEASwBBAEIASABBAEcAVQBBAGQAQQBBAHQAQQBGAFkAQQBZAFEAQgB5AEEARwBrAEEAWQBRAEIAaQBBAEcAdwBBAFoAUQBBAGcAQQBFAHcAQQBRAFEAQgBUAEEARgBRAEEAUgBRAEIAWQBBAEUAawBBAFYAQQBCAEQAQQBFADgAQQBSAEEAQgBGAEEAQwBBAEEATABRAEIARgBBAEgASQBBAGMAZwBCAHYAQQBIAEkAQQBRAFEAQgBqAEEASABRAEEAYQBRAEIAdgBBAEcANABBAEkAQQBCAFQAQQBHAGsAQQBiAEEAQgBsAEEARwA0AEEAZABBAEIAcwBBAEgAawBBAFEAdwBCAHYAQQBHADQAQQBkAEEAQgBwAEEARwA0AEEAZABRAEIAbABBAEMAawBBAEkAQQBCADcAQQBDAEEAQQBaAFEAQgA0AEEARwBrAEEAZABBAEEAZwBBAEMAUQBBAFQAQQBCAEIAQQBGAE0AQQBWAEEAQgBGAEEARgBnAEEAUwBRAEIAVQBBAEUATQBBAFQAdwBCAEUAQQBFAFUAQQBJAEEAQgA5AEEAQwBBAEEAUgBRAEIAcwBBAEgATQBBAFoAUQBBAGcAQQBIAHMAQQBJAEEAQgBsAEEASABnAEEAYQBRAEIAMABBAEMAQQBBAE0AUQBBAGcAQQBIADAAQQBJAEEAQgA5AEEAQQA9AD0A 10341000x8000000000000000497Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.618{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000496Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.618{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000495Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.602{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000494Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.602{F97E5129-0B7F-5F7F-0F03-000000007E01}35242796C:\Windows\system32\conhost.exe{F97E5129-0B7F-5F7F-1203-000000007E01}2388C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000493Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.602{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000492Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.602{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000491Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.602{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000490Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.602{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000489Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.602{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000488Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.602{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000487Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.602{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000486Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.602{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000485Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.602{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000484Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.602{F97E5129-0A07-5F7F-0500-000000007E01}6402964C:\Windows\system32\csrss.exe{F97E5129-0B7F-5F7F-1203-000000007E01}2388C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000483Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.602{F97E5129-0B7F-5F7F-0E03-000000007E01}51123700C:\Windows\system32\WinrsHost.exe{F97E5129-0B7F-5F7F-1203-000000007E01}2388C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\WinrsHost.exe+2c94|C:\Windows\system32\WinrsHost.exe+2eb1|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb 154100x8000000000000000482Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.613{F97E5129-0B7F-5F7F-1203-000000007E01}2388C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAAVQB3AEIAbABBAEgAUQBBAEwAUQBCAFQAQQBIAFEAQQBjAGcAQgBwAEEARwBNAEEAZABBAEIATgBBAEcAOABBAFoAQQBCAGwAQQBDAEEAQQBMAFEAQgBXAEEARwBVAEEAYwBnAEIAegBBAEcAawBBAGIAdwBCAHUAQQBDAEEAQQBUAEEAQgBoAEEASABRAEEAWgBRAEIAegBBAEgAUQBBAEMAZwBCAHoAQQBHAGcAQQBkAFEAQgAwAEEARwBRAEEAYgB3AEIAMwBBAEcANABBAEkAQQBBAHYAQQBIAEkAQQBJAEEAQQB2AEEASABRAEEASQBBAEEAeQBBAEMAQQBBAEwAdwBCAGoAQQBDAEEAQQBJAGcAQgBTAEEARwBVAEEAWQBnAEIAdgBBAEcAOABBAGQAQQBBAGcAQQBHAGsAQQBiAGcAQgBwAEEASABRAEEAYQBRAEIAaABBAEgAUQBBAFoAUQBCAGsAQQBDAEEAQQBZAGcAQgA1AEEAQwBBAEEAUQBRAEIAdQBBAEgATQBBAGEAUQBCAGkAQQBHAHcAQQBaAFEAQQBpAEEAQQBvAEEAUwBRAEIAbQBBAEMAQQBBAEsAQQBBAHQAQQBHADQAQQBiAHcAQgAwAEEAQwBBAEEASgBBAEEALwBBAEMAawBBAEkAQQBCADcAQQBDAEEAQQBTAFEAQgBtAEEAQwBBAEEASwBBAEIASABBAEcAVQBBAGQAQQBBAHQAQQBGAFkAQQBZAFEAQgB5AEEARwBrAEEAWQBRAEIAaQBBAEcAdwBBAFoAUQBBAGcAQQBFAHcAQQBRAFEAQgBUAEEARgBRAEEAUgBRAEIAWQBBAEUAawBBAFYAQQBCAEQAQQBFADgAQQBSAEEAQgBGAEEAQwBBAEEATABRAEIARgBBAEgASQBBAGMAZwBCAHYAQQBIAEkAQQBRAFEAQgBqAEEASABRAEEAYQBRAEIAdgBBAEcANABBAEkAQQBCAFQAQQBHAGsAQQBiAEEAQgBsAEEARwA0AEEAZABBAEIAcwBBAEgAawBBAFEAdwBCAHYAQQBHADQAQQBkAEEAQgBwAEEARwA0AEEAZABRAEIAbABBAEMAawBBAEkAQQBCADcAQQBDAEEAQQBaAFEAQgA0AEEARwBrAEEAZABBAEEAZwBBAEMAUQBBAFQAQQBCAEIAQQBGAE0AQQBWAEEAQgBGAEEARgBnAEEAUwBRAEIAVQBBAEUATQBBAFQAdwBCAEUAQQBFAFUAQQBJAEEAQgA5AEEAQwBBAEEAUgBRAEIAcwBBAEgATQBBAFoAUQBBAGcAQQBIAHMAQQBJAEEAQgBsAEEASABnAEEAYQBRAEIAMABBAEMAQQBBAE0AUQBBAGcAQQBIADAAQQBJAEEAQgA5AEEAQQA9AD0AC:\Users\Administrator\ATTACKRANGE\Administrator{F97E5129-0B7F-5F7F-32DC-110000000000}0x11dc320HighMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{F97E5129-0B7F-5F7F-0E03-000000007E01}5112C:\Windows\System32\winrshost.exeC:\Windows\system32\WinrsHost.exe -Embedding 10341000x8000000000000000481Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.602{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000480Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.602{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000479Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.602{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000478Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.602{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000477Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.602{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000476Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.602{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0A10-5F7F-1300-000000007E01}1336C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000475Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.431{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0B7F-5F7F-1103-000000007E01}2352C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000474Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.431{F97E5129-0A0E-5F7F-0B00-000000007E01}860592C:\Windows\system32\lsass.exe{F97E5129-0B7F-5F7F-1103-000000007E01}2352C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000473Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.399{F97E5129-0B7F-5F7F-1103-000000007E01}2352C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_tftw3eta.nus.ps12020-10-08 12:52:15.399 10341000x8000000000000000472Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.384{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7F-5F7F-1103-000000007E01}2352C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000471Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.368{F97E5129-0B7F-5F7F-0F03-000000007E01}35242796C:\Windows\system32\conhost.exe{F97E5129-0B7F-5F7F-1103-000000007E01}2352C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000470Microsoft-Windows-Sysmon/Operationalwin-dc-8537412.attackrange.local-2020-10-08 12:52:15.368{F97E5129-0A10-5F7F-0C00-000000007E01}5721120C:\Windows\system32\svchost.exe{F97E5129-0B7A-5F7F-F402-000000007E01}4268C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Win