154100x800000000000000024681Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-2025-03-17 09:28:23.274{09721E1F-EB37-67D7-FE00-00000000D803}4464C:\Windows\System32\mstsc.exe10.0.14393.4169 (rs1_release.210107-1130)Remote Desktop ConnectionMicrosoft® Windows® Operating SystemMicrosoft Corporationmstsc.exe"C:\Windows\system32\mstsc.exe" /v:3.33.33.33:3389C:\Windows\system32\ATTACKRANGE\Administrator{09721E1F-EAC7-67D7-8FE0-060000000000}0x6e08f2HighMD5=4CDEF06648D9EBBD838902C7CACBE93C,SHA256=039EA156489734B5822B6A5B44B3F4FF06706D6F91D491477D7AB710009D2CB9,IMPHASH=625CC0C39AF8D5F649C939225D424264{09721E1F-EAC8-67D7-E500-00000000D803}4516C:\Windows\explorer.exe"C:\Windows\Explorer.EXE" /NOUACCHECKATTACKRANGE\Administrator 4688201331200x8020000000000000548371Securityar-win-dc.attackrange.localATTACKRANGE\AdministratorAdministratorATTACKRANGE0x6e08f0x1170C:\Windows\System32\mstsc.exe%%19360x11a4NULL SID--0x0C:\Windows\explorer.exeMandatory Label\High Mandatory Level 154100x800000000000000024680Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-2025-03-17 09:28:11.465{09721E1F-EB2B-67D7-FD00-00000000D803}1436C:\Windows\System32\mstsc.exe10.0.14393.4169 (rs1_release.210107-1130)Remote Desktop ConnectionMicrosoft® Windows® Operating SystemMicrosoft Corporationmstsc.exe"C:\Windows\system32\mstsc.exe" /v:4.44.44.44:3389 /u:Administrator /p:password1C:\Windows\system32\ATTACKRANGE\Administrator{09721E1F-EAC7-67D7-8FE0-060000000000}0x6e08f2HighMD5=4CDEF06648D9EBBD838902C7CACBE93C,SHA256=039EA156489734B5822B6A5B44B3F4FF06706D6F91D491477D7AB710009D2CB9,IMPHASH=625CC0C39AF8D5F649C939225D424264{09721E1F-EAC8-67D7-E500-00000000D803}4516C:\Windows\explorer.exe"C:\Windows\Explorer.EXE" /NOUACCHECKATTACKRANGE\Administrator 4688201331200x8020000000000000548370Securityar-win-dc.attackrange.localATTACKRANGE\AdministratorAdministratorATTACKRANGE0x6e08f0x59cC:\Windows\System32\mstsc.exe%%19360x11a4NULL SID--0x0C:\Windows\explorer.exeMandatory Label\High Mandatory Level 154100x800000000000000024672Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-2025-03-17 09:27:30.922{09721E1F-EB02-67D7-F400-00000000D803}5672C:\Windows\System32\mstsc.exe10.0.14393.4169 (rs1_release.210107-1130)Remote Desktop ConnectionMicrosoft® Windows® Operating SystemMicrosoft Corporationmstsc.exe"C:\Windows\system32\mstsc.exe" /v:5.55.55.55:3389C:\Windows\system32\ATTACKRANGE\Administrator{09721E1F-EAC7-67D7-8FE0-060000000000}0x6e08f2HighMD5=4CDEF06648D9EBBD838902C7CACBE93C,SHA256=039EA156489734B5822B6A5B44B3F4FF06706D6F91D491477D7AB710009D2CB9,IMPHASH=625CC0C39AF8D5F649C939225D424264{09721E1F-EAC8-67D7-E500-00000000D803}4516C:\Windows\explorer.exe"C:\Windows\Explorer.EXE" /NOUACCHECKATTACKRANGE\Administrator 4688201331200x8020000000000000548349Securityar-win-dc.attackrange.localATTACKRANGE\AdministratorAdministratorATTACKRANGE0x6e08f0x1628C:\Windows\System32\mstsc.exe%%19360x11a4NULL SID--0x0C:\Windows\explorer.exeMandatory Label\High Mandatory Level