154100x80000000000000001090536Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-2025-02-11 09:49:08.620{A9E392D4-1D14-67AB-8702-00000000CD03}6668C:\Windows\SysWOW64\svchost.exe10.0.14393.5582 (rs1_release.221130-1719)Host Process for Windows ServicesMicrosoft® Windows® Operating SystemMicrosoft Corporationsvchost.exeC:\Windows\system32\svchost.exeC:\Users\Public\ATTACKRANGE\Administrator{A9E392D4-1530-67AB-2A2A-080000000000}0x82a2a2HighMD5=E1880C3871F1A80A185DA63892DC7FF8,SHA256=2B6BDE0D1DD250F7940137E562B0DEDD41ACD2B9B84C41BAE7BDC359C2CAF6BB,IMPHASH=B6C5D4A35B608F0A4A2DAE9E8FF12A1A{A9E392D4-1D14-67AB-8602-00000000CD03}6976C:\ProgramData\Microsot\MicrosotShared.exeC:\ProgramData\Microsot\MicrosotShared.exe -FHGXGVJ_MCQAZL_VHMZHWUGATTACKRANGE\Administrator