{"CommandLine": "\"C:\\ProgramData\\USOShared\\svchost.exe\" -nostdlib -run conf.c", "EventCode": "1", "EventData_Xml": "-2026-02-02 22:28:05.802{05ed74c3-24f5-6981-ef92-000000005302}8968C:\\ProgramData\\USOShared\\svchost.exe10.0.20348.4647 (WinBuild.160101.0800)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.Exe\"C:\\ProgramData\\USOShared\\svchost.exe\" -nostdlib -run conf.c C:\\Users\\Administrator\\ATTACKRANGE\\Administrator{05ed74c3-b450-697b-1298-200000000000}0x2098122HighMD5=F63068E624FE6B82058AAAA671D4BC96,SHA256=90D120880614E1E2A94067BAAD1454B09E2BE7A9DA51B71E33C247077D9F9538,IMPHASH=D60B77062898DC6BFAE7FE11A0F8806C{05ed74c3-24f4-6981-eb92-000000005302}9844C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" ATTACKRANGE\\Administrator", "EventID": "1", "Image": "C:\\ProgramData\\USOShared\\svchost.exe", "System_Props_Xml": "154100x800000000000000043009Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local", "_bkt": "win~2~84569963-7203-40C6-84C0-B281193711B0", "_cd": "2:204952332", "_indextime": "1770071286", "_raw": "154100x800000000000000043009Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-2026-02-02 22:28:05.802{05ed74c3-24f5-6981-ef92-000000005302}8968C:\\ProgramData\\USOShared\\svchost.exe10.0.20348.4647 (WinBuild.160101.0800)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.Exe\"C:\\ProgramData\\USOShared\\svchost.exe\" -nostdlib -run conf.c C:\\Users\\Administrator\\ATTACKRANGE\\Administrator{05ed74c3-b450-697b-1298-200000000000}0x2098122HighMD5=F63068E624FE6B82058AAAA671D4BC96,SHA256=90D120880614E1E2A94067BAAD1454B09E2BE7A9DA51B71E33C247077D9F9538,IMPHASH=D60B77062898DC6BFAE7FE11A0F8806C{05ed74c3-24f4-6981-eb92-000000005302}9844C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" ATTACKRANGE\\Administrator", "_serial": "0", "_si": ["splunk-server", "win"], "_sourcetype": "XmlWinEventLog", "_time": "2026-02-02T22:28:05.000+00:00", "host": "AR-WIN-DC", "index": "win", "linecount": "1", "source": "XmlWinEventLog:Microsoft-Windows-Sysmon/Operational", "sourcetype": "XmlWinEventLog", "splunk_server": "splunk-server"}