154100x800000000000000024907Microsoft-Windows-Sysmon/Operationalar-win-2.attackrange.local-2023-11-08 19:16:34.365{6CA7D817-DE92-654B-7325-000000000A03}1356C:\tmpa\Autoit3.exe3, 3, 14, 5AutoIt v3 ScriptAutoIt v3 ScriptAutoIt TeamAutoIt3.exec:\tmpa\Autoit3.exe c:\tmpa\script.au3C:\Users\ADMINI~1\AppData\Local\Temp\MW-180f9688-8ac3-4403-88a4-5a09c8ffa5e1\files\AR-WIN-2\Administrator{6CA7D817-C8F6-654B-7D62-110200000000}0x211627d2HighMD5=C56B5F0201A3B3DE53E561FE76912BFD,SHA256=237D1BCA6E056DF5BB16A1216A434634109478F882D3B1D58344C801D184F95D{6CA7D817-DE91-654B-7225-000000000A03}3752C:\Users\ADMINI~1\AppData\Local\Temp\MW-180f9688-8ac3-4403-88a4-5a09c8ffa5e1\files\windbg.exe"C:\Users\ADMINI~1\AppData\Local\Temp\MW-180f9688-8ac3-4403-88a4-5a09c8ffa5e1\files\windbg.exe" AR-WIN-2\Administrator