0debbcb2-f9f2-934f-75f3-dbdc4adca4074a9a9614-29cf-44fe-86f1-a5515dab8bf1 1 5 4 1 0 0x8000000000000000 5036 Microsoft-Windows-Sysmon/Operational DESKTOP-94AM2TR - 2025-07-30 17:26:57.877 F7E2254D-55E1-688A-AA0C-000000000200 8512 C:\Windows\System32\cmd.exe 10.0.19041.4355 (WinBuild.160101.0800) Windows Command Processor Microsoft® Windows® Operating System Microsoft Corporation Cmd.Exe "c:\Windows\System32\cmd.exe" "/c dir /od /s /a c:\ > C:\Windows\Temp\TS_Aahoivw.tmp 2>nul" C:\Windows\system32\ DESKTOP-94AM2TR\user F7E2254D-55E1-688A-95CE-A90000000000 0xa9ce95 0 High MD5=2B40C98ED0F7A1D3B091A3E8353132DC,SHA256=BADF4752413CB0CBDC03FB95820CA167F0CDC63B597CCDB5EF43111180E088B0,IMPHASH=272245E2988E1E430500B852C4FB5E18 F7E2254D-4166-688A-2F00-000000000200 2712 C:\Program Files\VMware\VMware Tools\vmtoolsd.exe "C:\Program Files\VMware\VMware Tools\vmtoolsd.exe" NT AUTHORITY\SYSTEM