13241300x80000000000000001489340Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.555{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\14.0\Outlook\WebView\Tasks\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489338Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.539{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\14.0\Outlook\WebView\Sent Mail\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489336Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.533{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\14.0\Outlook\WebView\RSS\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489334Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.517{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\14.0\Outlook\WebView\Outbox\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489332Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.517{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\14.0\Outlook\WebView\Notes\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489330Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.501{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\14.0\Outlook\WebView\Junk E-mail\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489328Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.501{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\14.0\Outlook\WebView\Journal\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489326Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.486{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\14.0\Outlook\WebView\Drafts\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489324Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.470{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\14.0\Outlook\WebView\Deleted Items\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489322Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.470{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\14.0\Outlook\WebView\Contacts\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489318Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.455{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\14.0\Outlook\WebView\Calendar\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489249Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.455{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\14.0\Outlook\WebView\Inbox\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489221Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.439{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\15.0\Outlook\WebView\Tasks\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489192Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.417{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\15.0\Outlook\WebView\Sent Mail\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489189Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.417{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\15.0\Outlook\WebView\RSS\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489187Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.401{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\15.0\Outlook\WebView\Outbox\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489185Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.401{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\15.0\Outlook\WebView\Notes\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489149Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.385{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\15.0\Outlook\WebView\Junk E-mail\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489146Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.370{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\15.0\Outlook\WebView\Journal\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489117Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.354{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\15.0\Outlook\WebView\Drafts\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489115Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.338{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\15.0\Outlook\WebView\Deleted Items\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489113Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.332{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\15.0\Outlook\WebView\Contacts\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489111Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.317{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\15.0\Outlook\WebView\Calendar\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489058Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.287{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\15.0\Outlook\WebView\Inbox\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001489025Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.254{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\16.0\Outlook\WebView\Tasks\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001488997Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.239{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\16.0\Outlook\WebView\Sent Mail\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001488967Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.217{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\16.0\Outlook\WebView\RSS\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001488940Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.201{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\16.0\Outlook\WebView\Outbox\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001488914Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.186{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\16.0\Outlook\WebView\Notes\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001488886Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.186{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\16.0\Outlook\WebView\Junk E-mail\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001488858Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.170{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\16.0\Outlook\WebView\Journal\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001488841Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.154{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\16.0\Outlook\WebView\Drafts\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001488827Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.139{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\16.0\Outlook\WebView\Deleted Items\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001488823Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.132{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\16.0\Outlook\WebView\Contacts\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001488821Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.116{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\16.0\Outlook\WebView\Calendar\URLhttps://example.com/maliciousATTACKRANGE\Administrator 13241300x80000000000000001488819Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-SetValue2024-07-30 15:29:40.116{16e6810e-c3eb-66a7-d370-060000009302}6560C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKU\S-1-5-21-560616516-1175754387-3922768235-500\Software\Microsoft\Office\16.0\Outlook\WebView\Inbox\URLhttps://example.com/maliciousATTACKRANGE\Administrator