13241300x800000000000000010987Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.localT1060,RunKeySetValue2023-09-25 14:33:19.151{AEEC61E8-93F5-6511-1104-000000001503}5784C:\Users\Administrator\AppData\Local\Temp\server.exeHKU\S-1-5-21-924054271-2621075704-621839002-500\SOFTWARE\c4d89260ab33f649750816ed8ac2eedd\2681e81bb4c4b3e6338ce2a456fb93a7Binary DataATTACKRANGE\Administrator 13241300x80000000000000007385Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.localT1060,RunKeySetValue2023-09-25 14:08:09.677{AEEC61E8-93F5-6511-1104-000000001503}5784C:\Users\Administrator\AppData\Local\Temp\server.exeHKU\S-1-5-21-924054271-2621075704-621839002-500\SOFTWARE\c4d89260ab33f649750816ed8ac2eedd\2681e81bb4c4b3e6338ce2a456fb93a7Binary DataATTACKRANGE\Administrator 12241200x80000000000000007376Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.localT1060,RunKeyDeleteValue2023-09-25 14:08:06.405{AEEC61E8-940B-6511-1A04-000000001503}5580C:\Windows\regedit.exeHKU\S-1-5-21-924054271-2621075704-621839002-500\SOFTWARE\c4d89260ab33f649750816ed8ac2eedd\2681e81bb4c4b3e6338ce2a456fb93a7ATTACKRANGE\Administrator