154100x80000000000000001646308Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-2024-07-30 16:50:34.784{16e6810e-19da-66a9-c302-000000009402}1504C:\Windows\System32\net1.exe10.0.17763.1 (WinBuild.160101.0800)Net CommandMicrosoft® Windows® Operating SystemMicrosoft Corporationnet1.exeC:\Windows\system32\net1 group "ESX Admins" /domain /addC:\Users\Administrator\Desktop\ATTACKRANGE\Administrator{16e6810e-081f-66a9-f032-0e0000000000}0xe32f02HighMD5=63DD4523677E62A73A8A7494DB321EA2,SHA256=C687157FD58EAA51757CDA87D06C30953A31F03F5356B9F5A9C004FA4BAD4BF5{16e6810e-19da-66a9-c202-000000009402}1992C:\Windows\System32\net.exe"C:\Windows\system32\net.exe" group "ESX Admins" /domain /addATTACKRANGE\Administrator 154100x80000000000000001646288Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-2024-07-30 16:50:34.765{16e6810e-19da-66a9-c202-000000009402}1992C:\Windows\System32\net.exe10.0.17763.1 (WinBuild.160101.0800)Net CommandMicrosoft® Windows® Operating SystemMicrosoft Corporationnet.exe"C:\Windows\system32\net.exe" group "ESX Admins" /domain /addC:\Users\Administrator\Desktop\ATTACKRANGE\Administrator{16e6810e-081f-66a9-f032-0e0000000000}0xe32f02HighMD5=AE61D8F04BCDE8158304067913160B31,SHA256=25C8266D2BC1D5626DCDF72419838B397D28D44D00AC09F02FF4E421B43EC369{16e6810e-0831-66a9-fa00-000000009402}6424C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" ATTACKRANGE\Administrator 154100x80000000000000001645907Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-2024-07-30 16:50:05.137{16e6810e-19bd-66a9-c102-000000009402}4036C:\Windows\System32\net1.exe10.0.17763.1 (WinBuild.160101.0800)Net CommandMicrosoft® Windows® Operating SystemMicrosoft Corporationnet1.exeC:\Windows\system32\net1 group "ESX Admins" /domain /addC:\Users\Administrator\Desktop\ATTACKRANGE\Administrator{16e6810e-081f-66a9-f032-0e0000000000}0xe32f02HighMD5=63DD4523677E62A73A8A7494DB321EA2,SHA256=C687157FD58EAA51757CDA87D06C30953A31F03F5356B9F5A9C004FA4BAD4BF5{16e6810e-19bd-66a9-c002-000000009402}1668C:\Windows\System32\net.exe"C:\Windows\system32\net.exe" group "ESX Admins" /domain /addATTACKRANGE\Administrator 154100x80000000000000001645810Microsoft-Windows-Sysmon/Operationalar-win-dc.attackrange.local-2024-07-30 16:50:05.047{16e6810e-19bd-66a9-c002-000000009402}1668C:\Windows\System32\net.exe10.0.17763.1 (WinBuild.160101.0800)Net CommandMicrosoft® Windows® Operating SystemMicrosoft Corporationnet.exe"C:\Windows\system32\net.exe" group "ESX Admins" /domain /addC:\Users\Administrator\Desktop\ATTACKRANGE\Administrator{16e6810e-081f-66a9-f032-0e0000000000}0xe32f02HighMD5=AE61D8F04BCDE8158304067913160B31,SHA256=25C8266D2BC1D5626DCDF72419838B397D28D44D00AC09F02FF4E421B43EC369{16e6810e-0831-66a9-fa00-000000009402}6424C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" ATTACKRANGE\Administrator