11/23/2021 02:49:00 PM LogName=System SourceName=Microsoft-Windows-Service Control Manager EventCode=7045 EventType=4 Type=Information ComputerName=win-host-987.attackrange.local User=NOT_TRANSLATED Sid=S-1-5-21-1166625382-1442148322-2337405042-500 SidType=0 TaskCategory=None OpCode=The operation completed successfully. RecordNumber=102421 Keywords=Classic Message=A service was installed in the system. Service Name: maliciousService Service File Name: C:\metS.exe Service Type: user mode service Service Start Type: demand start Service Account: LocalSystem 11/23/2021 02:49:13 PM LogName=System SourceName=Microsoft-Windows-Service Control Manager EventCode=7036 EventType=4 Type=Information ComputerName=win-host-987.attackrange.local TaskCategory=None OpCode=The operation completed successfully. RecordNumber=102423 Keywords=Classic Message=The maliciousService service entered the stopped state. 11/23/2021 02:49:13 PM LogName=System SourceName=Microsoft-Windows-Service Control Manager EventCode=7036 EventType=4 Type=Information ComputerName=win-host-987.attackrange.local TaskCategory=None OpCode=The operation completed successfully. RecordNumber=102422 Keywords=Classic Message=The maliciousService service entered the running state. 11/23/2021 02:49:14 PM LogName=System SourceName=Microsoft-Windows-Service Control Manager EventCode=7036 EventType=4 Type=Information ComputerName=win-host-987.attackrange.local TaskCategory=None OpCode=The operation completed successfully. RecordNumber=102424 Keywords=Classic Message=The Windows Error Reporting Service service entered the running state.